Rhumbatron Operations Guide
These runbooks tell operators how to run Rhumbatron environments, infrastructure, quotas, and deployments.
Core Policies
Section titled “Core Policies”- Terraform-only remote control plane: Terraform manages all remote Cloudflare infrastructure and Worker deployments. Do not make manual dashboard changes. Do not run
wrangler deploy(AGENTS.mdsection 2, ADR 0004). - Quota and free-tier discipline: Stay within Cloudflare free and included limits and within the model spend caps (
AGENTS.mdsection 7 and rule 50). - Executable Evidence gates: Releases and promotions depend on machine-verifiable Evidence. Model confidence and unverified claims never pass a gate.
Runbook Index
Section titled “Runbook Index”| Runbook | Purpose | Primary Commands |
|---|---|---|
| Deployment | Terraform deployments for dev, prod, and global; bundle generation; bootstrap/apex switches; D1 migration ordering. | bun run cf:bundlebun run tf:plan:dev / tf:apply:devbun run tf:plan:prod / tf:apply:prodbun run tf global <args>bun run tf:drift / tf:drift:prodbun run smoke:dev / smoke:prod |
| Pause & Resume | Global paused switch that stops background cron sweeps and container execution to save quota. |
bun run tf:plan:<env> / tf:apply:<env> |
| Cleanup & Retention | Smoke-test Project cleanup, the Project archive pipeline, daily fork sweeps, and R2 retention lifecycles. | bun run cleanup:projectsbun run cleanup:projects --dry-run |
| Costs & Budgets | Cost reports, guard layers, budget ceilings (Sandbox, Browser Run, Vertex AI), account budget alerts, call quotas, and recovery after a cap trips. | bun run cost:reportbun run cost:report --alerts-only |
| Application Releases | Cloudflare Workers Builds releases (blocked: no Artifacts connection yet), smoke verification, one-time dashboard/CLI setup, and failure injection. | bun run smoke:releasebun run inject --only=release-smoke-failure |
| Resource Naming | Conventions for naming and tagging Cloudflare resources and Workers. | bun run check:guardrails |
Related Architecture Decision Records (ADRs)
Section titled “Related Architecture Decision Records (ADRs)”- ADR 0004: Resource organization and bootstrap credentials
- ADR 0005: Durable Object Worker deploys
- ADR 0007: OpenRouter free models
- ADR 0010: Artifacts project source
- ADR 0011: Sandbox workspaces
- ADR 0012: Sandbox worker
- ADR 0014: Workers Builds connection to Artifacts
- ADR 0016: Gemini overflow
- ADR 0017: Prod environment
- ADR 0018: Release via Workers Builds
- ADR 0019: Runaway-billing guards