Cloudflare OS: Here‘s What’s Inside the Open-Source AI Agent Platform

요약:Cloudflare open-sourced Cloudflare OS, a platform that gives every employee an agent, workspace, and tools to build small apps. It combines an agent workspace grounded in curated company context, a security and governance layer built around "Gatekeepers" that mediate access without exposing credentials to agents, and a layer for personal apps running as Cloudflare Workers. Cloudflare first deployed it internally and rebuilt it for outside organizations. The design deliberately makes security part of the platform: agents start with no access, request specific resources, and every observation is logged and checked against user permissions. Still, skeptics may note that while the code is open source, the runtime lives on Cloudflare's edge, meaning a central entity still controls execution.

In brief

  • Cloudflare open sourced a new version of Cloudflare OS, a platform that gives every employee an agent, a workspace, and tools to build small apps.
  • It bundles an agent workspace, a security and governance layer built around “Gatekeepers,” and a way to ship personal apps that run as Cloudflare Workers.
  • The pitch: run the whole thing on your own systems, connected to your own data, instead of handing agents broad API keys.

Cloudflare built the first version of Cloudflare OS for itself. In May, the company gave every one of its thousands of employees access, CEO Matthew Prince wrote, and people outside engineering started using it to draft documents, build slides, and automate repeatable work. Now Cloudflare is open sourcing a rebuilt version that any organization can deploy and connect to its own internal systems.

“The security had to be part of the platform, not something every person building an app or using an agent has to implement correctly,” the company said in its announcement. That's the real product.

What's actually inside

Cloudflare OS combines three parts. First, there's an agent workspace that grounds each conversation in your company's curated context and skills, with an isolated runtime where the agent can write and run code. There's also a security and governance framework, new in this version, which sits between agents and your systems of record. And, lastly, there's a layer for personal, modifiable apps that lets a workspace turn a chat into a document, a workflow, or a small full-stack app.

Cloudflare's CIO Sam Rhea laid out how the company approached security in this agentic-powered experiment: handing API keys to people and agents is dangerous and doesn't scale, because keys give broad, long-lived access that's hard to constrain or audit. Instead, agents start with access to nothing. So they request a specific resource, and a Gatekeeper — a service-specific Cloudflare Worker — mediates. The credential never touches the agent or its code.

That's a cleaner model than MCP alone. Model Context Protocol tells an agent which tools it can call, but not which underlying resources it has actually seen. Cloudflare OS logs every observation and checks a person's access before they can open a workspace or view what an agent produced.

Each app an agent builds is a real Cloudflare Worker, riding on Dynamic Workers and Durable Object Facets the company built for this project, talking to the client over Cap'n Web, its open-source object-capability RPC system. “If you can build a tool to do a job yourself, agents can use your tool to do the job when you're not there,” the post notes.

It's a strong vision, but some users may still be skeptical: Cloudflare OS is a Cloudflare product, so the agents, apps, and governance it sells you to run all live on Cloudflare's edge. The “open” in open source gets you the code; the runtime still is controlled by a central entity.

면책 성명

본 기사의 견해는 저자의 개인적 견해일 뿐이며 본 플랫폼은 투자 권고를 하지 않습니다. 본 플랫폼은 기사 내 정보의 정확성, 완전성, 적시성을 보장하지 않으며, 개인의 기사 내 정보에 의한 손실에 대해 책임을 지지 않습니다.
전편

Coldcard 익스플로잇이 규제된 비트코인 노출에 대한 수요를 증가시킬 수 있다고 분석가들이 전망

다음

암호화폐 캠페인 활동에서 드문 손실 기록, 그러나 의회 내 암호화폐 대표단은 성장할 가능성 높아