Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology7 min read

Cloudflare open-sources vibe-coding platform for people who aren't coders - Ars Technica

Cloudflare built an AI agent workspace for its employees. Now it’s open source. Discover insights about cloudflare open-sources vibe-coding platform for people

TechnologyInnovationBest PracticesGuideTutorial
Cloudflare open-sources vibe-coding platform for people who aren't coders - Ars Technica
Listen to Article
0:00
0:00
0:00

Cloudflare open-sources vibe-coding platform for people who aren't coders - Ars Technica

Overview

Cloudflare open-sources vibe-coding platform for people who aren’t coders

Cloudflare built an AI agent workspace for its employees. Now it’s open source.

Details

Cloudflare has open-sourced its Cloudflare OS platform, which it first developed as an internal workspace for employees to build apps using AI agents—including people who are not software developers or engineers. The company also touts a security framework designed to reduce the risk of employee vibe-coding sessions creating serious security flaws or leading to data breaches.

The tech company spent several months building and internally testing Cloudflare OS, which allows employees to describe workflows in natural language so that an AI agent can code them into applications. In an August 5 blog post announcing the open source version’s availability on Git Hub, the company claims thousands of Cloudflare employees use the platform on a daily basis to “create documents and slides, automate repeatable tasks, and build small apps to visualize data and help them do their work.”

“This is a full-on personal app vibe coding platform, in which the sandbox is so secure that you can pretty much go wild—the AI cannot introduce a significant security bug,” said Kenton Varda, principal engineer at Cloudflare, in a post on the social media platform X. “We believe a company’s security team can feel comfortable giving non-technical users permission to vibe code and then sleep soundly at night.”

The security model relies on creating fine-grained app instances so that a document editor app would run each document as a separate instance in a separate sandbox, Varda explained. The Cloudflare OS platform manages who has permission to access each instance, and each individual runs their own copy of the code that they can freely modify.

This sandboxing mechanism, based on a preexisting Cloudflare feature called Dynamic Workers, does not use typical software containers. Instead, it creates “isolates”—instances of the V8 Java Script execution engine—that take just a few milliseconds to start up and use only a few megabytes of memory. That makes isolates 100 times faster and 10–100 times more memory-efficient than a standard container.

To minimize the exposure of company data, AI agents start out with no permissions to access or share resources and must request them through the Cloudflare OS platform. Server code runs with “global outbound networking disabled” while client code “runs in a sandboxed frame in the browser,” meaning “neither can reach the Internet except through capabilities you explicitly provide,” according to the main company blog post.

That sandboxing and permission process baked into the Cloudflare OS framework could prove helpful in practice, even if no system is foolproof. Researchers at Pillar Security just published a report on sandbox escapes and boundary bypasses in popular AI coding agents such as Cursor, Codex, Gemini CLI, and Antigravity.

Cloudflare OS can work with just about any AI model and allows organizations to select the most suitable model for the job at hand. “Not every user needs access to the max thinking mode of the latest frontier lab model,” said Sam Rhea, chief information officer at Cloudflare, in a separate blog post. “And we do not need team members spending $20 to summarize their email inbox every hour.”

The company has also improved the platform so that running skill files for specific workflows relies more on deterministic steps with AI inference used only when needed rather than requiring a “token-hungry inference session” each time, Rhea said.

The platform also enables administrators to monitor employees’ AI inference spending and set budgets and rate limits—a crucial feature at a time when companies and individuals have found it can be all too easy to burn through their budgets for AI model use. But that won’t stop more questionable practices if corporate leaders decide to incentivize AI “tokenmaxxing” to pressure employees to use AI tools.

Cloudflare shared some hard lessons learned along the way as it tried to ensure the efficient use of AI tools through Cloudflare OS. One early mistake involved simply giving everyone outside the engineering team “the same tools with slightly friendlier user interfaces” because the AI coding harnesses that engineers typically use are less suitable for knowledge work involving “one-off outputs and work on projects that involve dozens of systems of record,” Rhea explained.

“If you give everyone a harness workspace that is great at writing code, you’ll wind up with way more code than you need,” Rhea wrote in his blog post. “The result became a flood of vibe coded apps looking for a problem to solve.”

The growing use of AI agents within the organization also meant “anyone at Cloudflare could now write bad code, faster, thanks to AI,” Rhea said. So the organization created the Cloudflare Engineering Codex, an “authoritative guide” to help both human engineers and AI agents review code and catch potential issues.

Over the past four months, the company’s AI code reviewer “flagged nearly a quarter of a million deviations from Cloudflare engineering standards and blocked 16,000 merges,” said Timo Reimann, a systems engineer at Cloudflare, in a blog post about the Engineering Codex and how the company uses AI agents to uphold engineering standards.

Now that the company is open-sourcing Cloudflare OS for others to use, developers can try to run the entire stack on their own machines. A notable caveat is that the Cloudflare OS backend can only be deployed by Cloudflare users who have subscribed to the Workers Paid plan.

The paid subscription requirement was not initially made clear up front. A Git Hub user raised the issue and shared a screenshot showing that their Workers Free plan had been stopped from deploying the Cloudflare OS backend partway through the process.

“You have a right to charge but requirements should be completed before starting the deployment process,” wrote the Git Hub user mac 2net. “I wasted 20 minutes I will never get back.”

To Cloudflare’s credit, the company quickly updated the deployment process to alert users at the start about the paid plan requirements. A company representative also responded to the issue on Git Hub.

  1.          This Atlantic hurricane season is looking like a dud, but there will be a price to pay
    
  2.          Hank Green found the AI problem that You Tube labels can’t catch
    
  3.          Reddit signals ominous upcoming "changes” for old.reddit.com
    
  4.          After jacking up prices, Disney+ and Netflix consider offering free alternatives
    
  5.          Google plans to kill Assistant on your phone on September 4
    

Ars Technica has been separating the signal from the noise for over 25 years. With our unique combination of technical savvy and wide-ranging interest in the technological arts and sciences, Ars is the trusted source in a sea of information. After all, you don’t need to know everything, only what’s important.

Key Takeaways

  • Cloudflare open-sources vibe-coding platform for people who aren’t coders

  • Cloudflare built an AI agent workspace for its employees

  • Cloudflare has open-sourced its Cloudflare OS platform, which it first developed as an internal workspace for employees to build apps using AI agents—including people who are not software developers or engineers

  • The tech company spent several months building and internally testing Cloudflare OS, which allows employees to describe workflows in natural language so that an AI agent can code them into applications

  • “This is a full-on personal app vibe coding platform, in which the sandbox is so secure that you can pretty much go wild—the AI cannot introduce a significant security bug,” said Kenton Varda, principal engineer at Cloudflare, in a post on the social media platform X

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.