Cf: The Agentic CLI for the Cloudflare API

(blog.cloudflare.com)

69 points | by macleos 5 hours ago ago

32 comments

  • slowin 3 hours ago

    I don't understand why this is written in Typescript. This is a great example of how agents can write code (I'm sure they wrote `cf`), yet having fundamental computer science knowledge is still critical. Do not force your users to manage the dependencies of your cli. Do write your cli in a compiled language. Understand the reason for those decisions and tell your agents to use the correct architecture.

    • geodel an hour ago

      No it is exactly right mode for modern tech companies:

      1) If it runs on my dime and my infrastructure I will optimize the hell out using most cleverly written Rust and what not and gloat about engineering prowess.

      2) If it runs on users computers well then, we have carefully evaluated our strategic direction and come to conclusion that JS/TS/Electron option is the best way to go.

      • cschmatzler an hour ago

        This is also not correct in this case since they recently rewrote the Artifacts backend from Zig to TypeScript.

    • tcdent 2 hours ago

      My read is that it's generally the teams that have been assigned to build a certain product that end up choosing the architecture that it runs on. So when we see TypeScript involved in TUI and CLI applications, most of it is just a repurposing of skill sets from that domain into the terminal. In an organization like Cloudflare, I expect that the developers who don't specialize in TypeScript are working on far more important problems.

    • cush 16 minutes ago

      Seriously there’s zero benefit to be writing CLIs in typescript in 2026

    • kelchm 2 hours ago

      Are you really suggesting that the choice to use Typescript wasn't a deliberate one?

      IMO -- it makes total sense within the existing Cloudflare tooling ecosystem.

      • slowin 2 hours ago

        Whether it was deliberate or not, I do not think it's a good choice. When agents can write in any language, there's no reason to pick the wrong tool for the job. At this point Javascript/Typescript belongs only in the browser. It's the suboptimal choice for every other environment. Especially for a command line tool. Even if the back-end is written in Typescript (also not the best choice imho), the clients need not be in the same language.

        • chatmasta 2 hours ago

          Typescript and the npm/JS ecosystem may be complex, but you don’t need AGI to figure out how to install a CLI built with TS. My agent can figure out how to install this.

          • slowin 2 hours ago

            It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.

            • isopede 31 minutes ago

              Pretty much every modern language with a package repository is vulnerable to supply chain attacks.

              Are there any languages doing something unique or are especially resilient in this respect?

      • xtajv an hour ago

        Code should be written for the user.

    • squiffsquiff 2 hours ago

      AWS and GCP CLIs have been in Python for a decade or more. Last I checked Python was not a compiled language

      • xtajv an hour ago

        Raise your hand if you have been personally traumatized by the miniature standalone py3 distribution bundled within the aws cli.

      • mjr00 an hour ago

        Yeah, and they're terrible. If anything they're a prime example of what 100% should be written in a compiled language.

      • slowin an hour ago

        I think these are both examples that help prove my point. Neither of these tools benefit the user by being in Python and distributing a runtime just for a CLI tool.

    • perching_aix 2 hours ago

      "Claude, rewrite this in amd64 and arm64 assembly. Optimize it to the max, and make no mistakes. Oh yeah, formally verify it while there, may as well."

  • emadabdulrahim an hour ago

    It's crazy that some of the best product launches nowadays are CLIs.

    • fallinditch an hour ago

      Agreed. Cloudlflare appear to be innovating really well.

  • alasano 3 hours ago

    I don't know what it is about wrangler that made me dislike it so much but I welcome this change since it's meant to replace wrangler.

    • verdverm 3 hours ago

      re: wrangler, my biggest gripe was inconsistency between dev and prod

      • alasano 3 hours ago

        I think I may be confusing my annoyance with pages vs workers and agents that kept deploying to pages due to outdated training data.

        Wrangler still didn't feel great to use.

  • smithclay 3 hours ago

    This is a lot to like here as someone who pretty much exclusively uses the Cloudflare API via agents. Hoping (since it's built on top of Forge), some kind of native terraform support is also in the works.

    Great when you're a solo dev deploying a worker, but would be incredible for production deployments if this could also just natively output terraform code.

  • recroad 3 hours ago

    This is cool, but I've never had an issue with agents working on Cloudflare by just making REST calls. With the rest docs, it knows pretty much everything about what kind of operations it can do. Is the CLI a subset of that or does in encompass everything?

    • verdverm 3 hours ago

      The actual title is

      > Introducing cf: the agentic CLI for the entire Cloudflare API

      emphasis my own to highlight the key word missing in the HN title

  • unified101 3 hours ago

    I think the shape of clouds and services is going to change given current clouds are uxed for humans. Cloudflare is making the right bet. Specially the free agent report account. That's like a wonderful idea for building agent share.

  • esafak 3 hours ago

    1.0 isn't actually out and CI is red. https://github.com/cloudflare/cf/commits/main/ https://github.com/cloudflare/cf/releases

    I have been using the pre-releases with success, but this post could have waited a few days!

  • ozarkerD an hour ago

    Great now i have to uninstall the Cloudfoundry CLI to not collide with this :)

    • fragmede 17 minutes ago

      helpful tip is to make use of single letter personal aliases. g=git c=cf or cf ;)

  • zarmin 20 minutes ago

    so uh, the favicon for cloudflare and soundcloud are just the same thing now? soundcloudflare?

  • verdverm 3 hours ago

    Kudos to cloudflare on this, it looks like a great CLI, I especially like the `cf cli search`.

    Related, Matt Pocock's skill for having agents generate an interactive bash script for things only humans can do (or should do), presented in the context of devops like activities

    https://github.com/mattpocock/skills/blob/main/skills/produc...

    I have found that having the agents write scripts to use tools like this is better (less tokens, more reliability, fewer side quests) than giving it to them directly with markdown they may or may not follow on any given day.

    The other benefit to this is that you can put scripts on either side of the agent and remove all credentials from their process, removing whole classes of issues you don't want to have to tell your boss about. CLIs like this are great for read-only debug sessions, but if you are going to make modifications to your cloud infra, keep doing IaC.