Maestro Briefby Maestro Mojo

Cloudflare Built a CLI for Coding Agents. The Safety Feature Is Dry Run.

Maestro Brief · Published by Maestro Mojo

2026-10-01

Maestro’s take. Cloudflare’s new cf CLI is a useful blueprint for tools built for coding agents. The clever part is not thousands of commands. It is letting an agent find, inspect, and preview many commands before it changes anything.

Cloudflare released cf in open beta on September 28. It is a new command-line interface for Cloudflare’s API. Cloudflare says it exposes more than 2,900 commands, compared with roughly 280 operations in Wrangler.

That sounds like a bigger toolbox. For an AI agent, the more important change is predictability. According to Cloudflare’s agent documentation, cf returns JSON by default, separates machine output from human messages, lets the agent search commands locally, exposes schemas for generated API commands, and can preview many API requests with --dry-run.

TL;DR

What changed

Wrangler was designed around Cloudflare developer workflows: build a Worker, run it locally, deploy it, and manage common resources.

cf is broader. It maps Cloudflare’s public API into a large command tree. An agent can search that tree, inspect the expected input for generated API commands, run a command, and parse structured output.

In plain English, the agent has fewer reasons to guess.

A developer can ask an agent to create a D1 database in an isolated test account. The agent can first discover the command:

cf cli search "create D1 database"

Then inspect the generated API command’s input and output shape:

cf schema d1 create

Then check the command’s help and, when supported, preview the actual API request:

cf d1 create --help
cf d1 create --name my-database --dry-run

Only after the preview matches the request should the real command run. If the command has no dry-run option, keep it approval-gated or test it only in the isolated account.

Do this

Do not do this

A safer agent instruction

Do not say:

Set up Cloudflare for this app and deploy it.

Say:

Use the cf CLI only in the isolated test account and only with the least-privilege token already provided. Search for the needed command and read --help. For generated API commands, inspect the schema. When supported, run --dry-run first. Show me the proposed request and explain every resource it will create, change, or delete. Do not deploy, delete, change DNS, reveal or rotate secrets, enable paid services, or use --force without my approval. After an approved command, query the resource again and return the resulting JSON as evidence.

That instruction separates discovery, preview, approval, action, and verification.

Why Maestro users care

An agent can waste time and tokens when it has to search web documentation, guess flags, parse decorative terminal text, and retry errors. A discoverable CLI with schemas and structured output should reduce some of that friction.

That is a design inference, not a measured result. Cloudflare has published its own usage telemetry and product behavior, but no independent reliability or token-savings benchmark for cf is cited here.

The tool also gives one process a large surface area. The cost of a wrong instruction can grow from a failed command to changed infrastructure.

The useful pattern is simple: give the agent a tool it can understand, a credential with limited reach, and a required preview when the command supports one.

Should you replace Wrangler?

Not yet by default.

Use Wrangler for a production project that already depends on it. Try cf in an isolated test account when an agent needs API coverage beyond Wrangler.

If you choose to migrate, commit or stash your work first. Run Cloudflare’s migration dry run, inspect the generated configuration and any TODO comments, then test the project before changing production workflows.

Cloudflare says Wrangler will receive maintenance support for 18 months after cf leaves beta. The clock has not started while cf remains in open beta.

One thing to try

Give a coding agent access to an isolated test account and one harmless job: list that account’s D1 databases with cf.

Require it to find the command with cf cli search, read --help, run the command, and return the JSON result. If it cannot explain each step, do not expand its permissions.

The bottom line

Cloudflare did not make infrastructure safe for autonomous agents. It made its command line easier for agents to understand.

That matters. The winning workflow is still not “let the agent run everything.” It is “let the agent discover and preview where possible, then prove what happened.”

Sources considered

Published October 1, 2026 · Tags: Cloudflare, Developer Tools, Coding Agents, CLI, DevOps

MarkdownOpen in ClaudeOpen in ChatGPT