cloudflare
Import
Section titled “Import”import * as api from "@fungi.computer/puffball/cloudflare";Exports
Section titled “Exports”| Kind | Export | Description |
|---|---|---|
| type alias | AssetR2Object | Native R2 metadata: checksums are validated by R2, not custom metadata claims. |
| type alias | AssetR2Bucket | Native R2 operations required to verify and serve one asset build. |
| type alias | AppReleaseTransitionObligation | Durable catalog-scoped fact awaiting delivery to a separately owned Team. |
| type alias | AppReleaseAffectedSurface | Catalog-owned public-Surface material carried with a transition obligation. |
| type alias | AppReleaseTeamRecipient | Durable delivery state for one Team recipient of a transition obligation. |
| type alias | AppReleaseTeamRecipientPage | One ordered page of Team IDs returned by the separately owned Team directory. |
| type alias | AppReleaseTeamRecipientOutcome | Terminal delivery outcome recorded for one Team recipient. |
| type alias | AppReleaseTransitionObligationStore | D1-only at-least-once read/ack seam; Team routing remains outside App Release. |
| type alias | AppReleaseSurfaceTransitionBasis | Selected Release basis from the same D1 authority snapshot, including its transition sequence. |
| type alias | AppReleaseD1QueryResult | Structural result returned by the D1 operations used by App Release. |
| type alias | AppReleaseD1PreparedStatement | Structural prepared-statement surface needed by the D1-backed store. |
| type alias | AppReleaseD1Database | Structural D1 surface kept independent of Cloudflare vendor declarations. |
| type alias | AppReleaseR2Object | Structural R2 object surface needed by the artifact reader. |
| type alias | AppReleaseR2Bucket | Structural R2 surface kept independent of Cloudflare vendor declarations. |
| type alias | ErasureBucket | R2 operations used by the scoped Team erasure owner. |
| type alias | ArtifactSnapshotPolicy | Trusted composition limit for reading one immutable artifact. |
| constant | appArtifactErasureReadbackSchema | The erasure coordinator consumes this owner-issued readback, including outstanding buyer custody. |
| constant | APP_RELEASE_D1_FRESH_SCHEMA | The one current App Release D1 schema for an empty catalog. |
| function | createTeamAppReleaseErasure() | Read every catalog reference before deleting content-addressed R2 objects. |
| function | createD1TeamAppPublisherRegistry() | Create the native registry that joins a Team publisher to one App/source. |
| function | createD1AppReleaseStore() | Create the D1-backed App Release store with private public-website authority. |
| function | createR2ArtifactReader() | Create the R2-backed artifact reader for opaque artifact references. |
| function | createD1TransitionObligationStore() | Open the D1-only obligation adjunct for a future owner-driven dispatcher. The ordinary App Release store contract intentionally does not expose it. |
| function | readD1SurfaceTransitionBasis() | Resolve one previously selected Release on a Surface and retain the exact transition sequence. The Release need not remain the Surface’s current default, but it must still be verified, active, and owned by that Surface. |
| function | matchEligibleSurfaceTransitionBasis() | Match one eligible selected Release without leaking store-result branching to consumers. |
AssetR2Objecttype alias
Section titled “AssetR2Object”type AssetR2Object = object;Native R2 metadata: checksums are validated by R2, not custom metadata claims.
Properties
Section titled “Properties”version
Section titled “version”readonly version: string;readonly size: number;checksums
Section titled “checksums”readonly checksums: object;sha256?
Section titled “sha256?”readonly optional sha256?: ArrayBuffer;AssetR2Buckettype alias
Section titled “AssetR2Bucket”type AssetR2Bucket = object;Native R2 operations required to verify and serve one asset build.
Methods
Section titled “Methods”head()
Section titled “head()”head(key): Promise<AssetR2Object | null>;Read immutable object metadata without loading its body.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
key |
string |
Returns
Section titled “Returns”Promise<AssetR2Object | null>
get(key): Promise<AssetR2Object & object | null>;Read immutable object metadata and its streaming body.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
key |
string |
Returns
Section titled “Returns”Promise<AssetR2Object & object | null>
AppReleaseTransitionObligationtype alias
Section titled “AppReleaseTransitionObligation”type AppReleaseTransitionObligation = object;Durable catalog-scoped fact awaiting delivery to a separately owned Team.
Properties
Section titled “Properties”sequence
Section titled “sequence”readonly sequence: number;transition
Section titled “transition”readonly transition: ReleaseTransition;transitionId
Section titled “transitionId”readonly transitionId: AppTransitionId;affectedPublicSurfaceIds
Section titled “affectedPublicSurfaceIds”readonly affectedPublicSurfaceIds: readonly PublicSurfaceId[];affectedSurfaces
Section titled “affectedSurfaces”readonly affectedSurfaces: readonly AppReleaseAffectedSurface[];Catalog-owned material needed by a Team without a second catalog read.
affectedBuyerApps
Section titled “affectedBuyerApps”readonly affectedBuyerApps: readonly AppId[];enumeration
Section titled “enumeration”readonly enumeration: object;The last opaque Global Team cursor and whether enumeration is complete.
cursor
Section titled “cursor”readonly cursor: string | null;complete
Section titled “complete”readonly complete: boolean;readonly state: "pending" | "acknowledged";AppReleaseAffectedSurfacetype alias
Section titled “AppReleaseAffectedSurface”type AppReleaseAffectedSurface = object;Catalog-owned public-Surface material carried with a transition obligation.
Properties
Section titled “Properties”publicSurfaceId
Section titled “publicSurfaceId”readonly publicSurfaceId: PublicSurfaceId;readonly appId: AppId;stableRoute
Section titled “stableRoute”readonly stableRoute: StableRoute;AppReleaseTeamRecipienttype alias
Section titled “AppReleaseTeamRecipient”type AppReleaseTeamRecipient = object;Durable delivery state for one Team recipient of a transition obligation.
Properties
Section titled “Properties”teamId
Section titled “teamId”readonly teamId: string;readonly state: "pending" | "applied" | "no-op" | "expired";AppReleaseTeamRecipientPagetype alias
Section titled “AppReleaseTeamRecipientPage”type AppReleaseTeamRecipientPage = object;One ordered page of Team IDs returned by the separately owned Team directory.
Properties
Section titled “Properties”cursor?
Section titled “cursor?”readonly optional cursor?: string | null;Null identifies the first page; all later cursors remain opaque strings.
nextCursor?
Section titled “nextCursor?”readonly optional nextCursor?: string | null;teamIds
Section titled “teamIds”readonly teamIds: readonly string[];complete
Section titled “complete”readonly complete: boolean;AppReleaseTeamRecipientOutcometype alias
Section titled “AppReleaseTeamRecipientOutcome”type AppReleaseTeamRecipientOutcome = "applied" | "no-op" | "expired";Terminal delivery outcome recorded for one Team recipient.
AppReleaseTransitionObligationStoretype alias
Section titled “AppReleaseTransitionObligationStore”type AppReleaseTransitionObligationStore = object;D1-only at-least-once read/ack seam; Team routing remains outside App Release.
Methods
Section titled “Methods”readByTransitionId()
Section titled “readByTransitionId()”readByTransitionId(transitionId): Promise<AppReleaseStoreResult< | AppReleaseTransitionObligation | { kind: "absent";}>>;Read one obligation by its immutable transition identity, or report it absent.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
transitionId |
AppTransitionId |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult< |
AppReleaseTransitionObligation | {
kind: "absent"; }>>
read()
Section titled “read()”read(options): Promise<AppReleaseStoreResult<readonly AppReleaseTransitionObligation[]>>;Read pending obligations after a sequence cursor in ascending sequence order.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
options |
{ afterSequence?: number; limit?: number; } |
options.afterSequence? |
number |
options.limit? |
number |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<readonly
AppReleaseTransitionObligation[]>>
recordTeamRecipientPage()
Section titled “recordTeamRecipientPage()”recordTeamRecipientPage(sequence, page): Promise<AppReleaseStoreResult< | AppReleaseTransitionObligation | { kind: "absent";}>>;Persist the next ordered Team-recipient page; identical replays are idempotent.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
sequence |
number |
page |
AppReleaseTeamRecipientPage |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult< |
AppReleaseTransitionObligation | {
kind: "absent"; }>>
readPendingTeamRecipients()
Section titled “readPendingTeamRecipients()”readPendingTeamRecipients(options): Promise<AppReleaseStoreResult<readonly AppReleaseTeamRecipient[]>>;Read pending recipients for one obligation in stable Team-ID order.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
options |
{ sequence: number; limit?: number; } |
options.sequence |
number |
options.limit? |
number |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<readonly
AppReleaseTeamRecipient[]>>
recordTeamRecipientOutcome()
Section titled “recordTeamRecipientOutcome()”recordTeamRecipientOutcome( sequence, teamId, outcome): Promise<AppReleaseStoreResult< | AppReleaseTeamRecipient | { kind: "absent";}>>;Record a pending recipient’s terminal outcome; conflicting replays fail.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
sequence |
number |
teamId |
string |
outcome |
AppReleaseTeamRecipientOutcome |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult< |
AppReleaseTeamRecipient | { kind: "absent";
}>>
acknowledge()
Section titled “acknowledge()”acknowledge(sequence): Promise<AppReleaseStoreResult< | AppReleaseTransitionObligation | { kind: "absent";}>>;Acknowledge only after enumeration is complete and no recipients remain pending.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
sequence |
number |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult< |
AppReleaseTransitionObligation | {
kind: "absent"; }>>
AppReleaseSurfaceTransitionBasistype alias
Section titled “AppReleaseSurfaceTransitionBasis”type AppReleaseSurfaceTransitionBasis = | { kind: "absent"; } | { kind: "ambiguous"; } | { kind: "none"; appId: AppId; publicSurfaceId: PublicSurfaceId; } | { kind: "selected"; appId: AppId; publicSurfaceId: PublicSurfaceId; releaseId: ReleaseId; sequence: number; eligibility: "eligible" | "ineligible"; checkedAt: number; };Selected Release basis from the same D1 authority snapshot, including its transition sequence.
Union Members
Section titled “Union Members”Type Literal
Section titled “Type Literal”{ kind: "absent";}Type Literal
Section titled “Type Literal”{ kind: "ambiguous";}Type Literal
Section titled “Type Literal”{ kind: "none"; appId: AppId; publicSurfaceId: PublicSurfaceId;}Type Literal
Section titled “Type Literal”{ kind: "selected"; appId: AppId; publicSurfaceId: PublicSurfaceId; releaseId: ReleaseId; sequence: number; eligibility: "eligible" | "ineligible"; checkedAt: number;}| Name | Type | Description |
|---|---|---|
kind |
"selected" |
- |
appId |
AppId |
- |
publicSurfaceId |
PublicSurfaceId |
- |
releaseId |
ReleaseId |
- |
sequence |
number |
- |
eligibility |
"eligible" | "ineligible" |
- |
checkedAt |
number |
Authority-read start time; consumers may only shorten its horizon. |
AppReleaseD1QueryResulttype alias
Section titled “AppReleaseD1QueryResult”type AppReleaseD1QueryResult = object;Structural result returned by the D1 operations used by App Release.
Properties
Section titled “Properties”success
Section titled “success”readonly success: boolean;Whether D1 completed the operation successfully.
results
Section titled “results”readonly results: readonly unknown[];Untrusted row values returned by the operation.
AppReleaseD1PreparedStatementtype alias
Section titled “AppReleaseD1PreparedStatement”type AppReleaseD1PreparedStatement = object;Structural prepared-statement surface needed by the D1-backed store.
Methods
Section titled “Methods”bind()
Section titled “bind()”bind(...values): AppReleaseD1PreparedStatement;Bind positional values and return the statement to execute.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
…values |
unknown[] |
Returns
Section titled “Returns”first()
Section titled “first()”first(): Promise<object | null>;Read the first untrusted row, or null when none exists.
Returns
Section titled “Returns”Promise<object | null>
all(): Promise<AppReleaseD1QueryResult>;Read all matching rows.
Returns
Section titled “Returns”Promise<AppReleaseD1QueryResult>
run(): Promise<AppReleaseD1QueryResult>;Execute a mutating statement.
Returns
Section titled “Returns”Promise<AppReleaseD1QueryResult>
AppReleaseD1Databasetype alias
Section titled “AppReleaseD1Database”type AppReleaseD1Database = object;Structural D1 surface kept independent of Cloudflare vendor declarations.
Methods
Section titled “Methods”prepare()
Section titled “prepare()”prepare(query): AppReleaseD1PreparedStatement;Prepare one SQL statement for binding and execution.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
query |
string |
Returns
Section titled “Returns”batch()
Section titled “batch()”batch(statements): Promise<readonly AppReleaseD1QueryResult[]>;Execute a group of statements atomically in native D1.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
statements |
readonly AppReleaseD1PreparedStatement[] |
Returns
Section titled “Returns”Promise<readonly AppReleaseD1QueryResult[]>
AppReleaseR2Objecttype alias
Section titled “AppReleaseR2Object”type AppReleaseR2Object = object;Structural R2 object surface needed by the artifact reader.
Properties
Section titled “Properties”version
Section titled “version”readonly version: string;Native immutable object version checked for referenced App children.
readonly size: number;Object size in bytes, checked before the body is buffered.
httpMetadata?
Section titled “httpMetadata?”readonly optional httpMetadata?: object;HTTP metadata retained with the object, when present.
contentType?
Section titled “contentType?”readonly optional contentType?: string;Declared media type for the stored object.
Methods
Section titled “Methods”arrayBuffer()
Section titled “arrayBuffer()”arrayBuffer(): Promise<ArrayBuffer>;Read the immutable object body.
Returns
Section titled “Returns”Promise<ArrayBuffer>
AppReleaseR2Buckettype alias
Section titled “AppReleaseR2Bucket”type AppReleaseR2Bucket = object;Structural R2 surface kept independent of Cloudflare vendor declarations.
Methods
Section titled “Methods”get(key): Promise<AppReleaseR2Object | null>;Read one object by its opaque storage key.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
key |
string |
Returns
Section titled “Returns”Promise<AppReleaseR2Object | null>
ErasureBuckettype alias
Section titled “ErasureBucket”type ErasureBucket = AppReleaseR2Bucket & object;R2 operations used by the scoped Team erasure owner.
Type Declaration
Section titled “Type Declaration”| Name | Type | Description |
|---|---|---|
head() |
(key) => Promise<object | null> |
Read the metadata for an exact object key. |
delete() |
(key) => Promise<void> |
Delete an exact object key after catalog references are checked. |
ArtifactSnapshotPolicytype alias
Section titled “ArtifactSnapshotPolicy”type ArtifactSnapshotPolicy = Readonly<{ maxBytes: number; maxManifestBytes?: number;}>;Trusted composition limit for reading one immutable artifact.
appArtifactErasureReadbackSchemaconstant
Section titled “appArtifactErasureReadbackSchema”const appArtifactErasureReadbackSchema: Struct<{ clear: Boolean; personalClear: Boolean; retainedArtifacts: $Array< Struct<{ disposition_id: String; app_id: refine<AppId, String>; release_ids_json: String; artifact_roots_json: String; created_at: Number; state: Literals< readonly ["pending", "retaining", "retained", "revoking", "revoked"] >; request_id: NullOr<String>; reason: NullOr<String>; completed_at: NullOr<Number>; releaseIds: $Array<refine<ReleaseId, String>>; }> >; remaining: $Array<String>; pending: $Array<String>; obligationTeams: $Array<String>; obligationPages: $Array<String>; objects: $Array<String>;}>;The erasure coordinator consumes this owner-issued readback, including outstanding buyer custody.
APP_RELEASE_D1_FRESH_SCHEMAconstant
Section titled “APP_RELEASE_D1_FRESH_SCHEMA”const APP_RELEASE_D1_FRESH_SCHEMA: string;The one current App Release D1 schema for an empty catalog.
createTeamAppReleaseErasure()function
Section titled “createTeamAppReleaseErasure()”function createTeamAppReleaseErasure( database, bucket, assetPolicy?, now?,): object;Read every catalog reference before deleting content-addressed R2 objects.
Parameters
Section titled “Parameters”| Parameter | Type | Default value |
|---|---|---|
database |
AppReleaseD1Database |
undefined |
bucket |
ErasureBucket |
undefined |
assetPolicy? |
{ maxManifestBytes: number; maxObjects: number; maxObjectBytes: number; maxTotalBytes: number; } |
undefined |
assetPolicy.maxManifestBytes? |
number |
positiveInteger |
assetPolicy.maxObjects? |
number |
positiveInteger |
assetPolicy.maxObjectBytes? |
number |
positiveInteger |
assetPolicy.maxTotalBytes? |
number |
positiveInteger |
now? |
() => number |
Date.now |
Returns
Section titled “Returns”| Name | Type | Description |
|---|---|---|
verifyManifest() |
( teamId, appIds, keys ) => Promise<{ teamId: string; apps: object[]; repositories: string[]; }> |
Reject any live App or R2 key outside this Team’s current or retry scope. |
preflight() |
(teamId) => Promise<{ teamId: string; apps: object[]; repositories: string[]; }> |
Inventory Team catalog rows, exclusive objects, and source repositories. |
erase() |
(teamId) => Promise<{ apps: number; }> |
Remove one Team’s catalog and exclusive objects, resuming pending jobs. |
readback() |
( teamId, appIds, keys ) => Promise<{ clear: boolean; personalClear: boolean; retainedArtifacts: object[]; remaining: string[]; pending: string[]; obligationTeams: string[]; obligationPages: string[]; objects: string[]; }> |
Verify the named Apps, pending jobs, obligations and exclusive objects. |
createD1TeamAppPublisherRegistry()function
Section titled “createD1TeamAppPublisherRegistry()”function createD1TeamAppPublisherRegistry(database): TeamAppPublisherRegistry;Create the native registry that joins a Team publisher to one App/source.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
database |
AppReleaseD1Database |
Returns
Section titled “Returns”createD1AppReleaseStore()function
Section titled “createD1AppReleaseStore()”function createD1AppReleaseStore(database): PromiseAppReleaseStore & object;Create the D1-backed App Release store with private public-website authority.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
database |
AppReleaseD1Database |
Returns
Section titled “Returns”PromiseAppReleaseStore & object
createR2ArtifactReader()function
Section titled “createR2ArtifactReader()”function createR2ArtifactReader(bucket, policy?, assets?): ArtifactReader;Create the R2-backed artifact reader for opaque artifact references.
Asset manifests are verified cheaply for delivery: the root bytes are
digest-checked here, while the asset handler checks the requested object.
Publication callers pass verification: "publication" to retain the complete
manifest object sweep.
Parameters
Section titled “Parameters”| Parameter | Type | Default value |
|---|---|---|
bucket |
AppReleaseR2Bucket |
undefined |
policy |
ArtifactSnapshotPolicy |
DEFAULT_ARTIFACT_SNAPSHOT_POLICY |
assets? |
{ bucket: Pick<AssetR2Bucket, "head">; policy: { maxManifestBytes: number; maxObjects: number; maxObjectBytes: number; maxTotalBytes: number; }; } |
undefined |
assets.bucket? |
Pick<AssetR2Bucket, "head"> |
undefined |
assets.policy? |
{ maxManifestBytes: number; maxObjects: number; maxObjectBytes: number; maxTotalBytes: number; } |
undefined |
assets.policy.maxManifestBytes? |
number |
positiveInteger |
assets.policy.maxObjects? |
number |
positiveInteger |
assets.policy.maxObjectBytes? |
number |
positiveInteger |
assets.policy.maxTotalBytes? |
number |
positiveInteger |
Returns
Section titled “Returns”createD1TransitionObligationStore()function
Section titled “createD1TransitionObligationStore()”function createD1TransitionObligationStore( database,): AppReleaseTransitionObligationStore;Open the D1-only obligation adjunct for a future owner-driven dispatcher. The ordinary App Release store contract intentionally does not expose it.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
database |
AppReleaseD1Database |
Returns
Section titled “Returns”AppReleaseTransitionObligationStore
readD1SurfaceTransitionBasis()function
Section titled “readD1SurfaceTransitionBasis()”function readD1SurfaceTransitionBasis( database, stableRoute, releaseId, now?,): Promise<AppReleaseStoreResult<AppReleaseSurfaceTransitionBasis>>;Resolve one previously selected Release on a Surface and retain the exact transition sequence. The Release need not remain the Surface’s current default, but it must still be verified, active, and owned by that Surface.
Parameters
Section titled “Parameters”| Parameter | Type | Default value |
|---|---|---|
database |
AppReleaseD1Database |
undefined |
stableRoute |
StableRoute |
undefined |
releaseId |
ReleaseId |
undefined |
now |
() => number |
Date.now |
Returns
Section titled “Returns”Promise<AppReleaseStoreResult<AppReleaseSurfaceTransitionBasis>>
matchEligibleSurfaceTransitionBasis()function
Section titled “matchEligibleSurfaceTransitionBasis()”function matchEligibleSurfaceTransitionBasis( result, expected,): { kind: "selected"; appId: AppId; publicSurfaceId: PublicSurfaceId; releaseId: ReleaseId; sequence: number; eligibility: "eligible" | "ineligible"; checkedAt: number;} | null;Match one eligible selected Release without leaking store-result branching to consumers.
Parameters
Section titled “Parameters”| Parameter | Type |
|---|---|
result |
AppReleaseStoreResult<AppReleaseSurfaceTransitionBasis> |
expected |
Readonly<{ appId: AppId; releaseId: ReleaseId; sequence?: number; }> |
Returns
Section titled “Returns”Type Literal
Section titled “Type Literal”{ kind: "selected"; appId: AppId; publicSurfaceId: PublicSurfaceId; releaseId: ReleaseId; sequence: number; eligibility: "eligible" | "ineligible"; checkedAt: number;}| Name | Type | Description |
|---|---|---|
kind |
"selected" |
- |
appId |
AppId |
- |
publicSurfaceId |
PublicSurfaceId |
- |
releaseId |
ReleaseId |
- |
sequence |
number |
- |
eligibility |
"eligible" | "ineligible" |
- |
checkedAt |
number |
Authority-read start time; consumers may only shorten its horizon. |
null