Release Notes
Version 1.0.0
📅 Release Date
August 6, 2026
📖 Overview
The first release of @bayudwiyansatria/cloudflare. Cloudflare adapters that had been vendored as
src/core/cloudflare/ and src/core/http/ are now a library, so a fix to KVService lands once rather than in every
consuming Worker.
The repository's existing library scaffolding is kept — the Rollup build, the @/* mapping, the TypeDoc gate, and the
documentation portal — while its placeholder domain is replaced.
⚠️ Breaking Changes
- None. First release — there is no prior version to break.
🚀 Features
| Layer | Contents |
|---|---|
core/bindings/ |
Binding plus ten accessors: AI, Analytics Engine, D1, Durable Objects, Hyperdrive, KV, Queues, R2, Rate Limiting, Vectorize |
core/services/ |
Ten capability services, each implementing an interface from @bayudwiyansatria/core |
constants/, types/ |
cloudflareDefaults and the twelve settings shapes |
./middlewares |
SecurityMiddleware and logToAnalytics, behind a separate subpath |
- Two published entries:
.and./middlewares, each emitting CommonJS, ESM, and declarations. - Hono is an optional peer.
SecurityMiddlewareandlogToAnalyticsship behind@bayudwiyansatria/cloudflare/middlewares, so a Worker using another framework — or none — depends on this package without installing Hono. An ESLint rule keeps Hono confined to that directory, because the moment a binding imports it the peer stops being optional.
🔧 Enhancements
- Configuration is registered, not imported.
resolve()used to import the application'ssrc/config/directly. A package cannot reach into its consumer, so the application now hands the surface to the kernel throughconfigure()and everything here reads it back throughresolve(). - Settings resolve on first use. Accessors are created at module scope so one instance is reused across requests —
and module scope runs while a consumer's imports are still being hoisted, before
configure()can have run. Resolving in a constructor therefore made the import statement throw, with no ordering a consumer could write to avoid it. Everything now goes throughlazySettings(), which memoises a getter and looks the module up on first use, inside a request. EnvbecameCloudflareEnv. The ambient globalinterface Envis now an exported interface a Worker extends: a published package has no reliable way to merge into a consumer's global scope, and two packages attempting it would collide. Every member is optional, widened from the boilerplate's requiredTELEMETRY,AI, andKV— a library cannot know which resources a given Worker provisioned, and every accessor already reports absence throughisBound.- Generic over the environment. Bindings and services are
<E extends CloudflareEnv>with a default, sonew KVService()still works andKVService<Env>gets the Worker's own type at call sites.
🐛 Bug Fixes
- None. First release — there is no prior behaviour to fix.
🔐 Security
- The kernel stays external.
MissingBindingErrorextendsMissingCapabilityErroracross the package boundary, and the configuration registry is module state. A bundle that inlined a second copy of the kernel would break both silently: everyresolve()would throw, andinstanceofwould stop matching.rollup.config.ts#externalprevents it, and anassertExternalsplugin in the same file proves it on every build — a check the unit tests cannot make, since they import fromsrc/rather thanlib/. SecurityMiddlewareships behind its own subpath and carries its own spec.
🧪 Tests
47 specs across four suites, plus test/utils/lazySettings.spec.ts guarding the deferred-resolution contract that made
the package importable at all.
📚 Documentation
- Migrating from the Boilerplate — moving a Worker off a vendored
src/core/. docs/reference/bindings.md— the ten accessors and theirwrangler.jsonwiring.
⬆️ Upgrading
See Migrating from the Boilerplate.
🚨 Known Issues
- None
📦 Dependencies
| Kind | Package |
|---|---|
| Peer | @bayudwiyansatria/core |
| Optional peer | hono — only for ./middlewares |
Packaging notes:
typesVersionsmaps the./middlewaressubpath for consumers on classic (node10) resolution, which predatesexports.- No UMD output: it needs every dependency reachable as a browser global, and this package has real externals.
- No
.d.ts.map:rollup-plugin-dtsemits one withsources: [], which is inert and crashes TypeDoc downstream.
👥 Contributors
- Bayu Dwiyan Satria
🙏 Acknowledgments
Special thanks to all contributors and the open-source community for their support.
For more information, visit the project's GitHub repository.