Skip to content

feat: add a read-only Cloudflare account audit script - #43

Merged
codethor0 merged 1 commit into
mainfrom
chore/cloudflare-audit-script
Sep 19, 2026
Merged

codethor0 merged 1 commit into
mainfrom
chore/cloudflare-audit-script

Conversation

@codethor0

Copy link
Copy Markdown
Owner

Goal

Automate the account audit so the no-charge boundary can be verified with one command, and make the two facts that need a person (the plan and the live observability settings) one click away.

Scope / non-goals

Added scripts/cloudflare-audit.mjs. It runs Wrangler's own read-only list and view commands and checks:

  • no KV, D1, Queues, Vectorize, Hyperdrive, or Secrets Store resources, and no Worker secrets;
  • R2 is not enabled;
  • exactly one Worker version at 100 percent;
  • the live version's bindings, compatibility date and flags, and handlers match wrangler.jsonc.

--open opens the plan page and the Worker settings page in the default browser. Docs (FREE_TIER.md, CLOUDFLARE.md) and the changelog now point to it.

Deliberately not done: reading the plan or observability settings through the API. The plan needs a Billing Read token, which this project does not create, and I did not extract the Wrangler OAuth token to try. The script uses only Wrangler's own commands, never reads or prints a token, calls no Cloudflare API itself, and changes nothing on the account.

Public contract

None. Not part of the Worker bundle.

Security impact

  • No new secret or credential handling
  • No new outbound network access
  • No new persistence or user data
  • No new runtime dependency
  • Threat model updated if attack surface changed -- unchanged

Verification

  • Tests added or updated when behavior changed -- run against production v0.7.0 (12 of 12 pass) and negatively tested by mismatching wrangler.jsonc, which fails two checks and exits 1
  • npm run verify (the script is linted; the policy check confirms the documented path exists)
  • git diff --check
  • Public docs and OpenAPI updated if behavior changed
  • Change is intentionally scoped and contains no unrelated cleanup

🤖 Generated with Claude Code

scripts/cloudflare-audit.mjs runs Wrangler's own read-only list and view
commands and checks the account against the free-tier boundary: no KV, D1,
Queues, Vectorize, Hyperdrive, or Secrets Store resources, no secrets, R2
not enabled, exactly one Worker version at 100 percent, and live bindings,
compatibility settings, and handlers matching wrangler.jsonc.

It uses the existing Wrangler login, never reads or prints a token, calls no
Cloudflare API itself, and changes nothing. With --open it opens the two
dashboard pages that only a person can read (the plan and the live
observability settings). Exit code is 1 on any failure.

Verified against production v0.7.0 (12 of 12 pass) and negatively tested by
mismatching the config, which fails two checks and exits 1.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@codethor0
codethor0 merged commit 29a0a0f into main Sep 19, 2026
5 checks passed
@codethor0
codethor0 deleted the chore/cloudflare-audit-script branch September 19, 2026 14:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant