An unofficial, community-maintained one-click Cloudflare deployment template for oomol-lab/open-connector.
This repository follows stable OpenConnector releases and packages them for Cloudflare Workers. It is not affiliated with or endorsed by OOMOL.
Clicking the button asks Cloudflare to:
- Create a new copy of this repository in your GitHub or GitLab account.
- Create and bind a D1 database as
DB. - Create and bind an R2 bucket as
TRANSIT_FILES. - Ask you for the two required Worker secrets listed below.
- Apply the D1 migrations, build the Web Console, and deploy the Worker.
- Connect the new repository to Workers Builds for future deployments.
The generated repository belongs to you. It is a standalone copy rather than a GitHub fork.
Generate two different long random values and save them in a password manager:
| Secret | Purpose |
|---|---|
OOMOL_CONNECT_ADMIN_TOKEN |
Signs in to the Web Console and authenticates the admin API. |
OOMOL_CONNECT_ENCRYPTION_KEY |
Encrypts stored credentials and OAuth client configuration inside D1. |
Do not reuse one value for both secrets. If the encryption key is lost or changed, existing encrypted credentials cannot be recovered.
OOMOL_CONNECT_RUNTIME_TOKEN is optional. You can create runtime tokens later from the Web
Console, so the one-click deployment does not request it.
The included GitHub Actions workflow checks the latest stable upstream Release every day at 04:02 Beijing time (20:02 UTC). When a new release is available, it:
- Replaces the application source with the immutable upstream Release.
- Restores this template's Cloudflare configuration and update workflow.
- Installs dependencies and runs lint, formatting, type checks, tests, the Web Console build, and a Wrangler dry run.
- Pushes the verified update to
main. - Lets Cloudflare Workers Builds deploy the new commit and apply pending D1 migrations.
If validation fails, no commit is pushed and the currently deployed version keeps running. Code-only updates do not delete D1 data, R2 objects, custom domains, or Worker secrets.
The sync also reserves headroom below Cloudflare Free plan hard limits. It stops before updating
main if the Worker gzip size exceeds 2.7 MiB, an individual static asset exceeds 23 MiB, or the
build contains more than 18,000 static assets. The workflow log identifies the exceeded guard so a
release that has outgrown the Free plan is not deployed automatically.
The workflow intentionally restores upstream application files on every release. Keep deployment
customizations in Cloudflare settings or in separate branches; custom changes to tracked
application files on main may be replaced by the next automatic update.
You can also run the update immediately from Actions → Sync latest upstream release → Run workflow.
The optional canary branch is isolated from production and can track either upstream main or a
branch from the owner's source fork. Run Actions → Sync canary source, choose
oomol-lab/open-connector or LJAYi/open-connector, and enter a branch, tag, or full commit SHA.
The workflow resolves the selection to an immutable commit, runs the complete validation suite and
Cloudflare Free plan guard, then updates only canary.
Connect canary to a separate Worker named open-connector-canary. Use an independent D1 database
and R2 bucket, then set their identifiers as the GitHub repository variables
CANARY_D1_DATABASE_ID and CANARY_R2_BUCKET_NAME. The sync writes those non-secret identifiers
into the canary Wrangler config. Do not bind the canary Worker to production storage. Scheduled
canary syncs follow oomol-lab/open-connector@main daily at 04:32 Beijing time.
The Deploy to Cloudflare button is recommended. For a manual deployment:
npm install
npx wrangler login
npx wrangler secret put OOMOL_CONNECT_ADMIN_TOKEN
npx wrangler secret put OOMOL_CONNECT_ENCRYPTION_KEY
npm run deployThe deployment command generates the provider catalog, builds the Web Console, applies D1 migrations, and deploys the Worker.
When connecting this repository to an existing Worker, add these two Workers Builds variables:
OPEN_CONNECT_D1_DATABASE_ID: the UUID of the existing D1 database.OPEN_CONNECT_R2_BUCKET_NAME: the name of the existing R2 bucket.
Run npm run configure:cloudflare-resources before migrations and deployment. The command updates
only the temporary build checkout. If neither variable is set, automatic resource provisioning
continues to work for new one-click deployments.
This template uses R2 for temporary transit files so it supports files larger than Workers KV's per-value limit. Depending on your Cloudflare account, enabling R2 may require a payment method, even when usage stays within the free allowance. OpenConnector also supports KV when configured manually; see the upstream Cloudflare guide.
- OpenConnector source and documentation: oomol-lab/open-connector
- Template deployment issues: LJAYi/open-connector-cloudflare/issues
- Cloudflare Deploy Button documentation: Deploy to Cloudflare buttons
OpenConnector is licensed under the Apache License, Version 2.0. The upstream license and notices are preserved in LICENSE.txt and NOTICE.md.
这是 oomol-lab/open-connector 的非官方 Cloudflare 一键部署模板,由社区维护,并非 OOMOL 官方项目。
点击上方按钮后,Cloudflare 会在你的 GitHub 或 GitLab 账户中创建一个独立的新仓库, 自动创建并绑定 D1 和 R2,要求填写管理员 Token 与加密密钥,然后完成数据库迁移、前端 构建和 Worker 部署。它不会要求你预先 Fork 上游仓库。
部署完成后,新仓库的 main 每次产生提交,Cloudflare Workers Builds 都会自动构建和
部署。仓库内置的 GitHub Actions 会在北京时间每天凌晨 04:02 检查上游正式 Release;
只有在完整验证通过后才更新 main。代码更新不会删除 D1、R2、域名或 Worker Secrets。
同步流程还会预留 Cloudflare 免费计划的安全余量:Worker gzip 超过 2.7 MiB、单个静态
资源超过 23 MiB,或者静态资源超过 18,000 个时停止更新 main,避免自动部署已经不再
适合免费计划的上游版本。
必须妥善保存并使用两个不同的随机值:
OOMOL_CONNECT_ADMIN_TOKEN:登录 Web Console 和调用管理接口。OOMOL_CONNECT_ENCRYPTION_KEY:加密 D1 中保存的凭据和 OAuth 配置;丢失后无法解密 已有数据。
如需测试官方 main 或个人源码分支,可使用 Actions → Sync canary source。该流程只更新
canary 分支,并应连接到独立的 open-connector-canary Worker、D1 数据库和 R2 存储桶;
不要让测试环境复用生产数据。定时任务会在北京时间每天 04:32 同步官方 main,也可以
手动选择 LJAYi/open-connector 中的任意分支、tag 或完整 commit SHA。
Runtime Token 无需在首次部署时创建,之后可以在 Web Console 中按需创建多个。
如果要把本仓库连接到已有 Worker,可在 Workers Builds 中同时设置
OPEN_CONNECT_D1_DATABASE_ID 和 OPEN_CONNECT_R2_BUCKET_NAME,并在迁移和部署前运行
npm run configure:cloudflare-resources。资源 ID 只会写入临时构建目录,不会提交到仓库。