workers-best-practices

作成者: Cloudflare

Cloudflare Workersのコードをレビューし、本番環境のベストプラクティスに照らして作成します。新しいWorkersの作成時、Workerコードのレビュー時、wrangler.jsoncの設定時、または一般的なWorkersのアンチパターン(ストリーミング、フローティングプロミス、グローバルステート、シークレット、バインディング、可観測性)の確認時に読み込んでください。事前学習された知識よりもCloudflareのドキュメントからの取得を優先します。

npx skills add https://github.com/cloudflare/skills --skill workers-best-practices

Your knowledge of Cloudflare Workers APIs, types, and configuration may be outdated. Prefer retrieval over pre-training when writing or reviewing Workers code.

Use the project's installed versions, generated types, and Wrangler compatibility settings as the baseline for existing code. Retrieve relevant Cloudflare documentation to verify API, configuration, runtime behavior, and limit claims.

References

Read the sections relevant to the task:

ReferenceWhen to use it
Configuration and observabilityCompatibility dates, bindings, generated types, secrets, logs, and traces
Runtime patternsStreaming, promise lifetime, request state, service calls, security, and runtime tests
Platform API checksHandler signatures, platform classes, binding access, and serialization

For missing evidence, consult Workers best practices or find the affected product in the Cloudflare docs directory. Use the installed Wrangler schema for config fields. A newer type package does not supersede the project's configured target.

Keep Compatibility Dates Current

Use today's date for new Workers. Encourage periodic updates for existing Workers, reviewing compatibility changes and running relevant tests. Assess existing behavior against its configured date and flags; see compatibility guidance.

Enable Observability

Enable Workers Logs and Traces when creating or preparing a Worker for production. Set observability.enabled and observability.traces.enabled to true; the top-level setting alone does not enable traces. Use structured JSON logging and configure sampling for the workload. During reviews, flag missing logs or traces. See the configuration example.

Anti-Patterns to Flag

Anti-patternConsequence and preferred pattern
await response.text() or similar buffering on unbounded dataCan exhaust Worker memory; stream large or unbounded bodies.
Hardcoded secrets in source or configLeaks credentials through version control; use Wrangler secrets.
Math.random() for security-sensitive tokens or IDsPredictable values; use crypto.randomUUID() or crypto.getRandomValues().
Async work started without awaiting, returning, or attaching it to ctx.waitUntil()Work can be dropped and errors missed; tie it to the request or background-work lifetime.
Module-level mutable request stateLeaks data across requests and can cause I/O ownership errors; pass request state explicitly.
Cloudflare REST API calls for operations available through Worker bindingsAdds network and authentication overhead; use the available binding.
ctx.passThroughOnException() used as general error handlingCan conceal Worker failures by forwarding to the origin; use explicit error handling and structured error responses.
Hand-written Env that duplicates Wrangler bindingsCan drift from configuration; generate binding types with wrangler types.
Direct string comparison of secret valuesCan expose timing differences; use the Web Crypto comparison pattern.
Destructuring ctx methods, such as const { waitUntil } = ctxLoses the receiver; call ctx.waitUntil(...).
any on Env or handler parametersHides binding and handler contract errors; use the project's generated and platform types.
as unknown as T to force a platform type matchHides incompatibilities; fix the underlying contract.
implements used in place of extending a platform base classDoes not inherit runtime behavior, this.ctx, or this.env; use the appropriate base class.
Unbound env.X in a platform class methodBindings are available through this.env.X; see binding access patterns.
Applying one serialization rule across Queues, Workflow steps, storage, and WebSocketsCan reject valid payloads or accept unsupported ones; check the specific API and encoding.

Validation

Use the project's existing checks for affected Workers behavior: type-check binding or handler contract changes, and run relevant runtime tests for behavior changes. Preserve required repository checks; a narrow edit does not require a full Workers audit.

Scope

This skill covers Workers-specific best practices and code review. For related topics:

  • Durable Objects: load the durable-objects skill
  • Workflows: see Rules of Workflows
  • Wrangler CLI commands: load the wrangler skill

Cloudflareのその他のスキル

agents-sdk
Cloudflare
Cloudflare Workers上でAgents SDKを使用してAIエージェントを構築します。ステートフルなエージェント、耐久性のあるワークフロー、リアルタイムWebSocketアプリ、スケジュールタスク、MCPサーバー、チャットアプリケーションを作成する際に読み込んでください。Agentクラス、状態管理、呼び出し可能RPC、Workflows統合、Reactフックをカバーします。
building-ai-agent-on-cloudflare
Cloudflare
| Cloudflare上でAIエージェントを構築します。Agents SDKを使用し、状態管理、リアルタイムWebSocket、スケジュールタスク、ツール統合、チャット機能を備え、Workersにデプロイ可能なプロダクション対応のエージェントコードを生成します。 使用するタイミング: ユーザーが「エージェントを構築」「AIエージェント」「チャットエージェント」「ステートフルエージェント」を希望する場合、「Agents SDK」に言及する場合、「リアルタイムAI」「WebSocket AI」が必要な場合、またはエージェントの「状態管理」「スケジュールタスク」「ツール呼び出し」について質問する場合。
development
building-mcp-server-on-cloudflare
Cloudflare
Cloudflare Workers上でツール、OAuth認証、本番デプロイを備えたリモートMCP(Model Context Protocol)サーバーを構築します。サーバーコードの生成、認証プロバイダーの設定、Workersへのデプロイを行います。 使用タイミング: ユーザーが「MCPサーバーを構築」「MCPツールを作成」「リモートMCP」「MCPをデプロイ」「MCPにOAuthを追加」、またはCloudflare上のModel Context Protocolについて言及した場合。また、「MCP認証」や「MCPデプロイ」にも反応します。
development
cloudflare
Cloudflare
Cloudflareプラットフォームに関する包括的なスキル。Workers、Pages、ストレージ(KV、D1、R2)、AI(Workers AI、Vectorize、Agents SDK)、ネットワーキング(Tunnel、Spectrum)、セキュリティ(WAF、DDoS)、およびインフラストラクチャ・アズ・コード(Terraform、Pulumi)をカバー。あらゆるCloudflare開発タスクに使用可能。
durable-objects
Cloudflare
Cloudflare Durable Objectsを作成・レビューします。ステートフルな連携(チャットルーム、マルチプレイヤーゲーム、予約システム)の構築時、RPCメソッド、SQLiteストレージ、アラーム、WebSocketの実装時、またはDOコードのベストプラクティス確認時に使用します。Workers統合、wrangler設定、Vitestを使ったテストをカバーします。
sandbox-sdk
Cloudflare
サンドボックス化されたアプリケーションを構築し、安全なコード実行を実現します。AIコード実行、コードインタプリタ、CI/CDシステム、インタラクティブな開発環境、または信頼できないコードの実行時にロードしてください。Sandbox SDKのライフサイクル、コマンド、ファイル、コードインタプリタ、プレビューURLをカバーします。
web-perf
Cloudflare
Chrome DevTools MCPを使用してウェブパフォーマンスを分析します。Core Web Vitals(FCP、LCP、TBT、CLS、Speed Index)を測定し、レンダリングをブロックするリソース、ネットワーク依存関係チェーン、レイアウトシフト、キャッシュ問題、アクセシビリティのギャップを特定します。ページ読み込みパフォーマンス、Lighthouseスコア、サイト速度の監査、プロファイリング、デバッグ、最適化を求められた際に使用します。
wrangler
Cloudflare
Cloudflare Workers CLIを使用して、Workers、KV、R2、D1、Vectorize、Hyperdrive、Workers AI、Containers、Queues、Workflows、Pipelines、Secrets Storeのデプロイ、開発、管理を行います。wranglerコマンドを実行する前にロードして、正しい構文とベストプラクティスを確保します。