cloudflare / cloudflare-os
Cloudflare OS: An AI productivity environment
Cloudflare OS is an “operating system” for AI productivity originally developed for use inside Cloudflare. A large portion of Cloudflare’s workforce — from engineering to sales and everything in between — uses Cloudflare OS every day to help them do their jobs.
Cloudflare OS:一个 AI 生产力环境。Cloudflare OS 是一个最初为 Cloudflare 内部使用而开发的 AI 生产力“操作系统”。Cloudflare 的大部分员工——从工程到销售以及其他所有部门——每天都在使用 Cloudflare OS 来辅助工作。
This is not a traditional computer operating system. We use the term “operating system” in two senses: An operating system for the company to be productive with AI, in a way that is safe, so that the security team can sleep at night. An operating system for AI workloads, analogous to the sense in which a traditional operating system manages compute workloads.
这并不是传统的计算机操作系统。我们从两个层面使用“操作系统”这个术语:一是作为公司利用 AI 提高生产力的操作系统,且必须以安全的方式运行,让安全团队能够高枕无忧;二是作为 AI 工作负载的操作系统,类似于传统操作系统管理计算工作负载的方式。
Cloudflare OS provides three things in particular: An agent chat UI where you can ask agents to do tasks, preloaded with knowledge about how your company operates. Sandboxed application development, so that you can ask agents to build “gadgets” (small personal apps) and safely share what you’ve built with others. A security framework, called Gatekeepers, that applies guardrails to both agents and apps such that non-technical users can safely “go nuts” and nothing bad will happen.
Cloudflare OS 特别提供了三项功能:一个代理聊天界面(Agent chat UI),你可以在其中要求代理执行任务,并预加载了关于公司运作方式的知识;沙盒化应用开发,你可以要求代理构建“小工具”(小型个人应用),并安全地与他人分享你的成果;一个名为 Gatekeepers 的安全框架,它为代理和应用提供护栏,使非技术用户可以安全地“尽情发挥”而不会造成任何负面影响。
We are making Cloudflare OS open source so that others can copy it and customize it for their own company. The idea is not that your company uses Cloudflare OS, but rather that you make it “Your Company OS”.
我们将 Cloudflare OS 开源,以便其他人可以复制并为自己的公司进行定制。我们的初衷不是让你的公司使用 Cloudflare OS,而是让你将其打造为“你的公司操作系统”。
Quick Start
To quickly run Cloudflare OS locally, install pnpm, then do: pnpm run-local. Then visit: http://localhost:8787. This runs the whole stack locally on wrangler and workerd. This is not meant for production use, but is a quick way to see what the product does. Alternatively, you can deploy to your Cloudflare account. (More options at the end of this readme.)
快速开始
要快速在本地运行 Cloudflare OS,请安装 pnpm,然后执行:pnpm run-local。接着访问:http://localhost:8787。这将在 wrangler 和 workerd 上本地运行整个技术栈。此方式不适用于生产环境,但可以让你快速了解该产品的功能。或者,你也可以将其部署到你的 Cloudflare 账户中。(更多选项请见本文档末尾。)
What to try
Try prompts like: “Make slides for my upcoming meeting with a customer.” (This will use the built-in slides blueprint.) “Make a collaborative whiteboard app.” (This will create a new app from scratch.) “Make a tic tac toe game.” followed by “I’ll be X and you be O. I’ve made my first move. Your turn.” “Make an issue dashboard for this GitHub repo.” (Attach a repo; requires that the GitHub integration is configured.) “Fix the typos in this Google Doc.” (Attach a doc; requires that the Google integration is configured.)
尝试一下
尝试输入以下提示词:“为我即将到来的客户会议制作幻灯片。”(这将使用内置的幻灯片蓝图。)“制作一个协作白板应用。”(这将从零开始创建一个新应用。)“制作一个井字棋游戏。”接着输入“我是 X,你是 O。我已经走了第一步,轮到你了。”“为这个 GitHub 仓库制作一个问题仪表板。”(需附加一个仓库;要求已配置 GitHub 集成。)“修正这个 Google 文档中的错别字。”(需附加一个文档;要求已配置 Google 集成。)
WARNING: Early access
Cloudflare OS is in a state of heavy development. This repository is actually version 2, a complete rewrite taking what we learned from version 1 and putting it on a new foundation. As of the August 2026 release, Cloudflare OS v2 is very capable, but still has many rough edges. We know, and we’re working on it. For now, consider this an “early access” release.
警告:早期访问
Cloudflare OS 正处于高强度的开发阶段。此仓库实际上是第 2 版,它是基于我们在第 1 版中学到的经验进行的彻底重写,并建立在全新的基础之上。截至 2026 年 8 月的版本,Cloudflare OS v2 功能非常强大,但仍有许多不完善之处。我们对此心知肚明,并正在努力改进。目前,请将其视为“早期访问”版本。
Overview: What is Cloudflare OS really?
Gadgets: A new way of thinking about software
Cloudflare OS is more than just another chatbox with connectors. The system revolves around a new approach to software, where every user runs their own copy of the productivity apps they use. When you create a slide deck in Cloudflare OS, you are not calling out to some SaaS software running in the cloud. The system creates a private instance of the slide deck software just for you. We call this a “gadget”. This instance runs in a separate sandbox from everyone else’s slide decks.
概览:Cloudflare OS 到底是什么?
Gadgets(小工具):一种全新的软件思维方式
Cloudflare OS 不仅仅是另一个带有连接器的聊天框。该系统围绕一种新的软件方法构建,即每个用户都运行自己所用生产力应用的独立副本。当你在 Cloudflare OS 中创建幻灯片时,你并不是在调用云端运行的某个 SaaS 软件。系统会专门为你创建一个幻灯片软件的私有实例。我们称之为“Gadget”。该实例运行在与其他人的幻灯片完全隔离的沙盒中。
This has two profound effects: It’s impossible for the slide deck app to have a security bug that leaks your slides to an attacker. The Cloudflare OS sandbox controls all access to your private instance of the app. If you want, you can freely modify the code. If the slide deck app is missing a feature you need, you can just ask your agent to add it. And because of point 1, it’s totally safe to do so. This is a big departure from the last 25 years of cloud architecture and “Software as a Service”, but we think AI has changed the equation. When any user is capable of prompting an agent to add the features they need, the centralized model of software stops making sense.
这带来了两个深远的影响:幻灯片应用不可能出现将你的幻灯片泄露给攻击者的安全漏洞。Cloudflare OS 沙盒控制着对你私有应用实例的所有访问。如果你愿意,可以自由修改代码。如果幻灯片应用缺少你所需的功能,只需让你的代理添加即可。而且由于第一点,这样做是绝对安全的。这与过去 25 年的云架构和“软件即服务”(SaaS)模式有很大不同,但我们认为 AI 已经改变了这一等式。当任何用户都有能力通过提示词让代理添加所需功能时,中心化的软件模式就不再适用了。
Gatekeepers: A capability-based security layer
Gatekeepers are like supercharged MCP servers. When you introduce an agent or Gadget to an external resource, a Gatekeeper is created to manage that access. The Gatekeeper is a piece of software specific to each external service which moderates a Gadget’s connection to that service.
Gatekeepers(守门人):基于能力的安全性层
Gatekeepers 就像是增强版的 MCP 服务器。当你为代理或 Gadget 引入外部资源时,系统会创建一个 Gatekeeper 来管理该访问权限。Gatekeeper 是针对每个外部服务编写的软件,用于调节 Gadget 与该服务的连接。
It: Provides a clean Cap’n Web API to the service (wrapping whatever API the service provides natively). Handles authorization (e.g. via OAuth). Enforces narrow access to only the specific resource the user intended. Logs every action the Gadget (or agent) performs, for your review. For any action which has side effects, provides the human user an opportunity to approve or deny the action (“human in the loop”).
它具备以下功能:为服务提供简洁的 Cap’n Web API(封装服务原生提供的任何 API);处理授权(例如通过 OAuth);强制执行窄范围访问,仅限于用户指定的特定资源;记录 Gadget(或代理)执行的每一个操作,以供你审查;对于任何具有副作用的操作,为人类用户提供批准或拒绝的机会(“人在回路”)。
On the last point, Gatekeepers implement a significant advancement in the state of the art. Traditionally, human-in-the-loop setups require the human to approve actions synchronously. When the agent wants to do something, it has to stop and wait for said approval before it can continue. This is annoying: you give your agent a task, then walk away and get a coffee, only to come back and find the agent got stuck on an approval on the first step and has made no progress. As a result, people often give in and set their agents to “auto-approve”, or —dangerously-skip-permissions, which is, obviously, unsafe.
关于最后一点,Gatekeepers 在技术水平上实现了重大进步。传统上,“人在回路”的设置要求人类同步批准操作。当代理想要执行某项操作时,它必须停下来等待批准才能继续。这很烦人:你给代理分配了任务,然后去喝杯咖啡,回来却发现代理在第一步就卡在等待批准上,毫无进展。结果,人们往往会妥协,将代理设置为“自动批准”,或者危险地跳过权限检查,这显然是不安全的。
Gatekeepers provide a better way: When the agent (or Gadget) performs an action that requires approval, the Gatekeeper will simulate the outcome locally, allowing the agent to proceed and queue up more actions. The Gatekeeper tells the agent that the action completed, and if the agent tries to read back the results, the Gatekeeper gives it simulated results. Once the agent is done, the user may approve or reject the actions in bulk, or one-by-one, but either way, they can do it later, when it is convenient.
Gatekeepers 提供了一种更好的方式:当代理(或 Gadget)执行需要批准的操作时,Gatekeeper 会在本地模拟结果,允许代理继续执行并排队后续操作。Gatekeeper 会告知代理操作已完成;如果代理尝试读取结果,Gatekeeper 会提供模拟结果。一旦代理完成任务,用户可以批量或逐个批准/拒绝这些操作,无论哪种方式,用户都可以在方便时再进行处理。
Logistically, each Gatekeeper is implemented as a separate Worker. In the future, we envision Gatekeeper services being deployed and maintained independently from OS instances, but the details have yet to be worked out. For now…
在实现层面,每个 Gatekeeper 都作为一个独立的 Worker 实现。未来,我们设想 Gatekeeper 服务可以独立于 OS 实例进行部署和维护,但具体细节尚未确定。目前……