Skip to content

[Feat] Add Cloudflare AI Gateway and Workers AI model providers - #3242

Open
pridemusvaire wants to merge 2 commits into
RooCodeInc:developfrom
pridemusvaire:feat/cloudflare-inference-providers-catalog
Open

pridemusvaire wants to merge 2 commits into
RooCodeInc:developfrom
pridemusvaire:feat/cloudflare-inference-providers-catalog

Conversation

@pridemusvaire

Copy link
Copy Markdown
Contributor

What

Adds Cloudflare AI Gateway and Cloudflare Workers AI as built-in task-model providers on develop's catalog-driven provider architecture.

cloudflare-ai-gateway/openai/...            -> Cloudflare /ai/v1 (unified REST surface)
cloudflare-ai-gateway/workers-ai/@cf/...    -> Cloudflare /ai/v1
cloudflare-workers-ai/@cf/...               -> Cloudflare /ai/v1

Env vars: CLOUDFLARE_AI_GATEWAY_API_TOKEN, CLOUDFLARE_AI_GATEWAY_ACCOUNT_ID, CLOUDFLARE_AI_GATEWAY_ID (AI Gateway), CLOUDFLARE_WORKERS_AI_API_TOKEN, CLOUDFLARE_WORKERS_AI_ACCOUNT_ID (Workers AI).

The port

  • Setup catalog (packages/types/src/model-provider-config.ts): two SETUP_MODEL_PROVIDER_CATALOG entries following the Azure AI Foundry pattern (additionalEnvFields for account id and gateway id, authKind: 'api-key'), plus both ids in ENABLED_DIRECT_TASK_MODEL_PROVIDER_IDS. Credential env-var forwarding derives from the catalog.
  • Full OpenCode registration (packages/types/src/cloudflare-opencode-provider.ts, following the bedrock-opencode-provider.ts / kimi-for-coding-opencode-provider.ts pattern): neither provider depends on OpenCode's models.dev catalog; OpenCode gets @ai-sdk/openai-compatible, the /accounts/<id>/ai/v1 base URL, the key, and (AI Gateway) the cf-aig-gateway-id header. Wired into the task worker (agent-home.ts) and the non-task helper runtime (opencode-runtime.ts), including the operator-supplied OPENCODE_CONFIG_CONTENT path where reasoning merges before registrations onto the rewritten model id.
  • Inference gateway (apps/api): requiredHeaders on the gateway provider schema injects cf-aig-gateway-id from the deployment env (identity-pattern validated); the request body's model field is rewritten so models.dev's workers-ai/@cf/... slug reaches Cloudflare as @cf/....
  • Model-id rewrites shared through @roomote/types (rewriteCloudflareOpenCodeModelId and friends) so task, helper, and gateway paths all address Cloudflare with the same id.
  • Web: catalog flows drive the setup and settings surfaces automatically; docs links registered.
  • Docs: two provider pages, navigation, environment-variables table, models table, README/SELF_HOSTING.
  • Deployment plumbing: the checked-in Compose files, PM2 config, and env examples pass the five Cloudflare vars to the control-plane services.

Supersedes

#3015 and #2809, which were built on the pre-catalog provider registration architecture and now conflict with develop. Their review findings (missing Cloudflare registration under operator config content, reasoning merged under the un-rewritten id) are covered here, with tests.

Verified

  • packages/types: 157 tests (incl. the new cloudflare-opencode-provider suite) - pass
  • packages/cloud-agents: 143 tests (opencode-runtime, non-task-provider-usage) - pass
  • apps/worker: 93 agent-home tests - pass
  • apps/api: 80 inference-gateway tests - pass
  • apps/web: 59 + 31 + 31 tests (task-models lookup, models-dev, setup docs) - pass
  • pnpm exec turbo check-types: 27/27 packages clean
  • pnpm lint:fast + pnpm exec oxlint --deny-warnings: clean
  • gitleaks detect: no leaks

…on the catalog architecture. Operators connect one Cloudflare token, account, and gateway id (AI Gateway) or token and account (Workers AI); OpenCode registers both providers in full, the inference gateway injects the cf-aig-gateway-id header and rewrites Workers AI catalog slugs onto Cloudflare's /ai/v1 surface, and non-task helpers reuse the same registration so configured reasoning applies.
@roomote-community

roomote-community Bot commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

No code issues found. See task

  • packages/types/src/model-provider-config.ts:636 Cloudflare helper inference drops the required account and gateway values when R_MODEL_ENV_KEYS is set.

Reviewed 71d2ce7

Comment thread packages/types/src/model-provider-config.ts
…s. R_MODEL_ENV_KEYS adds custom provider credentials; it does not replace the catalog-derived set, so a Cloudflare model still forwards its required account and gateway values to helper inference when custom key names are configured.
@pridemusvaire

Copy link
Copy Markdown
Contributor Author

Fixed in 71d2ce7. R_MODEL_ENV_KEYS was replacing the catalog-derived provider env keys at the runtime resolver (packages/db resolveProviderKeyNames), unlike every forwarder which unions them; selected catalog models now keep their own env keys alongside custom names, so the required Cloudflare account and gateway values reach helper inference. Covered by a new packages/db test.

@pridemusvaire
pridemusvaire marked this pull request as ready for review September 27, 2026 05:02
@pridemusvaire

Copy link
Copy Markdown
Contributor Author

@roomote-community please review this pull request again and flag anything outstanding

@roomote-community

roomote-community Bot commented Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

@roomote-community please review this pull request again and flag anything outstanding

Re-reviewing the current head, including the R_MODEL_ENV_KEYS fix and the Cloudflare runtime paths, for any remaining actionable issues.

Open in Roomote

Re-reviewing the current head. Findings, if any, will be posted directly on the pull request.

@roomote-community

Copy link
Copy Markdown
Contributor

No outstanding code issues found at 71d2ce7. All listed CI checks are passing.

Reply anytime · Open in Roomote

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant