Cloudflare Deploy Guide
Production Cloudflare deployment with custom domains, OAuth apps, and monitoring.
Prerequisites
Section titled “Prerequisites”- Node.js 22+, pnpm 10+
- Cloudflare Workers Paid plan ($5/mo)
- wrangler CLI logged in
- Anthropic API key (or compatible provider)
Quick Deploy
Section titled “Quick Deploy”git clone https://github.com/duyet/oma.gitcd omapnpm installnpx wrangler login./scripts/setup-cf.shCustom Domain
Section titled “Custom Domain”setup-cf.sh writes your account’s config to gitignored
apps/<app>/wrangler.local.jsonc copies — edit those, not the tracked
wrangler.jsonc files. apps/main and apps/integrations each own a
different subdomain; apps/agent has no routes block at all
(the agent worker is only reached internally, not via a public route). Edit
the routes in the two worker configs that do have one:
"routes": [ { "pattern": "app.yourdomain.com", "custom_domain": true }]"routes": [ { "pattern": "integrations.yourdomain.com", "custom_domain": true }]Redeploy:
npx wrangler deploy --config apps/main/wrangler.local.jsoncnpx wrangler deploy --config apps/integrations/wrangler.local.jsoncDNS records auto-create on first deploy (cert provisioning ~1 min).
OAuth Apps
Section titled “OAuth Apps”GitHub OAuth (Console sign-in)
Section titled “GitHub OAuth (Console sign-in)”This adds GitHub as a sign-in option for the Console, alongside email/password.
- Create OAuth app at GitHub Settings → Developer settings → OAuth Apps
- Set callback URL to
https://app.yourdomain.com/auth/callback/github - Set secrets on the main worker:
npx wrangler secret put GITHUB_CLIENT_ID --config apps/main/wrangler.local.jsoncnpx wrangler secret put GITHUB_CLIENT_SECRET --config apps/main/wrangler.local.jsoncSlack OAuth
Section titled “Slack OAuth”Same pattern — see OAuth apps guide for full details.
Monitoring
Section titled “Monitoring”Workers dashboards are available in the Cloudflare Dashboard:
- Main worker: Request count, duration, errors
- Agent worker: Session metrics, tool usage
- Durable Objects: Storage, requests
Enable logging (tail whichever worker you’re debugging):
npx wrangler tail --config apps/main/wrangler.jsoncnpx wrangler tail --config apps/agent/wrangler.jsoncnpx wrangler tail --config apps/integrations/wrangler.jsoncArchitecture
Section titled “Architecture”┌──────────────┐ ┌──────────────┐ ┌──────────────┐│ Console UI │────►│ Main Worker │────►│ Agent Worker ││ (CF Workers)│ │ (API + Auth)│ │ (Sandbox) │└──────────────┘ └──────┬───────┘ └──────────────┘ │ ┌───────┴───────┐ │ Durable Objs │ │ + R2 + D1 │ └───────────────┘Cost Estimates
Section titled “Cost Estimates”| Resource | Cost (approx) |
|---|---|
| Workers Paid plan | $5/mo |
| Durable Objects | ~$2-10/mo (usage dependent) |
| R2 storage | ~$0.015/GB/mo |
| D1 database | ~$0.001/million reads |
| Total | ~$10-20/mo |