ArcForges' former AI execution runtime on Cloudflare Workers and Workflows. The repository contains a private Hello Agent: a selected Workers AI model calls one validated greeting tool, then writes a final reply. The greeting tool uses the published ArcForges protobuf package.
Retired (HAR.40, authorized by the user on 2026-10-10): the
arcforges-ai-helloWorker and Workflow were deleted on 2026-10-11 by retire-cloudflare run 38104601546 (both return 404), after the dry-run run 38104522196 found the plan eligible; everyai-*release and record is kept. The AI runtime role ended under P2-021, and the C# Harness in the Cloud repository replaces the deleted Worker and Workflow. Main no longer deploys andnpm run deployrefuses. Releases, records and evidence are kept as history, and this repository is kept read-only as history. The retirement record describes how the deletion was gated.
The intended product architecture keeps the only model/tool loop in a Workflow. Cloud owns business authorization, D1 transactions, approvals and accounting under the current runtime authority. This bootstrap demonstrates the runtime, package boundary, build and deployment path; it does not implement the full product harness, streaming, R2 routes or commercial behavior.
Install Node 24.21.0 LTS with npm 11.19.0, then:
npm ci --ignore-scripts
npm run hooks
npm run check
npm run buildThese commands need no Cloudflare account. Default tests run pure offline units in Node. Workflow engine and bundle runtime tests are separate explicit local opt-in commands, never CI gates. The build produces artifacts/candidate/, including the deployable bundle, configuration, hashes, provenance, licenses and runtime SBOM.
The toolchain pins TypeScript 7.0.2, Wrangler 4.143.1 and @arcforges/proto 1.0.0-ci.287.1. See development for tool compatibility, local health testing and dependency updates.
- Validate
{ "name": "ArcForges" }before admitting a model call. - Ask
@cf/openai/gpt-oss-20bfor exactly onesay_hellofunction call using the model's Chat Completions binding profile. - Validate the tool and its arguments, then encode/decode the published request and response protobuf messages to produce
Hello, ArcForges!. - Supply that result to the model and require a bounded final text reply with no further tools.
Each model step disables automatic retries and allows at most 1,024 output tokens with a 90-second step timeout. Names are limited to 80 Unicode code points and 256 UTF-8 bytes, with no ASCII control characters. Whitespace and Unicode are preserved. Unsupported tools, changed arguments and incomplete/malformed model output fail the Workflow.
The Worker has no public route, workers.dev URL or preview URL. While deployed, remote runs were started and inspected through Cloudflare's authenticated Workflow API. The local GET /health handler reports the build identity; it does not call a model or prove inference.
PRs and main validate source, targeted offline units, dependencies/security and the sealed Worker build. Until HAR.40, main deployed that same candidate and created an ai-* prerelease containing the candidate and provider deployment record; main no longer deploys. CI does not invoke a Workflow or model, test the compiled runtime, poll health or download public release bytes. Deployment completion is distinct from live runtime acceptance. See validation policy.
This is a deployable Worker, not an npm library. Versions are automatic: 0.1.0-ci.<run-number>.<run-attempt>. No manual version edit, npm account, NuGet key or PGP key is needed.
Cloudflare setup and deployment records the retirement workflow and, as history, the account settings, the GitHub cloudflare environment, live verification and recovery of the former main deployment. Validation evidence distinguishes completed local checks from pending external gates.
- Bootstrap plan
- Development and hooks
- Project licence declarations and checks
- Reuse records and actual artifact provenance
- Cloudflare retirement, and the former setup, release and recovery
- Contributing, conduct and security
- AGPL-3.0-only license and third-party notices
Build candidates also carry the WP02.04 build identity, sealed from independent source/producer/lock inputs.