Cloudflare OS: The AI-Powered Company Operating System Explained
![]() |
| Cloudflare OS AI agents company operating system Cloudflare Workers |
Artificial intelligence is changing the way companies build software, manage information and complete everyday work.
But what if AI was not just another chatbot sitting inside a browser?
What if an entire company could have an AI-powered workspace where agents could build applications, work with company information, create documents and interact with business systems — while operating inside carefully controlled security boundaries?
That is the idea behind Cloudflare OS.
Cloudflare OS is an open-source AI productivity environment built on Cloudflare Workers. It combines AI agents, sandboxed applications, company context and security controls into one platform. Cloudflare describes it as an "operating system" for AI productivity and AI workloads rather than a traditional computer operating system.
The project was originally developed for use inside Cloudflare and is now available as open-source software so organisations can customise the concept for their own needs.
In simple terms, the vision is:
Turn AI prompts into useful private applications — while keeping control over data, permissions and external connections.
What Is Cloudflare OS?
Cloudflare OS is an AI productivity environment designed around three major ideas:
AI agents that can perform tasks
Sandboxed applications called Gadgets
A security framework called Gatekeepers
The official repository says Cloudflare OS provides an agent chat interface, sandboxed application development and a security framework that applies guardrails to agents and applications.
This makes it very different from a normal chatbot.
Instead of simply asking an AI to write some text, you can ask the system to create an application and then continue working with that application.
For example, you could ask it to:
Create a presentation
Build a dashboard
Make a collaborative whiteboard
Create a small game
Build an internal company tool
Analyse information from connected services
The important part is that the AI can create actual working software rather than only returning a block of text.
Why Is Cloudflare OS Different?
There are already hundreds of AI assistants available.
So why is Cloudflare OS interesting?
The answer is its architecture.
Cloudflare is trying to combine AI agents + applications + company context + security + cloud infrastructure into one environment.
Instead of thinking:
"I have an AI chatbot."
Cloudflare wants organisations to think:
"I have an AI-powered workspace where my employees and AI agents can safely create and use software."
That is a much bigger idea.
It Is Not a Traditional Operating System
The name "Cloudflare OS" can be slightly confusing.
It does not replace Windows, macOS or Linux.
You cannot install it on your laptop and use it like a traditional desktop operating system.
Cloudflare uses the word "operating system" because the platform manages AI workloads, applications, users, permissions and external services in a way that is conceptually similar to an operating system.
Cloudflare's own architecture documentation even compares components of the platform with traditional operating-system concepts such as kernels, processes, device drivers and permissions.
AI Agents as First-Class Workers
Traditional operating systems were designed around users and programs.
Cloudflare OS adds another important component:
AI agents.
The project's architecture treats agents as entities that should have their own restricted permissions rather than simply being treated as ordinary users.
This is important because an AI agent may be capable of writing code, executing code and interacting with external services.
Giving such an agent unrestricted access would obviously be dangerous.
Cloudflare OS therefore focuses heavily on controlling what an agent is allowed to do.
How Cloudflare OS Works
Cloudflare OS revolves around several important components.
The easiest way to understand them is to think about them as members of a virtual technology ecosystem.
Agents perform work.
Gadgets are the applications those agents can create.
Gatekeepers control connections to external services.
Cloudflare Workers provide the underlying execution environment.
Together, these components create the Cloudflare OS architecture.
Gadgets: AI-Built Applications
One of the most interesting concepts in Cloudflare OS is the Gadget.
A Gadget is essentially a small application created for a user.
Imagine asking:
"Build me a dashboard showing my project's tasks."
Instead of receiving only HTML or JavaScript in the chat, the AI can create an actual application inside the Cloudflare OS environment.
You can then interact with that application.
Even more interestingly, you can continue asking the AI to modify it.
For example:
"Add a search box."
Then:
"Add a chart showing completed tasks."
Then:
"Change the layout for mobile."
This creates a continuous loop:
Prompt → Application → Test → Modify → Improve
Cloudflare describes Gadgets as private application instances that run in their own sandbox.
Why Gadget Sandboxing Matters
Suppose an AI creates a small application.
What happens if that application contains a security bug?
In a traditional environment, a vulnerable application could potentially access resources it should not.
Cloudflare OS uses sandboxing to isolate Gadgets.
The goal is to ensure that a Gadget cannot freely access another user's information or unrelated resources.
This is one of the key security ideas behind the project.
Gatekeepers: The Security Layer
Another important component is the Gatekeeper system.
Gatekeepers act as controlled intermediaries between agents or applications and external services.
For example, suppose an AI agent needs to interact with:
GitHub
Google
Slack
Notion
Cloudflare
Supabase
Spotify
ZoomInfo
Instead of allowing the agent unrestricted network access, the relevant Gatekeeper can control the interaction.
The current project includes Gatekeeper packages for several external services, including GitHub, Google, Cloudflare, Supabase, Notion, Confluence, Slack and others.
This is a powerful idea because it creates a defined boundary between AI agents and external systems.
Human Approval
Gatekeepers can also support human approval workflows.
This means an AI agent does not necessarily have to be allowed to perform every sensitive action automatically.
Instead, the system can ask a human for approval when required.
This is especially useful for businesses.
Imagine an AI agent preparing an email campaign.
Creating the draft may be automatic.
Sending thousands of emails should probably require additional controls.
That distinction is exactly where capability-based permissions and approval workflows become valuable.
AI Agents in Cloudflare OS
The agent is the component that performs the actual work.
Cloudflare OS includes a multi-purpose coding agent capable of writing, executing, testing and debugging code in its Code Mode.
The platform is also designed to work with different large language model providers.
This means the system is not conceptually tied to only one AI model.
The architecture can support providers such as OpenAI, Anthropic and self-hosted models, depending on configuration.
This is useful for companies that want more flexibility over which AI models they use.
What Can You Build With Cloudflare OS?
This is probably the most exciting part for ordinary users.
Cloudflare OS is designed around natural-language interaction.
Instead of starting by writing code manually, you can describe what you want.
Create Presentations
For example:
"Make slides for my upcoming meeting with a customer."
Cloudflare OS includes a built-in slides blueprint that can be used for this type of task.
The important difference is that the AI is not merely writing a paragraph about the presentation.
It can create an application or document workflow around the request.
Build Collaborative Apps
You can also ask the system to create an application from scratch.
For example:
"Make a collaborative whiteboard app."
This is a good demonstration of the larger Cloudflare OS idea.
A user describes an application in natural language and an AI agent builds it.
Create Games
You can even use the platform for small interactive applications.
The official README gives a tic-tac-toe example:
"Make a tic tac toe game."
You can then continue interacting with the application through natural language.
This shows that Cloudflare OS is not limited to traditional office documents.
Build GitHub Dashboards
Cloudflare OS can also work with external services when the relevant integration has been configured.
For example:
"Make an issue dashboard for this GitHub repository."
The GitHub integration is required for this workflow.
This could be particularly useful for development teams that want custom internal dashboards without spending days building them manually.
Work With Google Documents
Another example provided by Cloudflare is:
"Fix the typos in this Google Doc."
Again, the Google integration needs to be configured.
This demonstrates how Gatekeepers can connect AI agents to external business systems while maintaining a controlled permission model.
Cloudflare OS and Company Context
One of the most important parts of Cloudflare OS is company context.
A generic AI assistant may know a lot about the world but know very little about your company.
Your organisation may have:
Internal terminology
Company policies
Product information
Customer information
Internal processes
Documentation
Private systems
Cloudflare OS is designed to connect agents with a company's context and systems.
This is what transforms a generic AI assistant into something closer to an organisation-specific AI workspace.
The ultimate vision is not simply to use Cloudflare's own setup.
Cloudflare describes the project as something organisations can copy and customise into their own "Your Company OS."
How Gatekeepers Improve Security
Security is arguably the most important part of Cloudflare OS.
Giving AI agents access to company systems without restrictions would create obvious risks.
An AI agent could potentially:
Read sensitive information
Modify records
Send messages
Execute code
Access APIs
Make changes to external systems
Cloudflare's approach is to put controlled boundaries around these capabilities.
Gatekeepers mediate external service access, while sandboxing limits what applications can access.
This creates a security model in which the AI agent does not automatically receive unlimited authority.
Cloudflare Workers Architecture
Cloudflare OS is built on Cloudflare Workers, making the project particularly interesting for developers who follow the Workers ecosystem.
The project makes extensive use of technologies such as:
Durable Objects
Dynamic Workers
Facets
Workers runtime features
Workerd
Cloudflare says the platform was built by the Workers team and uses some Workers Runtime features that were developed specifically to support Cloudflare OS.
Durable Objects
Cloudflare OS uses Durable Objects for workspace-related state.
In simple terms, Durable Objects provide a way to maintain strongly consistent state associated with individual objects or users.
This makes them useful for collaborative and stateful applications.
Dynamic Workers and Facets
Cloudflare OS also makes extensive use of Dynamic Workers and Facets.
The architecture uses these capabilities to isolate and run Gadgets and Gatekeepers.
This is an interesting demonstration of what modern Cloudflare Workers infrastructure can be used for beyond conventional request-response applications.
Workerd
Another interesting component is workerd, Cloudflare's open-source Workers runtime.
Cloudflare OS can run on workerd, although the project currently describes self-hosted production deployment documentation as still being developed.
This means the architecture is not conceptually limited to the hosted Cloudflare environment.
How to Run Cloudflare OS Locally
Developers can experiment with Cloudflare OS on their own computer.
The current repository provides a quick local setup using pnpm.
Install pnpm
First, make sure pnpm is installed on your system.
The repository currently specifies pnpm 11.17.0 in its package configuration.
Run the Local Environment
After cloning the repository and installing dependencies, the quick-start command is:
pnpm installThen run:
pnpm run-localThe official README says this runs the complete local stack using Wrangler and workerd.
Open Cloudflare OS
Once the local environment is running, open:
http://localhost:8787You should then be able to explore the Cloudflare OS interface locally.
Keep in mind that Cloudflare explicitly describes this local setup as a way to try the product and not as the recommended production deployment method.
Deploy Cloudflare OS to Your Cloudflare Account
Cloudflare also provides an online deployment flow for users who want to deploy Cloudflare OS to their own Cloudflare account.
There is also a separate cloudflare-os-starter repository for organisations that need more sophisticated customisation, such as branding, authentication, integrations, routes and upgrades.
The starter project is designed around pinned Cloudflare OS releases and gives organisations greater control over their deployment.
However, the project currently warns that Cloudflare OS is early-access software.
That means businesses should test carefully before relying on it for critical production workloads.
Who Should Use Cloudflare OS?
Cloudflare OS is particularly interesting for organisations that want to experiment with AI agents while maintaining strong control over security and data.
Engineering Teams
Engineering teams can use AI agents to build internal tools, dashboards and prototypes.
Instead of waiting for a developer to build a small internal application, a team member could describe the requirement and let an AI agent create the first version.
Product and Operations Teams
Product and operations teams frequently need small tools.
Examples include:
Dashboards
Trackers
Planning tools
Whiteboards
Reporting interfaces
Internal utilities
Cloudflare OS aims to make creating these applications much faster.
Security-Focused Organisations
Companies that are cautious about giving AI access to internal systems may find the Gatekeeper and sandboxing concepts particularly interesting.
The platform is designed around controlled capabilities rather than unrestricted AI access.
Cloudflare Developers
Developers interested in Cloudflare Workers can also learn a lot from the architecture.
The project provides a real-world example of Durable Objects, Dynamic Workers, Facets and other Workers technologies being combined into a complex AI platform.
Advantages of Cloudflare OS
There are several major advantages to the Cloudflare OS approach.
AI-Native Application Building
You can describe an application in natural language and let an AI agent build it.
Sandboxed Gadgets
Applications run in isolated environments designed to reduce the risk of one application affecting another.
Controlled External Access
Gatekeepers provide a structured way to connect agents to external services.
Company Context
The platform is designed to work with an organisation's own information and systems.
Flexible AI Models
The architecture is designed to support different LLM providers rather than locking the concept to a single model.
Cloudflare Workers Infrastructure
The platform benefits from Cloudflare's modern serverless and edge-computing infrastructure.
Limitations and Early Access Status
Cloudflare OS is exciting, but it is important to keep expectations realistic.
The official repository currently labels the project early access and warns that it is under heavy development. Cloudflare describes version 2 as a complete rewrite and acknowledges that there are still rough edges.
That means this is not necessarily a finished enterprise product that every organisation should immediately deploy.
Companies should test:
Security boundaries
Authentication
Data handling
Integrations
AI behaviour
Application isolation
Costs
Reliability
before putting important workloads into the platform.
Is Cloudflare OS Open Source?
Yes.
The Cloudflare OS repository is publicly available on GitHub and is released under the Apache-2.0 licence.
This is significant because organisations can inspect the implementation and customise the platform according to their requirements, subject to the licence.
Cloudflare's separate starter repository is specifically designed to help organisations customise their deployments.
Why Cloudflare OS Matters
The biggest idea behind Cloudflare OS is not simply another AI chatbot.
It represents a possible future where companies build their own AI-powered software environments.
Imagine an employee saying:
**"Build me a dashboard for today's sales."
The AI creates the dashboard.
Then the employee says:
**"Connect it to our CRM."
The system asks for the appropriate permission.
After approval, the dashboard connects to the approved service.
Then the employee says:
**"Add a weekly report."
The AI modifies the application.
This is very different from traditional software development.
Instead of every small tool requiring a developer, AI could allow employees to create specialised software themselves — while security controls determine what the software and AI agents are allowed to access.
Cloudflare OS vs Traditional SaaS
Traditional SaaS generally works like this:
Company → SaaS provider → Shared application
Cloudflare OS is moving toward a different model:
Company → AI agent → Private Gadget → Controlled integrations
That could change how internal software is created.
Instead of purchasing a separate SaaS product for every small workflow, companies could potentially build their own small applications when required.
Of course, this approach also creates new responsibilities around security, maintenance and governance.
Final Verdict
Cloudflare OS is one of the more interesting open-source AI projects to watch right now.
Its biggest idea is simple but powerful:
AI should not only answer questions — it should be able to safely build and operate software.
The combination of AI agents, Gadgets, Gatekeepers, sandboxing and Cloudflare Workers creates an architecture aimed at turning natural-language instructions into working applications.
For developers, it offers an interesting look at the future of AI-native software development.
For businesses, it presents a possible model for building private internal applications without giving AI unrestricted access to company systems.
And for Cloudflare Workers developers, the project provides a fascinating real-world example of what the Workers platform can do.
The project is still in early access, so it should be approached as an evolving technology rather than a finished replacement for every enterprise software system.
But the direction is compelling.
The future may not simply be:
"Open an AI chatbot and ask a question."
It could be:
"Tell your company's AI what you need — and let it build the software for you, safely."
Explore Cloudflare OS on GitHub
Frequently Asked Questions
1. What is Cloudflare OS?
Cloudflare OS is an open-source AI productivity environment built on Cloudflare Workers. It allows users to interact with AI agents, create sandboxed applications called Gadgets and connect to external services through controlled Gatekeepers.
2. Is Cloudflare OS a replacement for Windows or Linux?
No. Cloudflare OS is not a traditional desktop operating system. The name refers to its role as an operating environment for AI workloads, applications, users and company productivity.
3. What are Gadgets in Cloudflare OS?
Gadgets are small applications that AI agents can create for users. Each Gadget runs in a sandboxed environment and can be modified or extended with AI assistance.
4. What are Gatekeepers in Cloudflare OS?
Gatekeepers are security and integration components that control how agents and applications communicate with external services. They can handle authentication, permissions and controlled access to services such as GitHub, Google, Slack and other platforms.
5. Is Cloudflare OS ready for production use?
Cloudflare currently describes Cloudflare OS as early-access software that is still under heavy development. Organisations should thoroughly test security, reliability, integrations and data handling before using it for critical production workloads.
Conclusion
Cloudflare OS gives us a glimpse of a very different future for workplace software.
Instead of buying or manually developing every small application, employees could describe what they need and allow AI agents to build it.
The key difference is that Cloudflare is not ignoring security in this model.
With Gadgets, Gatekeepers, sandboxing, capability-based permissions and Cloudflare Workers, the project is attempting to create an environment where AI can be productive without receiving unlimited access to everything.
That makes cloudflare/cloudflare-os a GitHub project worth watching — especially if you are interested in AI agents, enterprise automation, Cloudflare Workers or the future of software development.
Cloudflare OS could be an early glimpse of the "company operating system" of the AI era.


No comments:
Post a Comment