Skip to content
API reference

cloudflare

Import
import * as api from "@fungi.computer/puffball/cloudflare";
Kind Export Description
type alias AssetR2Object Native R2 metadata: checksums are validated by R2, not custom metadata claims.
type alias AssetR2Bucket Native R2 operations required to verify and serve one asset build.
type alias AppReleaseTransitionObligation Durable catalog-scoped fact awaiting delivery to a separately owned Team.
type alias AppReleaseAffectedSurface Catalog-owned public-Surface material carried with a transition obligation.
type alias AppReleaseTeamRecipient Durable delivery state for one Team recipient of a transition obligation.
type alias AppReleaseTeamRecipientPage One ordered page of Team IDs returned by the separately owned Team directory.
type alias AppReleaseTeamRecipientOutcome Terminal delivery outcome recorded for one Team recipient.
type alias AppReleaseTransitionObligationStore D1-only at-least-once read/ack seam; Team routing remains outside App Release.
type alias AppReleaseSurfaceTransitionBasis Selected Release basis from the same D1 authority snapshot, including its transition sequence.
type alias AppReleaseD1QueryResult Structural result returned by the D1 operations used by App Release.
type alias AppReleaseD1PreparedStatement Structural prepared-statement surface needed by the D1-backed store.
type alias AppReleaseD1Database Structural D1 surface kept independent of Cloudflare vendor declarations.
type alias AppReleaseR2Object Structural R2 object surface needed by the artifact reader.
type alias AppReleaseR2Bucket Structural R2 surface kept independent of Cloudflare vendor declarations.
type alias ErasureBucket R2 operations used by the scoped Team erasure owner.
type alias ArtifactSnapshotPolicy Trusted composition limit for reading one immutable artifact.
constant appArtifactErasureReadbackSchema The erasure coordinator consumes this owner-issued readback, including outstanding buyer custody.
constant APP_RELEASE_D1_FRESH_SCHEMA The one current App Release D1 schema for an empty catalog.
function createTeamAppReleaseErasure() Read every catalog reference before deleting content-addressed R2 objects.
function createD1TeamAppPublisherRegistry() Create the native registry that joins a Team publisher to one App/source.
function createD1AppReleaseStore() Create the D1-backed App Release store with private public-website authority.
function createR2ArtifactReader() Create the R2-backed artifact reader for opaque artifact references.
function createD1TransitionObligationStore() Open the D1-only obligation adjunct for a future owner-driven dispatcher. The ordinary App Release store contract intentionally does not expose it.
function readD1SurfaceTransitionBasis() Resolve one previously selected Release on a Surface and retain the exact transition sequence. The Release need not remain the Surface’s current default, but it must still be verified, active, and owned by that Surface.
function matchEligibleSurfaceTransitionBasis() Match one eligible selected Release without leaking store-result branching to consumers.

AssetR2Objecttype alias

Section titled “AssetR2Object”
Signature
type AssetR2Object = object;

Native R2 metadata: checksums are validated by R2, not custom metadata claims.

Signature
readonly version: string;
Signature
readonly size: number;
Signature
readonly checksums: object;
Signature
readonly optional sha256?: ArrayBuffer;

AssetR2Buckettype alias

Section titled “AssetR2Bucket”
Signature
type AssetR2Bucket = object;

Native R2 operations required to verify and serve one asset build.

Signature
head(key): Promise<AssetR2Object | null>;

Read immutable object metadata without loading its body.

Parameter Type
key string

Promise<AssetR2Object | null>

Signature
get(key): Promise<AssetR2Object & object | null>;

Read immutable object metadata and its streaming body.

Parameter Type
key string

Promise<AssetR2Object & object | null>


AppReleaseTransitionObligationtype alias

Section titled “AppReleaseTransitionObligation”
Signature
type AppReleaseTransitionObligation = object;

Durable catalog-scoped fact awaiting delivery to a separately owned Team.

Signature
readonly sequence: number;
Signature
readonly transition: ReleaseTransition;
Signature
readonly transitionId: AppTransitionId;
Signature
readonly affectedPublicSurfaceIds: readonly PublicSurfaceId[];
Signature
readonly affectedSurfaces: readonly AppReleaseAffectedSurface[];

Catalog-owned material needed by a Team without a second catalog read.

Signature
readonly affectedBuyerApps: readonly AppId[];
Signature
readonly enumeration: object;

The last opaque Global Team cursor and whether enumeration is complete.

Signature
readonly cursor: string | null;
Signature
readonly complete: boolean;
Signature
readonly state: "pending" | "acknowledged";

AppReleaseAffectedSurfacetype alias

Section titled “AppReleaseAffectedSurface”
Signature
type AppReleaseAffectedSurface = object;

Catalog-owned public-Surface material carried with a transition obligation.

Signature
readonly publicSurfaceId: PublicSurfaceId;
Signature
readonly appId: AppId;
Signature
readonly stableRoute: StableRoute;

AppReleaseTeamRecipienttype alias

Section titled “AppReleaseTeamRecipient”
Signature
type AppReleaseTeamRecipient = object;

Durable delivery state for one Team recipient of a transition obligation.

Signature
readonly teamId: string;
Signature
readonly state: "pending" | "applied" | "no-op" | "expired";

AppReleaseTeamRecipientPagetype alias

Section titled “AppReleaseTeamRecipientPage”
Signature
type AppReleaseTeamRecipientPage = object;

One ordered page of Team IDs returned by the separately owned Team directory.

Signature
readonly optional cursor?: string | null;

Null identifies the first page; all later cursors remain opaque strings.

Signature
readonly optional nextCursor?: string | null;
Signature
readonly teamIds: readonly string[];
Signature
readonly complete: boolean;

AppReleaseTeamRecipientOutcometype alias

Section titled “AppReleaseTeamRecipientOutcome”
Signature
type AppReleaseTeamRecipientOutcome = "applied" | "no-op" | "expired";

Terminal delivery outcome recorded for one Team recipient.


AppReleaseTransitionObligationStoretype alias

Section titled “AppReleaseTransitionObligationStore”
Signature
type AppReleaseTransitionObligationStore = object;

D1-only at-least-once read/ack seam; Team routing remains outside App Release.

Signature
readByTransitionId(transitionId): Promise<AppReleaseStoreResult<
| AppReleaseTransitionObligation
| {
kind: "absent";
}>>;

Read one obligation by its immutable transition identity, or report it absent.

Parameter Type
transitionId AppTransitionId

Promise<AppReleaseStoreResult< | AppReleaseTransitionObligation | { kind: "absent"; }>>

Signature
read(options): Promise<AppReleaseStoreResult<readonly AppReleaseTransitionObligation[]>>;

Read pending obligations after a sequence cursor in ascending sequence order.

Parameter Type
options { afterSequence?: number; limit?: number; }
options.afterSequence? number
options.limit? number

Promise<AppReleaseStoreResult<readonly AppReleaseTransitionObligation[]>>

Signature
recordTeamRecipientPage(sequence, page): Promise<AppReleaseStoreResult<
| AppReleaseTransitionObligation
| {
kind: "absent";
}>>;

Persist the next ordered Team-recipient page; identical replays are idempotent.

Parameter Type
sequence number
page AppReleaseTeamRecipientPage

Promise<AppReleaseStoreResult< | AppReleaseTransitionObligation | { kind: "absent"; }>>

Signature
readPendingTeamRecipients(options): Promise<AppReleaseStoreResult<readonly AppReleaseTeamRecipient[]>>;

Read pending recipients for one obligation in stable Team-ID order.

Parameter Type
options { sequence: number; limit?: number; }
options.sequence number
options.limit? number

Promise<AppReleaseStoreResult<readonly AppReleaseTeamRecipient[]>>

Signature
recordTeamRecipientOutcome(
sequence,
teamId,
outcome
): Promise<AppReleaseStoreResult<
| AppReleaseTeamRecipient
| {
kind: "absent";
}>>;

Record a pending recipient’s terminal outcome; conflicting replays fail.

Parameter Type
sequence number
teamId string
outcome AppReleaseTeamRecipientOutcome

Promise<AppReleaseStoreResult< | AppReleaseTeamRecipient | { kind: "absent"; }>>

Signature
acknowledge(sequence): Promise<AppReleaseStoreResult<
| AppReleaseTransitionObligation
| {
kind: "absent";
}>>;

Acknowledge only after enumeration is complete and no recipients remain pending.

Parameter Type
sequence number

Promise<AppReleaseStoreResult< | AppReleaseTransitionObligation | { kind: "absent"; }>>


AppReleaseSurfaceTransitionBasistype alias

Section titled “AppReleaseSurfaceTransitionBasis”
Signature
type AppReleaseSurfaceTransitionBasis =
| {
kind: "absent";
}
| {
kind: "ambiguous";
}
| {
kind: "none";
appId: AppId;
publicSurfaceId: PublicSurfaceId;
}
| {
kind: "selected";
appId: AppId;
publicSurfaceId: PublicSurfaceId;
releaseId: ReleaseId;
sequence: number;
eligibility: "eligible" | "ineligible";
checkedAt: number;
};

Selected Release basis from the same D1 authority snapshot, including its transition sequence.

Signature
{
kind: "absent";
}

Signature
{
kind: "ambiguous";
}

Signature
{
kind: "none";
appId: AppId;
publicSurfaceId: PublicSurfaceId;
}

Signature
{
kind: "selected";
appId: AppId;
publicSurfaceId: PublicSurfaceId;
releaseId: ReleaseId;
sequence: number;
eligibility: "eligible" | "ineligible";
checkedAt: number;
}
Name Type Description
kind "selected" -
appId AppId -
publicSurfaceId PublicSurfaceId -
releaseId ReleaseId -
sequence number -
eligibility "eligible" | "ineligible" -
checkedAt number Authority-read start time; consumers may only shorten its horizon.

AppReleaseD1QueryResulttype alias

Section titled “AppReleaseD1QueryResult”
Signature
type AppReleaseD1QueryResult = object;

Structural result returned by the D1 operations used by App Release.

Signature
readonly success: boolean;

Whether D1 completed the operation successfully.

Signature
readonly results: readonly unknown[];

Untrusted row values returned by the operation.


AppReleaseD1PreparedStatementtype alias

Section titled “AppReleaseD1PreparedStatement”
Signature
type AppReleaseD1PreparedStatement = object;

Structural prepared-statement surface needed by the D1-backed store.

Signature
bind(...values): AppReleaseD1PreparedStatement;

Bind positional values and return the statement to execute.

Parameter Type
…values unknown[]

AppReleaseD1PreparedStatement

Signature
first(): Promise<object | null>;

Read the first untrusted row, or null when none exists.

Promise<object | null>

Signature
all(): Promise<AppReleaseD1QueryResult>;

Read all matching rows.

Promise<AppReleaseD1QueryResult>

Signature
run(): Promise<AppReleaseD1QueryResult>;

Execute a mutating statement.

Promise<AppReleaseD1QueryResult>


AppReleaseD1Databasetype alias

Section titled “AppReleaseD1Database”
Signature
type AppReleaseD1Database = object;

Structural D1 surface kept independent of Cloudflare vendor declarations.

Signature
prepare(query): AppReleaseD1PreparedStatement;

Prepare one SQL statement for binding and execution.

Parameter Type
query string

AppReleaseD1PreparedStatement

Signature
batch(statements): Promise<readonly AppReleaseD1QueryResult[]>;

Execute a group of statements atomically in native D1.

Parameter Type
statements readonly AppReleaseD1PreparedStatement[]

Promise<readonly AppReleaseD1QueryResult[]>


AppReleaseR2Objecttype alias

Section titled “AppReleaseR2Object”
Signature
type AppReleaseR2Object = object;

Structural R2 object surface needed by the artifact reader.

Signature
readonly version: string;

Native immutable object version checked for referenced App children.

Signature
readonly size: number;

Object size in bytes, checked before the body is buffered.

Signature
readonly optional httpMetadata?: object;

HTTP metadata retained with the object, when present.

Signature
readonly optional contentType?: string;

Declared media type for the stored object.

Signature
arrayBuffer(): Promise<ArrayBuffer>;

Read the immutable object body.

Promise<ArrayBuffer>


AppReleaseR2Buckettype alias

Section titled “AppReleaseR2Bucket”
Signature
type AppReleaseR2Bucket = object;

Structural R2 surface kept independent of Cloudflare vendor declarations.

Signature
get(key): Promise<AppReleaseR2Object | null>;

Read one object by its opaque storage key.

Parameter Type
key string

Promise<AppReleaseR2Object | null>


ErasureBuckettype alias

Section titled “ErasureBucket”
Signature
type ErasureBucket = AppReleaseR2Bucket & object;

R2 operations used by the scoped Team erasure owner.

Name Type Description
head() (key) => Promise<object | null> Read the metadata for an exact object key.
delete() (key) => Promise<void> Delete an exact object key after catalog references are checked.

ArtifactSnapshotPolicytype alias

Section titled “ArtifactSnapshotPolicy”
Signature
type ArtifactSnapshotPolicy = Readonly<{
maxBytes: number;
maxManifestBytes?: number;
}>;

Trusted composition limit for reading one immutable artifact.

appArtifactErasureReadbackSchemaconstant

Section titled “appArtifactErasureReadbackSchema”
Signature
const appArtifactErasureReadbackSchema: Struct<{
clear: Boolean;
personalClear: Boolean;
retainedArtifacts: $Array<
Struct<{
disposition_id: String;
app_id: refine<AppId, String>;
release_ids_json: String;
artifact_roots_json: String;
created_at: Number;
state: Literals<
readonly ["pending", "retaining", "retained", "revoking", "revoked"]
>;
request_id: NullOr<String>;
reason: NullOr<String>;
completed_at: NullOr<Number>;
releaseIds: $Array<refine<ReleaseId, String>>;
}>
>;
remaining: $Array<String>;
pending: $Array<String>;
obligationTeams: $Array<String>;
obligationPages: $Array<String>;
objects: $Array<String>;
}>;

The erasure coordinator consumes this owner-issued readback, including outstanding buyer custody.


APP_RELEASE_D1_FRESH_SCHEMAconstant

Section titled “APP_RELEASE_D1_FRESH_SCHEMA”
Signature
const APP_RELEASE_D1_FRESH_SCHEMA: string;

The one current App Release D1 schema for an empty catalog.

createTeamAppReleaseErasure()function

Section titled “createTeamAppReleaseErasure()”
Signature
function createTeamAppReleaseErasure(
database,
bucket,
assetPolicy?,
now?,
): object;

Read every catalog reference before deleting content-addressed R2 objects.

Parameter Type Default value
database AppReleaseD1Database undefined
bucket ErasureBucket undefined
assetPolicy? { maxManifestBytes: number; maxObjects: number; maxObjectBytes: number; maxTotalBytes: number; } undefined
assetPolicy.maxManifestBytes? number positiveInteger
assetPolicy.maxObjects? number positiveInteger
assetPolicy.maxObjectBytes? number positiveInteger
assetPolicy.maxTotalBytes? number positiveInteger
now? () => number Date.now
Name Type Description
verifyManifest() ( teamId, appIds, keys ) => Promise<{ teamId: string; apps: object[]; repositories: string[]; }> Reject any live App or R2 key outside this Team’s current or retry scope.
preflight() (teamId) => Promise<{ teamId: string; apps: object[]; repositories: string[]; }> Inventory Team catalog rows, exclusive objects, and source repositories.
erase() (teamId) => Promise<{ apps: number; }> Remove one Team’s catalog and exclusive objects, resuming pending jobs.
readback() ( teamId, appIds, keys ) => Promise<{ clear: boolean; personalClear: boolean; retainedArtifacts: object[]; remaining: string[]; pending: string[]; obligationTeams: string[]; obligationPages: string[]; objects: string[]; }> Verify the named Apps, pending jobs, obligations and exclusive objects.

createD1TeamAppPublisherRegistry()function

Section titled “createD1TeamAppPublisherRegistry()”
Signature
function createD1TeamAppPublisherRegistry(database): TeamAppPublisherRegistry;

Create the native registry that joins a Team publisher to one App/source.

Parameter Type
database AppReleaseD1Database

TeamAppPublisherRegistry


createD1AppReleaseStore()function

Section titled “createD1AppReleaseStore()”
Signature
function createD1AppReleaseStore(database): PromiseAppReleaseStore & object;

Create the D1-backed App Release store with private public-website authority.

Parameter Type
database AppReleaseD1Database

PromiseAppReleaseStore & object


createR2ArtifactReader()function

Section titled “createR2ArtifactReader()”
Signature
function createR2ArtifactReader(bucket, policy?, assets?): ArtifactReader;

Create the R2-backed artifact reader for opaque artifact references.

Asset manifests are verified cheaply for delivery: the root bytes are digest-checked here, while the asset handler checks the requested object. Publication callers pass verification: "publication" to retain the complete manifest object sweep.

Parameter Type Default value
bucket AppReleaseR2Bucket undefined
policy ArtifactSnapshotPolicy DEFAULT_ARTIFACT_SNAPSHOT_POLICY
assets? { bucket: Pick<AssetR2Bucket, "head">; policy: { maxManifestBytes: number; maxObjects: number; maxObjectBytes: number; maxTotalBytes: number; }; } undefined
assets.bucket? Pick<AssetR2Bucket, "head"> undefined
assets.policy? { maxManifestBytes: number; maxObjects: number; maxObjectBytes: number; maxTotalBytes: number; } undefined
assets.policy.maxManifestBytes? number positiveInteger
assets.policy.maxObjects? number positiveInteger
assets.policy.maxObjectBytes? number positiveInteger
assets.policy.maxTotalBytes? number positiveInteger

ArtifactReader


createD1TransitionObligationStore()function

Section titled “createD1TransitionObligationStore()”
Signature
function createD1TransitionObligationStore(
database,
): AppReleaseTransitionObligationStore;

Open the D1-only obligation adjunct for a future owner-driven dispatcher. The ordinary App Release store contract intentionally does not expose it.

Parameter Type
database AppReleaseD1Database

AppReleaseTransitionObligationStore


readD1SurfaceTransitionBasis()function

Section titled “readD1SurfaceTransitionBasis()”
Signature
function readD1SurfaceTransitionBasis(
database,
stableRoute,
releaseId,
now?,
): Promise<AppReleaseStoreResult<AppReleaseSurfaceTransitionBasis>>;

Resolve one previously selected Release on a Surface and retain the exact transition sequence. The Release need not remain the Surface’s current default, but it must still be verified, active, and owned by that Surface.

Parameter Type Default value
database AppReleaseD1Database undefined
stableRoute StableRoute undefined
releaseId ReleaseId undefined
now () => number Date.now

Promise<AppReleaseStoreResult<AppReleaseSurfaceTransitionBasis>>


matchEligibleSurfaceTransitionBasis()function

Section titled “matchEligibleSurfaceTransitionBasis()”
Signature
function matchEligibleSurfaceTransitionBasis(
result,
expected,
): {
kind: "selected";
appId: AppId;
publicSurfaceId: PublicSurfaceId;
releaseId: ReleaseId;
sequence: number;
eligibility: "eligible" | "ineligible";
checkedAt: number;
} | null;

Match one eligible selected Release without leaking store-result branching to consumers.

Parameter Type
result AppReleaseStoreResult<AppReleaseSurfaceTransitionBasis>
expected Readonly<{ appId: AppId; releaseId: ReleaseId; sequence?: number; }>
Signature
{
kind: "selected";
appId: AppId;
publicSurfaceId: PublicSurfaceId;
releaseId: ReleaseId;
sequence: number;
eligibility: "eligible" | "ineligible";
checkedAt: number;
}
Name Type Description
kind "selected" -
appId AppId -
publicSurfaceId PublicSurfaceId -
releaseId ReleaseId -
sequence number -
eligibility "eligible" | "ineligible" -
checkedAt number Authority-read start time; consumers may only shorten its horizon.

null