
Cloudflare Run
CertifiedRun inline code on a Cloudflare gateway Worker (Dynamic Workers)
Cloudflare Run
Run inline code on a Cloudflare gateway Worker (Dynamic Workers)
POSTs inline JavaScript or TypeScript to a gateway Worker URL that calls env.LOADER.load(...) to run the code on the edge.
type: io.kestra.plugin.cloudflare.workers.dynamic.RunExamples
Run a JS snippet on the edge via a gateway Worker
id: run_dynamic_worker
namespace: company.team
tasks:
- id: run
type: io.kestra.plugin.cloudflare.workers.dynamic.Run
gatewayUrl: "https://loader.acme.workers.dev"
headers:
Authorization: "Bearer {{ secret('GATEWAY_TOKEN') }}"
payload:
user: "alice"
action: "greet"
script: |
export default {
async fetch(request) {
const body = await request.json();
return Response.json({ hello: body.user });
}
};
Properties
gatewayUrl *Requiredstring
Gateway URL
Absolute URL of the gateway Worker. The URL is used as-is; restrict reachable hosts via Kestra worker egress controls.
script *Requiredstring
Inline script
JavaScript or TypeScript source to execute on the edge. Sent as the script field of the JSON envelope.
contentType string
Content type
Content type sent to the gateway. Defaults to application/json.
headers object
Extra headers
Optional HTTP headers added to the request, typically for auth (e.g. Authorization, CF-Access-Client-Id).
options Non-dynamic
HTTP client options
Optional advanced HTTP settings like timeouts or proxy.
io.kestra.core.http.client.configurations.HttpConfiguration
falseIf true, allow a failed response code (response code >= 400)
List of response code allowed for this request
The authentication to use.
io.kestra.core.http.client.configurations.BasicAuthConfiguration
The password for HTTP basic authentication.
The username for HTTP basic authentication.
io.kestra.core.http.client.configurations.BearerAuthConfiguration
The token for bearer token authentication.
io.kestra.core.http.client.configurations.DigestAuthConfiguration
The password for HTTP Digest authentication.
The username for HTTP Digest authentication.
The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
durationThe time allowed to establish a connection to the server before failing.
durationThe time an idle connection can remain in the client's connection pool before being closed.
UTF-8The default charset for the request.
java.nio.charset.Charset
trueWhether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).
Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.
trueWhether redirects should be followed automatically.
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIEDThe log level for the HTTP client.
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODYThe enabled log.
The maximum content length of the response.
The proxy configuration.
io.kestra.core.http.client.configurations.ProxyConfiguration
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTDIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
durationThe time allowed for a read connection to remain idle before closing it.
durationThe maximum time allowed for reading data from the server before failing.
The SSL request options
io.kestra.core.http.client.configurations.SslOptions
Whether to disable checking of the remote SSL certificate.
Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.
The timeout configuration.
io.kestra.core.http.client.configurations.TimeoutConfiguration
The time allowed to establish a connection to the server before failing.
PT5MThe time allowed for a read connection to remain idle before closing it.
payload object
Payload
Optional JSON payload sent under the payload field of the envelope. The gateway Worker forwards it to the loaded module.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
Outputs
body string
Response body
Raw response body from the gateway Worker, returned as-is.
headers object
Response headers
Headers returned by the gateway Worker.
statusCode integer
HTTP status
Status code returned by the gateway Worker.