CIRCL is an experimental, externally visible Go cryptographic library. Consumers include Cloudflare's Go fork, downstream modules, and external researchers. Every change is security-sensitive. The README disclaims API stability — the…
- UserSpan::deferred() creates a stable request root that can be captured by telemetry contexts before activate() makes the sampling decision. - TelemetryContext::withuserspan() attaches an explicit UserSpan without changing ambient scope; the returned context and handle share the same underlying span. - A deferred root is an inactive span in a shared RwLock. Activation replaces it under the write lock; the first active span wins, while inactive results remain retryable. - Recording and children created before activation are inactive. Contexts that…
This document provides essential information for AI coding agents working in the PartyServer monorepo. PartyServer is a monorepo using npm workspaces with multiple packages:
This file provides guidance for AI coding assistants working with this repository. Always consult Cloudflare documentation when working on this repository. Key topics: Use the gh CLI for GitHub interactions.…
This directory contains a deployable Cloudflare Worker that uses @cloudflare/sandbox/bridge to expose the sandbox HTTP API. It is a thin wrapper — all route handling, authentication, pool management, and OpenAPI…
This directory contains a single-file uv script (main.py) that demonstrates the OpenAI Agents SDK with a Cloudflare Sandbox backend. - Single file: everything lives in main.py with inline # ///…
This directory contains a two-process workspace chat demo: a Python backend and a React frontend. - Framework: Starlette (not FastAPI) served with uvicorn. - Dependencies: managed via uv with pyproject.toml.…
Agent-driven QA test harness for the cloudflare-sandbox-bridge Cloudflare Worker. Uses the OpenAI Agents SDK (openai-agents[cloudflare]) to exercise sandbox exec, file I/O, process management, and session persistence against a production deployment.
This directory is the primary home for container-side control API methods used by the Sandbox Durable Object. Add control operations here. Use service methods directly rather than routing through HTTP…
The bridge is the library layer that powers @cloudflare/sandbox/bridge. It provides a bridge() factory that wraps a user's Worker with sandbox API routes, warm pool management, and authentication — all…
This directory is compatibility-only for the HTTP and custom WebSocket route-based API. Do not add transport-layer capabilities here unless the task explicitly requires HTTP/WebSocket compatibility maintenance. DO-to-container control-channel work belongs…
This directory is the primary home for Sandbox Durable Object to container control-channel code. Use role-based names such as ContainerControlClient, ContainerControlConnection, and SandboxControlAPI. Treat capnweb/RPC as an implementation detail unless…
Agent-facing context. If you're picking up work on this site, start here. Astro-based docs site. The nimbus-docs package provides the integration, content schemas, navigation/sidebar/TOC computation, MDX→markdown rendering, build hooks, and the nimbus CLI. Everything you see in src/ is user-owned and yours to edit. For Cloudflare deploys, also: wrangler.jsonc at project root. Frontmatter must validate against docsSchema from nimbus-docs/schemas. Required: title. The schema includes optional fields for description, sidebar overrides, drafts, dates, edit-link suppression — read the schema for the…