Cf: The Agentic CLI for the Cloudflare API

(blog.cloudflare.com)

129 points | by macleos 11 hours ago

18 comments

  • slowin 9 hours ago
    I don't understand why this is written in Typescript. This is a great example of how agents can write code (I'm sure they wrote `cf`), yet having fundamental computer science knowledge is still critical. Do not force your users to manage the dependencies of your cli. Do write your cli in a compiled language. Understand the reason for those decisions and tell your agents to use the correct architecture.
    • geodel 7 hours ago
      No it is exactly right mode for modern tech companies:

      1) If it runs on my dime and my infrastructure I will optimize the hell out using most cleverly written Rust and what not and gloat about engineering prowess.

      2) If it runs on users computers well then, we have carefully evaluated our strategic direction and come to conclusion that JS/TS/Electron option is the best way to go.

      • gobdovan 4 hours ago
        There's also a (maybe more minor but still interesting) explanation. On a server, you know quite precisely your load and you want to be able to causally trace bottlenecks, which is simpler with AOT compiled programs. On users' machines, they may not give you full telemetry and may use your system in quite variable ways. So V8 comes in quite nicely and optimises hot paths on workload it observes on each users system.
        • amluto 17 minutes ago
          Is this sarcasm? We’re talking about a CLI. The fancy JIT system will collect data from one single operation and then promptly forget everything it learned and discard all those shiny optimized instruction sequences before the next operation.

          For example are workloads for which Java performs very, very well. CLI tools that do one operation and return are not examples of these workloads. v8 is plausibly less bad because v8 is also optimized for short-running scripts, but that just means less outrageously slow, not that it will be remotely competitive with native code.

        • geodel 27 minutes ago
          I mean it is the reason they would like to give. Should we accept it though as their core motivation vis-a-vis it is most convenient and low effort for them so they will do it.
      • cschmatzler 7 hours ago
        This is also not correct in this case since they recently rewrote the Artifacts backend from Zig to TypeScript.
    • ashishb 51 minutes ago
      Exactly. Write it in any compiled language, I don't care, I just want the binary

      https://ashishb.net/programming/tools-standalone-binaries/

    • tcdent 8 hours ago
      My read is that it's generally the teams that have been assigned to build a certain product that end up choosing the architecture that it runs on. So when we see TypeScript involved in TUI and CLI applications, most of it is just a repurposing of skill sets from that domain into the terminal. In an organization like Cloudflare, I expect that the developers who don't specialize in TypeScript are working on far more important problems.
    • nharziro 1 hour ago
      I couldn't figure out why Microsoft wrote Github copilot CLI in typescript either.
      • simplesocieties 52 minutes ago
        Language choice is more often due to politics than practicality. Microsoft probably has some internal process for deciding on languages and "defaults" to typescript & C# since they have the most direct control over those languages.
    • cush 6 hours ago
      Seriously there’s zero benefit to be writing CLIs in typescript in 2026
    • amluto 20 minutes ago
      There’s no mention of how long the CLI takes to start. gcloud is hilariously slow even on human timescales, and even when not running it as a snap (sigh).

      IMO these tools should strive to start quickly.

    • kelchm 8 hours ago
      Are you really suggesting that the choice to use Typescript wasn't a deliberate one?

      IMO -- it makes total sense within the existing Cloudflare tooling ecosystem.

      • slowin 8 hours ago
        Whether it was deliberate or not, I do not think it's a good choice. When agents can write in any language, there's no reason to pick the wrong tool for the job. At this point Javascript/Typescript belongs only in the browser. It's the suboptimal choice for every other environment. Especially for a command line tool. Even if the back-end is written in Typescript (also not the best choice imho), the clients need not be in the same language.
        • amluto 3 minutes ago
          Various agent tools (including current versions of codex-rs, which is otherwise with Rust program) make effective use of JavaScript/TypeScript for “code mode”. I actually think it’s an excellent choice for this use case. (I think that a less weird language with otherwise similar optimizers and tooling would be even better, but JS/TypeScript is what we have.)

          What would even be a good alternative? The language should have no ambient authority, be fully safe, run newly loaded code quickly, and be popular enough that current LLMs are good at it. I think the languages that fit the bill are JS/TypeScript and Lua.

        • chatmasta 8 hours ago
          Typescript and the npm/JS ecosystem may be complex, but you don’t need AGI to figure out how to install a CLI built with TS. My agent can figure out how to install this.
          • miki123211 5 hours ago
            Installation is not the problem.

            Javascript is plenty fast, but only if it has enough time to JIT the code and can keep it JITed in memory. For long-running backed services, it's plenty fast, for browser things, it's the only option, but for the command line, it adds needless startup time.

            Agents make this even worse because they don't have a "sense of time", so if they accidentally do something which causes startup time to increase dramatically, they won't feel it like a human dev would, and won't immediately start optimizing. Unless you have some specific benchmarks in CI that fail any PR which makes the code too slow, agents will just make things slower and slower.

          • slowin 8 hours ago
            It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.
            • isopede 6 hours ago
              Pretty much every modern language with a package repository is vulnerable to supply chain attacks.

              Are there any languages doing something unique or are especially resilient in this respect?

              • slowin 5 hours ago
                You can get a binary compiled by the author or a trusted source and none of the dependencies can change out from under you. This isn't possible with an interpreted language where the dependencies are resolved (often from dubious places like npm) at install and update time.
                • chatmasta 45 minutes ago
                  You can write a CLI in typescript and bundle it into a a single JS file. In fact (without looking) I’m sure that’s what Cloudflare is doing here because it’s standard practice.
      • xtajv 7 hours ago
        Code should be written for the user.
    • forty 6 hours ago
      There is no more code, there are only specs, apparently. So I guess it's a typescript spec so your agent can generate its own CLI, in optimized native assembly of your local CPU and customized to your needs ? ;)
    • MattyRad 1 hour ago
      `npm...` and then instant tab close. The total lack of self-awareness regarding how much they're asking us to infect our toolchain is hilarious. I mean, consider that agents can and should be containerized.... Like, that's what competent engineers- the target audience- are doing. It's just so completely tone-deaf.
    • squiffsquiff 8 hours ago
      AWS and GCP CLIs have been in Python for a decade or more. Last I checked Python was not a compiled language
      • xtajv 7 hours ago
        Raise your hand if you have been personally traumatized by the miniature standalone py3 distribution bundled within the aws cli.
      • slowin 7 hours ago
        I think these are both examples that help prove my point. Neither of these tools benefit the user by being in Python and distributing a runtime just for a CLI tool.
      • mjr00 7 hours ago
        Yeah, and they're terrible. If anything they're a prime example of what 100% should be written in a compiled language.
    • perching_aix 7 hours ago
      "Claude, rewrite this in amd64 and arm64 assembly. Optimize it to the max, and make no mistakes. Oh yeah, formally verify it while there, may as well."
      • cruffle_duffle 6 hours ago
        You laugh now but in 5 years when these LLM’s operate at thousands or tens of thousands of tokens per second on dedicated hardware in your phone… “might as well” won’t even be a joke.
        • iharuya 5 hours ago
          That still feels like chartering a helicopter for a 20-minute drive just because helicopters got cheaper and faster.
        • perching_aix 4 hours ago
          Oh, I'm not entirely sure I was joking. This is already well possible at this point, it's just goofy sounding.
    • slopinthebag 4 hours ago
      the point is probably to have a ts library as well for consumers, so it kind of makes sense.

      i'd probably write it in rust and expose ts bindings tho.

    • 827a 1 hour ago
      Wow, the first four comments are negative. Welcome to Hacker News everybody!
  • emadabdulrahim 7 hours ago
    It's crazy that some of the best product launches nowadays are CLIs.
    • fallinditch 7 hours ago
      Agreed. Cloudlflare appear to be innovating really well.
  • hackernud3s 3 hours ago
    It can do everything except make the token to give it permissions. For that you need to dig through their website to find the tokens section. Oh and they change where that lives every week.
    • jumploops 3 hours ago
      As bad as the AWS console UX is, at least it’s mostly additive/unchanging over time.

      I frequently hit strange UI bugs with Cloudflare workers, where I need to do a hard refresh to make things right.

  • creatonez 49 minutes ago
    Is this a joke? Why would you want to use a random word generator on production infrastructure configuration? Cloudflare should be blocking these malicious/incompetent users, not enabling them.
  • recroad 9 hours ago
    This is cool, but I've never had an issue with agents working on Cloudflare by just making REST calls. With the rest docs, it knows pretty much everything about what kind of operations it can do. Is the CLI a subset of that or does in encompass everything?
    • artdigital 1 hour ago
      Yes I am doing that too. I have a separate folder called ai/cloudflare. the AGENTS.md references the cf docs and instructs the agent to leave a change log + write down learnings whenever it does something

      It’s now so good that I cd into this folder and say things like “add this and that to this configuration” and the agent immediately knows how to do it

      I’m guessing cf just wraps the API into a CLI that’s easier to traverse and explore

    • verdverm 9 hours ago
      The actual title is

      > Introducing cf: the agentic CLI for the entire Cloudflare API

      emphasis my own to highlight the key word missing in the HN title

  • alasano 9 hours ago
    I don't know what it is about wrangler that made me dislike it so much but I welcome this change since it's meant to replace wrangler.
    • george_max 32 minutes ago
      It feels heavy, the emojis are overused, and it is probably the only CLI tool I've felt as "clunky". Maybe that and Claude Code TUI.
    • verdverm 9 hours ago
      re: wrangler, my biggest gripe was inconsistency between dev and prod
      • alasano 8 hours ago
        I think I may be confusing my annoyance with pages vs workers and agents that kept deploying to pages due to outdated training data.

        Wrangler still didn't feel great to use.

  • smithclay 9 hours ago
    This is a lot to like here as someone who pretty much exclusively uses the Cloudflare API via agents. Hoping (since it's built on top of Forge), some kind of native terraform support is also in the works.

    Great when you're a solo dev deploying a worker, but would be incredible for production deployments if this could also just natively output terraform code.

  • vamsiraju 4 hours ago
    "Our new configuration format is based on TypeScript" This is the most head scratching but interesting bit.
  • unified101 9 hours ago
    I think the shape of clouds and services is going to change given current clouds are uxed for humans. Cloudflare is making the right bet. Specially the free agent report account. That's like a wonderful idea for building agent share.
  • bhouston 4 hours ago
    Nice! I would recommend you support one of the opencli specs, like https://clidoc.dev so that it is fully discoverable with examples, etc.
  • esafak 8 hours ago
    1.0 isn't actually out and CI is red. https://github.com/cloudflare/cf/commits/main/ https://github.com/cloudflare/cf/releases

    I have been using the pre-releases with success, but this post could have waited a few days!

  • ozarkerD 7 hours ago
    Great now i have to uninstall the Cloudfoundry CLI to not collide with this :)
    • fragmede 6 hours ago
      helpful tip is to make use of single letter personal aliases. g=git c=cf or cf ;)
  • zarmin 6 hours ago
    so uh, the favicon for cloudflare and soundcloud are just the same thing now? soundcloudflare?
  • plainjar 2 hours ago
    [dead]
  • Solvyx 3 hours ago
    [flagged]
  • BigBalli 6 hours ago
    [dead]
  • verdverm 9 hours ago
    Kudos to cloudflare on this, it looks like a great CLI, I especially like the `cf cli search`.

    Related, Matt Pocock's skill for having agents generate an interactive bash script for things only humans can do (or should do), presented in the context of devops like activities

    https://github.com/mattpocock/skills/blob/main/skills/produc...

    I have found that having the agents write scripts to use tools like this is better (less tokens, more reliability, fewer side quests) than giving it to them directly with markdown they may or may not follow on any given day.

    The other benefit to this is that you can put scripts on either side of the agent and remove all credentials from their process, removing whole classes of issues you don't want to have to tell your boss about. CLIs like this are great for read-only debug sessions, but if you are going to make modifications to your cloud infra, keep doing IaC.