Architect: start

What’s supported

The provider Architect runs on, every kind of resource it sees, which settings it changes, what it can make, remove, scale, and restart, what it never touches, and its limits.

Architect runs on Cloudflare in 2.0. It sees what an environment runs by starting at its target, a Worker, and following what that Worker reaches: the Workers it calls, and every database, namespace, bucket, queue, Durable Object, container, route, and custom domain they use. Nothing outside that scope is read or kept.

#Kinds of resource

Each resource in an environment’s file has a kind. These are Cloudflare’s:

KindWhat it isThe settings Architect managesMakeRemove
workerA WorkerCompatibility date and flags, usage model, Workers Logs, placement, cron triggers, and bindingsYes: it starts with a small module that answers /health until your deploy puts its code on itYes, and it can’t be undone
durable-objectA Durable Object namespaceNone: its class and the Worker that has itBy code: the Worker exports the class, and a migration in its wrangler config adds itBy a delete migration, and its data goes
d1A D1 databaseNone. Its schema is your repository’s migrationsYesYes, and its data goes
kvA KV namespaceNoneYesYes, and its values go
r2An R2 bucketCORS rules and lifecycle rulesYesOnly when it’s empty: Cloudflare refuses otherwise
queueA queueDelivery delay, delivery paused, retention, and most consumers at onceYesYes, and its messages go
containerA container applicationMost instancesBy code: the image, the Durable Object class that starts it, and the container in the Worker’s wrangler configYes, and it can’t be undone
routeA route: a hostname and path sent to a WorkerIts pattern and its WorkerYesYes, and it can be put back
custom-domainA hostname a Worker servesIts WorkerYesYes; the hostname stops answering until it’s attached again

A setting the file leaves out isn’t compared, so it stays the deploy’s. A Worker’s variables and secrets show by name only, and are set with its deploy, never by Architect. A Durable Object or a container can be added on the console, which says what code must exist first: its plan applies only once that code is deployed.

Changes to a route or a custom-domain decide who reaches what, so the policy’s access guard makes every one of them wait for you, whatever your allow rules say (Policy).

#Scale and restart

Envelopes let the board scale and restart without asking you each time. On Cloudflare, two kinds can:

KindScaleRestart
container, on the default scheduling policyIts most instances (max_instances)A rollout of its current configuration: each instance is replaced in turn, with time to drain
queue, with a Worker consumerIts consumer’s concurrency (max_concurrency)No

Cloudflare scales everything else by itself, so nothing else is offered. A container on the Durable Object scheduling policy, or a queue with no Worker consumer, is refused in words before anything is planned.

#Health

The board reads each resource’s health when it looks, every 15 minutes, and when you press Refresh:

The board reads health with the read-only token, through Cloudflare’s analytics. It reads no logs, traces, or metrics beyond these.

#What it never touches

#What isn’t supported yet

#Limits

WhatLimit
Environments per repository50, with at most 3 short-lived ones at once
Resources in one environment’s file500, in at most 256 KB
Edits in one change on the console50
Plan previews on the console6 a minute per environment
infra check previews10 a minute per repository
Plan checks on one pull requestUp to 5 environments
How often the board looks at what runsEvery 15 minutes, and on Refresh
How often it compares for driftAt most once an hour per environment, and as soon as its file changes
One apply’s lock on an environment15 minutes, renewed while it works
SignalsKept 7 days; their daily summaries 90
The audit trailKept two years