Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@ Tooling and guardrails:

Tests and documentation:

- Add a repeatable read-only account audit to `docs/security/FREE_TIER.md` that verifies the account holds only the Worker and its rate-limit binding, with the results from production v0.7.0.
- Add HTTP invariant property tests that assert bounded statuses, security headers, valid envelopes, no reflection of any request input, HEAD parity with GET, and fail-closed rate limiting across generated requests, plus full category and level coverage over HTTP.
- Extend `docs/DOCTRINE.md` with sections 21 to 24 (cost is a security property, the contract is the product, learning tools stay outside the production boundary, plain current documentation), tighten the testing, privacy, and agent rules, and bring the release gate list in line with `npm run verify`.
- Improve the repository page: a docs index (`docs/README.md`), a guide to studying an API call end to end with free tools (`docs/LEARNING.md`), a roast submission issue form, security and docs contact links, a social preview image, and README badges, navigation, and cost section. Document the `lab/` boundary and the request-boundary invariant in `docs/ARCHITECTURE.md`.
Expand Down
1 change: 1 addition & 0 deletions docs/security/CLOUDFLARE.md
Original file line number Diff line number Diff line change
Expand Up @@ -112,6 +112,7 @@ Before a public launch:
- Local Wrangler OAuth credentials are stored through macOS Keychain or an equivalently protected mechanism.
- No Global API Key is exposed in shell configuration, repository files, CI, or logs.
- Worker secret list is empty.
- The account holds no other resources; see the audit in `FREE_TIER.md`, and confirm the plan reads Free in the dashboard.
- Preview URLs remain disabled.
- Workers Logs remain enabled at 25 percent head sampling and traces remain enabled at 1 percent head sampling.
- No custom application logging or external telemetry destination is present.
Expand Down
31 changes: 31 additions & 0 deletions docs/security/FREE_TIER.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,6 +59,37 @@ Headroom is large. Even at 100 percent log sampling the worst case is about 110,

The Free plan allows 10 ms of CPU per invocation. A live `wrangler tail` of production v0.7.0 on 2026-09-18 recorded `cpuTime` of 0 to 1 ms and `wallTime` of 1 to 2 ms for four requests covering a success, a validation error, and a 404. This is a small sample at whole-millisecond resolution, so read it as an order of magnitude, roughly a tenfold margin, not as a guarantee. Re-measure after a release that changes request handling.

## Verify the account matches the boundary

These read-only commands check that the account holds nothing beyond the one Worker and its rate-limit binding. Run them from a maintainer machine with an authenticated Wrangler.

```bash
npx --no-install wrangler kv namespace list
npx --no-install wrangler d1 list --json
npx --no-install wrangler r2 bucket list
npx --no-install wrangler queues list
npx --no-install wrangler vectorize list
npx --no-install wrangler hyperdrive list
npx --no-install wrangler secrets-store store list --remote
npx --no-install wrangler secret list --config ./wrangler.jsonc --format json
npx --no-install wrangler versions view "$LIVE_VERSION_ID" --config ./wrangler.jsonc --json
```

Expected results:

| Command | Expected |
| --- | --- |
| `kv namespace list`, `d1 list` | `[]` |
| `r2 bucket list` | An error saying R2 is not enabled (code 10042). Enabling R2 is a billable-risk decision, see the catalog above |
| `queues list`, `hyperdrive list`, `vectorize list` | No entries |
| `secrets-store store list --remote` | No stores |
| `secret list` | `[]` |
| `versions view` | A single `ratelimit` binding named `RATE_LIMITER`, a `fetch` handler, and the compatibility date and flags from `wrangler.jsonc` |

Last verified 2026-09-18 against production v0.7.0: every result matched.

Two facts cannot be read with Wrangler and need the Cloudflare dashboard: the plan (Workers and Pages, then Plans, must read Free) and the live non-versioned observability settings (the Worker's Observability settings must show the sampling rates in `wrangler.jsonc`). Record both when a release changes them.

## Adding a free resource

A new binding is a one-way door under DOCTRINE section 18. Before the change:
Expand Down
Loading