How to Get Started with Cloudflare OS: Six Steps to Adoption
Key point: The basic Cloudflare OS setup starts by deploying the official cloudflare-os-starter to your Cloudflare account, then configuring Access authentication and AI Gateway. Technical setup alone does not guarantee business value: success depends on workflow selection → Limited PoC → governance → phased rollout.
What You Need Before You Start
- Cloudflare account — Cloudflare OS runs within your own Cloudflare account.
- Workers Paid plan — Required for key capabilities such as Dynamic Workers (starting at $5 per month per account).
- Official starter — cloudflare-os-starter. This is the foundation for the deployment.
- IdP (identity provider) — Connect Cloudflare Access to your existing IdP for employee authentication.
- Candidate workflows — Not a technical requirement, but without one the PoC cannot be evaluated.
For cost details, see the Pricing and Cost Guide.
Basic Setup Flow
The technical setup follows four basic steps.
- Get the official starter — Create your own repository from cloudflare-os-starter. The official guidance requires pinning releases and reviewing changes. Because the product continues to change during Early Access, track the version in use and review differences before applying updates.
- Deploy to your Cloudflare account — The workspace is created within your account.
- Configure authentication with Cloudflare Access — Connect your existing IdP and control who can access the workspace.
- Configure AI Gateway — Set model choices, budgets, rate limits, and cost visibility before use so metered AI inference costs remain controlled.
At this point, employees can sign in through a browser and work with AI agents. Add internal-system connections through Gatekeeper and MCP one system at a time. Custom integrations require development and are not entirely no-code.
For commands and configuration files, see the Deployment Guide. For internal data connections, see the Gatekeeper Guide.
Six Steps for Organizational Adoption
Because Cloudflare OS is in Early Access, use a phased rollout instead of a company-wide launch. Define an exit criterion for each step and advance only after it is met.
-
Workflow selection
Select one or two workflows and agree on a KPI. Exit criterion: measurable targets are approved.
-
Limited PoC
Validate value and usability with five to ten people, primarily using read-only access. Exit criterion: expected impact against the target KPI is clear.
-
Identity and AI governance
Configure Access, IdP integration, and AI Gateway. Exit criterion: users and inference costs are under control.
-
Gatekeeper and MCP connection
Connect one system first and expand gradually. Exit criterion: action approval, denial, and logging work as designed.
-
Approval-gated writes
Use a human-in-the-loop control to enable selected write actions. Exit criterion: approval flows and audit records operate reliably.
-
Departmental rollout
Expand with training and an operating model. Exit criterion: each department can use and operate the system independently.
Common Pitfalls
Treating deployment as the finish line
Deploying open-source software alone does not change a workflow. A PoC without clear decisions about the workflow, users, and delegated tasks often ends after a brief trial. Define the workflow and KPI before setup.
Enabling write access too early
Cloudflare OS starts with zero permissions, but the implementation determines whether that model remains effective. Prompt injection and authorization errors are still risks. Begin with read-only access and enable writes gradually with human approval.
Following upstream updates without review
Changes will continue during Early Access. Pin the release and establish a process for reviewing updates before applying them, as required by the official starter.
Deferring training and adoption
Even with the platform in place, adoption will stall if employees do not understand how to use it or the internal rules. Include administrator and user training, plus departmental champions, in the rollout plan.
We can support setup, initial configuration, hands-on enablement, and PoC design.
Discuss Your Adoption