Rendered at 08:54:05 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
slowin 15 hours ago [-]
I don't understand why this is written in Typescript. This is a great example of how agents can write code (I'm sure they wrote `cf`), yet having fundamental computer science knowledge is still critical. Do not force your users to manage the dependencies of your cli. Do write your cli in a compiled language. Understand the reason for those decisions and tell your agents to use the correct architecture.
geodel 13 hours ago [-]
No it is exactly right mode for modern tech companies:
1) If it runs on my dime and my infrastructure I will optimize the hell out using most cleverly written Rust and what not and gloat about engineering prowess.
2) If it runs on users computers well then, we have carefully evaluated our strategic direction and come to conclusion that JS/TS/Electron option is the best way to go.
gobdovan 10 hours ago [-]
There's also a (maybe more minor but still interesting) explanation. On a server, you know quite precisely your load and you want to be able to causally trace bottlenecks, which is simpler with AOT compiled programs. On users' machines, they may not give you full telemetry and may use your system in quite variable ways. So V8 comes in quite nicely and optimises hot paths on workload it observes on each users system.
amluto 6 hours ago [-]
Is this sarcasm? We’re talking about a CLI. The fancy JIT system will collect data from one single operation and then promptly forget everything it learned and discard all those shiny optimized instruction sequences before the next operation.
For example are workloads for which Java performs very, very well. CLI tools that do one operation and return are not examples of these workloads. v8 is plausibly less bad because v8 is also optimized for short-running scripts, but that just means less outrageously slow, not that it will be remotely competitive with native code.
gobdovan 4 hours ago [-]
I was pointing out a minor consideration for Rust on server vs TS on local in general, not current `cf` specifically.
locknitpicker 4 hours ago [-]
> Is this sarcasm? We’re talking about a CLI.
This is precisely why this blend of comments is insane.
All the CLI does is take command line arguments, put together requests based on them, send them to an API, get the responses, do mild transformation on the responses,and output it to stdout/stderr.
Pretty much any choice of tech stack will work well. This is not rocket science. It's pointless to talk about optimized solutions. It's a complete waste of time.
satvikpendem 2 hours ago [-]
When you have buggy software like Claude Code where they literally had to buy the company that made the software and then machine translate it to Rust just to make it fast enough, it's not "a complete waste of time." Somehow people can turn even CLIs into unoptimized garbage.
brabel 2 hours ago [-]
I don’t agree with that at all, there is a high startup cost to languages like Java and to a lesser extent, JS. Java won’t do anything at all for about 60ms last I measured. This is noticeable to users. JS does better which is why you still see some JS based CLIs. But languages like Go and Rust really are much better for this, they don’t require a huge VM installed on your system and start up instantly. I can also recommend Common Lisp as it has an insanely low startup latency. Ship a single file binary without dependencies please.
geodel 6 hours ago [-]
I mean it is the reason they would like to give. Should we accept it though as their core motivation vis-a-vis it is most convenient and low effort for them so they will do it.
cschmatzler 13 hours ago [-]
This is also not correct in this case since they recently rewrote the Artifacts backend from Zig to TypeScript.
tcdent 14 hours ago [-]
My read is that it's generally the teams that have been assigned to build a certain product that end up choosing the architecture that it runs on. So when we see TypeScript involved in TUI and CLI applications, most of it is just a repurposing of skill sets from that domain into the terminal. In an organization like Cloudflare, I expect that the developers who don't specialize in TypeScript are working on far more important problems.
kelchm 14 hours ago [-]
Are you really suggesting that the choice to use Typescript wasn't a deliberate one?
IMO -- it makes total sense within the existing Cloudflare tooling ecosystem.
slowin 14 hours ago [-]
Whether it was deliberate or not, I do not think it's a good choice. When agents can write in any language, there's no reason to pick the wrong tool for the job. At this point Javascript/Typescript belongs only in the browser. It's the suboptimal choice for every other environment. Especially for a command line tool. Even if the back-end is written in Typescript (also not the best choice imho), the clients need not be in the same language.
amluto 6 hours ago [-]
Various agent tools (including current versions of codex-rs, which is otherwise a normal Rust program) make effective use of JavaScript/TypeScript for “code mode”. I actually think it’s an excellent choice for this use case. (I think that a less weird language with otherwise similar optimizers and tooling would be even better, but JS/TypeScript is what we have.)
What would even be a good alternative? The language should have no ambient authority, be fully safe, run newly loaded code quickly, and be popular enough that current LLMs are good at it. I think the languages that fit the bill are JS/TypeScript and Lua.
lelanthran 3 hours ago [-]
> The language should have no ambient authority, be fully safe, run newly loaded code quickly, and be popular enough that current LLMs are good at it. I think the languages that fit the bill are JS/TypeScript and Lua.
JS as a tech stack breaks your "fully safe" constraint (unless you are talking about running a CLI JS application without using npm...)
chatmasta 14 hours ago [-]
Typescript and the npm/JS ecosystem may be complex, but you don’t need AGI to figure out how to install a CLI built with TS. My agent can figure out how to install this.
miki123211 11 hours ago [-]
Installation is not the problem.
Javascript is plenty fast, but only if it has enough time to JIT the code and can keep it JITed in memory. For long-running backed services, it's plenty fast, for browser things, it's the only option, but for the command line, it adds needless startup time.
Agents make this even worse because they don't have a "sense of time", so if they accidentally do something which causes startup time to increase dramatically, they won't feel it like a human dev would, and won't immediately start optimizing. Unless you have some specific benchmarks in CI that fail any PR which makes the code too slow, agents will just make things slower and slower.
slowin 14 hours ago [-]
It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.
isopede 13 hours ago [-]
Pretty much every modern language with a package repository is vulnerable to supply chain attacks.
Are there any languages doing something unique or are especially resilient in this respect?
slowin 12 hours ago [-]
You can get a binary compiled by the author or a trusted source and none of the dependencies can change out from under you. This isn't possible with an interpreted language where the dependencies are resolved (often from dubious places like npm) at install and update time.
chatmasta 7 hours ago [-]
You can write a CLI in typescript and bundle it into a a single JS file. In fact (without looking) I’m sure that’s what Cloudflare is doing here because it’s standard practice.
locknitpicker 4 hours ago [-]
> It's not just the complexity. You're also vulnerable to supply chain attacks via NPM.
Oh you mean like the attacks that occur in Rust's cargo?
Yes, and the user wants to use a command line app, regardless of what's running underneath.
wannabe44 4 hours ago [-]
1. There's always a possibility they evaluated Rust / Go, concluded the agentic code in those languages is less maintainable / productive (for AI agents) than typescript, but didn't spell it out to avoid internet flame wars. For instance, recent Microsoft rewrite of copilot almost doubled the code size.
2. They may intend the parts of it to be reused on workers?
satvikpendem 2 hours ago [-]
They literally write large parts of their codebase already in Rust and with agents, and Rust workers are supported so I really don't know the cause.
wannabe44 25 minutes ago [-]
Didn't know there was rust worker support. I stand corrected.
locknitpicker 4 hours ago [-]
> 1. There's always a possibility they evaluated Rust / Go, concluded the agentic code in those languages is less maintainable / productive (for AI agents) than typescript, but didn't spell it out to avoid internet flame wars.
This is a testament of how toxic the fanboys behind some of these language bandwagons became: people avoid mentioning their precious little tool wasn't the top choice to develop a project, because a mundane technical decision can gather so much vitriol from these types that a flame war is bound to happen.
cush 12 hours ago [-]
Seriously there’s zero benefit to be writing CLIs in typescript in 2026
7 hours ago [-]
forty 12 hours ago [-]
There is no more code, there are only specs, apparently. So I guess it's a typescript spec so your agent can generate its own CLI, in optimized native assembly of your local CPU and customized to your needs ? ;)
nharziro 7 hours ago [-]
I couldn't figure out why Microsoft wrote Github copilot CLI in typescript either.
simplesocieties 7 hours ago [-]
Language choice is more often due to politics than practicality. Microsoft probably has some internal process for deciding on languages and "defaults" to typescript & C# since they have the most direct control over those languages.
MattyRad 7 hours ago [-]
`npm...` and then instant tab close. The total lack of self-awareness regarding how much they're asking us to infect our toolchain is hilarious. I mean, consider that agents can and should be containerized.... Like, that's what competent engineers- the target audience- are doing. It's just so completely tone-deaf.
Imustaskforhelp 2 hours ago [-]
Optimization for me but not for thee.
locknitpicker 4 hours ago [-]
> I don't understand why this is written in Typescript
I suppose you're not very familiar with typescript then.
Listen, all this CLI app does is serve as an interface to send requests to the Cloudflare API. This means it only does things like sending HTTP requests, and outputting JSON. The cli app also needs to run on multiple platforms. Performance is not an issue or a concern.
I'd frame this the opposite way: what better tool do you think there is for this purpose other than TypeScript?
On top of that, there's the fact that Cloudflare's core services run on V8. If there is anything this company has, it's people familiar with JavaScript and TypeScript.
dash-44 2 hours ago [-]
Different use case but Claude Code CLI and GitHub Copilot CLI, both JS monstrosities, use 500MB at idle per session and it's not uncommon to have 10+ sessions across multiple IDE's. 5GB RAM gone on just an LLM harness doing nothing.
At least Codex CLI in rust uses 80-100MB which is still not great but a big improvement.
These AI companies screw you over from both sides. They make the cost of RAM skyrocket and then they build terrible software that uses all the RAM you have.
lelanthran 3 hours ago [-]
> I'd frame this the opposite way: what better tool do you think there is for this purpose other than TypeScript?
Well, anything less susceptible to supply-chain attacks, obviously.
amluto 6 hours ago [-]
There’s no mention of how long the CLI takes to start. gcloud is hilariously slow even on human timescales, and even when not running it as a snap (sigh).
IMO these tools should strive to start quickly.
squiffsquiff 14 hours ago [-]
AWS and GCP CLIs have been in Python for a decade or more. Last I checked Python was not a compiled language
xtajv 13 hours ago [-]
Raise your hand if you have been personally traumatized by the miniature standalone py3 distribution bundled within the aws cli.
mjr00 13 hours ago [-]
Yeah, and they're terrible. If anything they're a prime example of what 100% should be written in a compiled language.
slowin 13 hours ago [-]
I think these are both examples that help prove my point. Neither of these tools benefit the user by being in Python and distributing a runtime just for a CLI tool.
perching_aix 14 hours ago [-]
"Claude, rewrite this in amd64 and arm64 assembly. Optimize it to the max, and make no mistakes. Oh yeah, formally verify it while there, may as well."
cruffle_duffle 12 hours ago [-]
You laugh now but in 5 years when these LLM’s operate at thousands or tens of thousands of tokens per second on dedicated hardware in your phone… “might as well” won’t even be a joke.
iharuya 11 hours ago [-]
That still feels like chartering a helicopter for a 20-minute drive just because helicopters got cheaper and faster.
perching_aix 11 hours ago [-]
Oh, I'm not entirely sure I was joking. This is already well possible at this point, it's just goofy sounding.
slopinthebag 10 hours ago [-]
the point is probably to have a ts library as well for consumers, so it kind of makes sense.
i'd probably write it in rust and expose ts bindings tho.
827a 7 hours ago [-]
Wow, the first four comments are negative. Welcome to Hacker News everybody!
emadabdulrahim 13 hours ago [-]
It's crazy that some of the best product launches nowadays are CLIs.
fallinditch 13 hours ago [-]
Agreed. Cloudlflare appear to be innovating really well.
hackernud3s 10 hours ago [-]
It can do everything except make the token to give it permissions. For that you need to dig through their website to find the tokens section. Oh and they change where that lives every week.
jumploops 9 hours ago [-]
As bad as the AWS console UX is, at least it’s mostly additive/unchanging over time.
I frequently hit strange UI bugs with Cloudflare workers, where I need to do a hard refresh to make things right.
recroad 15 hours ago [-]
This is cool, but I've never had an issue with agents working on Cloudflare by just making REST calls. With the rest docs, it knows pretty much everything about what kind of operations it can do. Is the CLI a subset of that or does in encompass everything?
artdigital 8 hours ago [-]
Yes I am doing that too. I have a separate folder called ai/cloudflare. the AGENTS.md references the cf docs and instructs the agent to leave a change log + write down learnings whenever it does something
It’s now so good that I cd into this folder and say things like “add this and that to this configuration” and the agent immediately knows how to do it
I’m guessing cf just wraps the API into a CLI that’s easier to traverse and explore
verdverm 15 hours ago [-]
The actual title is
> Introducing cf: the agentic CLI for the entire Cloudflare API
emphasis my own to highlight the key word missing in the HN title
alasano 15 hours ago [-]
I don't know what it is about wrangler that made me dislike it so much but I welcome this change since it's meant to replace wrangler.
george_max 6 hours ago [-]
It feels heavy, the emojis are overused, and it is probably the only CLI tool I've felt as "clunky". Maybe that and Claude Code TUI.
verdverm 15 hours ago [-]
re: wrangler, my biggest gripe was inconsistency between dev and prod
alasano 15 hours ago [-]
I think I may be confusing my annoyance with pages vs workers and agents that kept deploying to pages due to outdated training data.
Wrangler still didn't feel great to use.
bhouston 10 hours ago [-]
Nice! I would recommend you support one of the opencli specs, like https://clidoc.dev so that it is fully discoverable with examples, etc.
smithclay 15 hours ago [-]
This is a lot to like here as someone who pretty much exclusively uses the Cloudflare API via agents. Hoping (since it's built on top of Forge), some kind of native terraform support is also in the works.
Great when you're a solo dev deploying a worker, but would be incredible for production deployments if this could also just natively output terraform code.
Of course, it's impossible to know for sure what was LLM processed or not, but your posts have been getting classified that way.
unified101 15 hours ago [-]
I think the shape of clouds and services is going to change given current clouds are uxed for humans. Cloudflare is making the right bet. Specially the free agent report account. That's like a wonderful idea for building agent share.
10 hours ago [-]
vamsiraju 10 hours ago [-]
"Our new configuration format is based on TypeScript"
This is the most head scratching but interesting bit.
creatonez 7 hours ago [-]
Is this a joke? Why would you want to use a random word generator on production infrastructure configuration? Cloudflare should be blocking these malicious/incompetent users, not enabling them.
draftsman 4 hours ago [-]
Scratching my head too. The thing is, the industry as whole is enabling this type of behavior
I have been using the pre-releases with success, but this post could have waited a few days!
ozarkerD 13 hours ago [-]
Great now i have to uninstall the Cloudfoundry CLI to not collide with this :)
fragmede 12 hours ago [-]
helpful tip is to make use of single letter personal aliases. g=git c=cf or cf ;)
zarmin 12 hours ago [-]
so uh, the favicon for cloudflare and soundcloud are just the same thing now? soundcloudflare?
plainjar 9 hours ago [-]
[dead]
Solvyx 9 hours ago [-]
[flagged]
BigBalli 12 hours ago [-]
[dead]
verdverm 15 hours ago [-]
Kudos to cloudflare on this, it looks like a great CLI, I especially like the `cf cli search`.
Related, Matt Pocock's skill for having agents generate an interactive bash script for things only humans can do (or should do), presented in the context of devops like activities
I have found that having the agents write scripts to use tools like this is better (less tokens, more reliability, fewer side quests) than giving it to them directly with markdown they may or may not follow on any given day.
The other benefit to this is that you can put scripts on either side of the agent and remove all credentials from their process, removing whole classes of issues you don't want to have to tell your boss about. CLIs like this are great for read-only debug sessions, but if you are going to make modifications to your cloud infra, keep doing IaC.
rahimnathwani 14 hours ago [-]
You linked to /skills/productivity/to-questionnaire/SKILL.md
Did you mean to link to /skills/engineering/wizard/SKILL.md ?
1) If it runs on my dime and my infrastructure I will optimize the hell out using most cleverly written Rust and what not and gloat about engineering prowess.
2) If it runs on users computers well then, we have carefully evaluated our strategic direction and come to conclusion that JS/TS/Electron option is the best way to go.
For example are workloads for which Java performs very, very well. CLI tools that do one operation and return are not examples of these workloads. v8 is plausibly less bad because v8 is also optimized for short-running scripts, but that just means less outrageously slow, not that it will be remotely competitive with native code.
This is precisely why this blend of comments is insane.
All the CLI does is take command line arguments, put together requests based on them, send them to an API, get the responses, do mild transformation on the responses,and output it to stdout/stderr.
Pretty much any choice of tech stack will work well. This is not rocket science. It's pointless to talk about optimized solutions. It's a complete waste of time.
IMO -- it makes total sense within the existing Cloudflare tooling ecosystem.
What would even be a good alternative? The language should have no ambient authority, be fully safe, run newly loaded code quickly, and be popular enough that current LLMs are good at it. I think the languages that fit the bill are JS/TypeScript and Lua.
JS as a tech stack breaks your "fully safe" constraint (unless you are talking about running a CLI JS application without using npm...)
Javascript is plenty fast, but only if it has enough time to JIT the code and can keep it JITed in memory. For long-running backed services, it's plenty fast, for browser things, it's the only option, but for the command line, it adds needless startup time.
Agents make this even worse because they don't have a "sense of time", so if they accidentally do something which causes startup time to increase dramatically, they won't feel it like a human dev would, and won't immediately start optimizing. Unless you have some specific benchmarks in CI that fail any PR which makes the code too slow, agents will just make things slower and slower.
Are there any languages doing something unique or are especially resilient in this respect?
Oh you mean like the attacks that occur in Rust's cargo?
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...
Yes, and the user wants to use a command line app, regardless of what's running underneath.
2. They may intend the parts of it to be reused on workers?
This is a testament of how toxic the fanboys behind some of these language bandwagons became: people avoid mentioning their precious little tool wasn't the top choice to develop a project, because a mundane technical decision can gather so much vitriol from these types that a flame war is bound to happen.
I suppose you're not very familiar with typescript then.
Listen, all this CLI app does is serve as an interface to send requests to the Cloudflare API. This means it only does things like sending HTTP requests, and outputting JSON. The cli app also needs to run on multiple platforms. Performance is not an issue or a concern.
I'd frame this the opposite way: what better tool do you think there is for this purpose other than TypeScript?
On top of that, there's the fact that Cloudflare's core services run on V8. If there is anything this company has, it's people familiar with JavaScript and TypeScript.
At least Codex CLI in rust uses 80-100MB which is still not great but a big improvement.
These AI companies screw you over from both sides. They make the cost of RAM skyrocket and then they build terrible software that uses all the RAM you have.
Well, anything less susceptible to supply-chain attacks, obviously.
IMO these tools should strive to start quickly.
i'd probably write it in rust and expose ts bindings tho.
I frequently hit strange UI bugs with Cloudflare workers, where I need to do a hard refresh to make things right.
It’s now so good that I cd into this folder and say things like “add this and that to this configuration” and the agent immediately knows how to do it
I’m guessing cf just wraps the API into a CLI that’s easier to traverse and explore
> Introducing cf: the agentic CLI for the entire Cloudflare API
emphasis my own to highlight the key word missing in the HN title
Wrangler still didn't feel great to use.
Great when you're a solo dev deploying a worker, but would be incredible for production deployments if this could also just natively output terraform code.
Of course, it's impossible to know for sure what was LLM processed or not, but your posts have been getting classified that way.
I have been using the pre-releases with success, but this post could have waited a few days!
Related, Matt Pocock's skill for having agents generate an interactive bash script for things only humans can do (or should do), presented in the context of devops like activities
https://github.com/mattpocock/skills/blob/main/skills/produc...
I have found that having the agents write scripts to use tools like this is better (less tokens, more reliability, fewer side quests) than giving it to them directly with markdown they may or may not follow on any given day.
The other benefit to this is that you can put scripts on either side of the agent and remove all credentials from their process, removing whole classes of issues you don't want to have to tell your boss about. CLIs like this are great for read-only debug sessions, but if you are going to make modifications to your cloud infra, keep doing IaC.
Did you mean to link to /skills/engineering/wizard/SKILL.md ?
thanks for surfacing this for everyone
link: https://github.com/mattpocock/skills/blob/main/skills/engine...