Skip to main content
Capy 0.9.7 has deploy target adapters for Cloudflare Workers (cf-worker) and Cloudflare Pages (cf-pages). These targets do not use a capy run runtime pair in the deployed Worker or Pages project.

Before you start

Install and authenticate Wrangler. The target preflight checks that it can find the required project configuration before Capy decrypts values.
You can use CLOUDFLARE_API_TOKEN where your Wrangler setup supports token authentication.

Configure a target

From the project directory, run:
Choose Cloudflare Workers or Cloudflare Pages, then provide the target name, Capy branch, project directory, and variable selection. Capy saves the non-secret target configuration in .capy/deploy.json so later runs can reuse it. Workers receive selected runtime values through Cloudflare’s secret store. In direct mode, Capy writes them with wrangler secret bulk and then runs wrangler deploy. Read them with your normal Worker bindings:
Pages targets select build-time values. In direct mode, Capy runs the target’s configured build command with those values in its build environment, then uploads the configured output directory with wrangler pages deploy. It does not write those values to the Pages environment-variable store. Do not configure the token runtime pair for a target-delivered Pages deployment.

Direct and CI modes

Both Cloudflare targets support direct and CI modes. In direct mode, Workers write secrets and deploy, while Pages build and upload the output. In CI mode, Workers write secrets but leave deployment to the pipeline after the deploy PR merges; Pages leave both the build and deploy to that pipeline. Capy shows the mode and target branch in its confirmation step. To re-enter setup, run capy deploy --connect --edit; it pre-fills the target when exactly one is saved. Create separate targets for staging and production. Each target pins a Capy branch and set of selected variables, avoiding a delivery from one environment to another by mistake.
Last modified on October 2, 2026