Skip to content

Rhumbatron Operations Guide

These runbooks tell operators how to run Rhumbatron environments, infrastructure, quotas, and deployments.

  1. Terraform-only remote control plane: Terraform manages all remote Cloudflare infrastructure and Worker deployments. Do not make manual dashboard changes. Do not run wrangler deploy (AGENTS.md section 2, ADR 0004).
  2. Quota and free-tier discipline: Stay within Cloudflare free and included limits and within the model spend caps (AGENTS.md section 7 and rule 50).
  3. Executable Evidence gates: Releases and promotions depend on machine-verifiable Evidence. Model confidence and unverified claims never pass a gate.

Runbook Purpose Primary Commands
Deployment Terraform deployments for dev, prod, and global; bundle generation; bootstrap/apex switches; D1 migration ordering. bun run cf:bundle
bun run tf:plan:dev / tf:apply:dev
bun run tf:plan:prod / tf:apply:prod
bun run tf global <args>
bun run tf:drift / tf:drift:prod
bun run smoke:dev / smoke:prod
Pause & Resume Global paused switch that stops background cron sweeps and container execution to save quota. bun run tf:plan:<env> / tf:apply:<env>
Cleanup & Retention Smoke-test Project cleanup, the Project archive pipeline, daily fork sweeps, and R2 retention lifecycles. bun run cleanup:projects
bun run cleanup:projects --dry-run
Costs & Budgets Cost reports, guard layers, budget ceilings (Sandbox, Browser Run, Vertex AI), account budget alerts, call quotas, and recovery after a cap trips. bun run cost:report
bun run cost:report --alerts-only
Application Releases Cloudflare Workers Builds releases (blocked: no Artifacts connection yet), smoke verification, one-time dashboard/CLI setup, and failure injection. bun run smoke:release
bun run inject --only=release-smoke-failure
Resource Naming Conventions for naming and tagging Cloudflare resources and Workers. bun run check:guardrails

Section titled “Related Architecture Decision Records (ADRs)”