Use when a deployed Cloudflare Worker in this repository misbehaves or fails to deploy — osn-api, cire-api or a cire Worker — or when setting or rotating a Worker secret. Covers where to look first, the secret-setting trap for JSON and JWK values, why a secret change needs a redeploy, and the module-evaluation crash on a first deploy.
71
86%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Passed
No findings from the security scan
The tier map, secrets checklist and deploy steps are in wiki/shared/production-deploy.md and wiki/shared/dev-environment.md. This skill holds the traps that cost time.
When a request that crosses several services misbehaves, run wrangler tail on the service that actually fails before forming any theory about the architecture:
bunx wrangler tail <worker-name> --env productionNever source a secrets file to set a secret shaped like JSON or a JWK: bash brace expansion mangles an unquoted {"a":"b"}. Extract the value and pipe it:
VAL=$(grep -m1 '^KEY=' "$SF" | sed 's/^[^=]*=//'); printf '%s' "$VAL" | bunx wrangler secret put KEY --env productionwrangler secret put and wrangler secret delete do not restart warm isolates. When behaviour must change now, redeploy after the change:
bunx wrangler deploy --env productionA Worker's first deploy — even with an existing wrangler.toml — can fail while workerd evaluates the module, because two things are missing then:
fileURLToPath(import.meta.url) at module top level;process.env read or validated at module top level.Move both into request-time code or lazy thunks. Verify with a real wrangler deploy; --dry-run does not catch it.
A named environment that has never deployed gets no routes from the top level. Add [[env.production.routes]] with custom_domain = true.
Changing the schema of a shared package other services import (a DB package, say) needs the whole monorepo suite before merging, not just that package's tests: bun run test.
c63f0ed
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.