[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3cxyi7tyo14sz":3,"$fanuq43nlrv5g":57},{"slug":4,"title":5,"body":6,"summary":7,"tags":8,"author":14,"cover_url":15,"published_at":16,"seo_title":17,"seo_description":18,"reading_minutes":19,"related":20},"deno-deploy-shutdown-exit-guide","Deno Deploy shuts down in six months: moving a small app to Cloudflare Workers, self-hosted Deno in Docker, or Node","\u003Cp>On 9 October 2026 Ryan Dahl announced that the whole Deno team is joining Cloudflare. Two lines in the post set your deadlines. Deno Deploy \"will continue operating for six months before shutting down\", with migration help for paying customers moving to Cloudflare Workers. The Deno runtime gets \"another year with monthly releases containing bug fixes and security updates\", and then development stops. The code stays open source, and JSR keeps running on Cloudflare infrastructure.\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac9c266dbaf8c2bc523a1f0\">\u003Cvideo src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac9c266dbaf8c2bc523a1fe-0-b019cea7.mp4\" autoplay muted loop playsinline preload=\"metadata\">\u003C\u002Fvideo>\u003C\u002Ffigure>\n\u003Cp>The post gives no exact shutdown date. Counting from 9 October, plan for Deploy to be gone around early April 2027 and for runtime patches to end around October 2027. If you have a side project or a small SaaS on Deploy, you have one migration to do and one decision to make: where it runs next.\u003C\u002Fp>\n\u003Cp>This guide shows the three realistic exits for a small HTTP app. You write the app once as a plain \u003Ccode>fetch\u003C\u002Fcode> handler, then add a few lines for each target.\u003C\u002Fp>\n\u003Ch2>Step 1: make the app a single fetch handler\u003C\u002Fh2>\n\u003Cp>Most Deploy apps start with \u003Ccode>Deno.serve(handler)\u003C\u002Fcode>. The handler takes a web-standard \u003Ccode>Request\u003C\u002Fcode> and returns a \u003Ccode>Response\u003C\u002Fcode>. Workers, Deno and Node (through a small adapter) all accept that shape, so move your routing into its own file that never touches the \u003Ccode>Deno\u003C\u002Fcode> global:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac9c185dbaf8c2bc523a103\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac9c185dbaf8c2bc523a108-0-7eca5877.png\" alt=\"Structuring your application as a single handler makes it portable across different platforms.\" loading=\"lazy\">\u003Cfigcaption>Structuring your application as a single handler makes it portable across different platforms.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cpre class=\"code-block\" data-lang=\"ts\">\u003Ccode class=\"hljs language-typescript\">\u003Cspan class=\"hljs-comment\">\u002F\u002F app.ts - no Deno.* calls in here\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">export\u003C\u002Fspan> \u003Cspan class=\"hljs-keyword\">async\u003C\u002Fspan> \u003Cspan class=\"hljs-keyword\">function\u003C\u002Fspan> \u003Cspan class=\"hljs-title function_\">handler\u003C\u002Fspan>(\u003Cspan class=\"hljs-params\">\u003Cspan class=\"hljs-attr\">req\u003C\u002Fspan>: \u003Cspan class=\"hljs-title class_\">Request\u003C\u002Fspan>\u003C\u002Fspan>): \u003Cspan class=\"hljs-title class_\">Promise\u003C\u002Fspan>&lt;\u003Cspan class=\"hljs-title class_\">Response\u003C\u002Fspan>&gt; {\n  \u003Cspan class=\"hljs-keyword\">const\u003C\u002Fspan> url = \u003Cspan class=\"hljs-keyword\">new\u003C\u002Fspan> \u003Cspan class=\"hljs-title function_\">URL\u003C\u002Fspan>(req.\u003Cspan class=\"hljs-property\">url\u003C\u002Fspan>);\n\n  \u003Cspan class=\"hljs-keyword\">if\u003C\u002Fspan> (url.\u003Cspan class=\"hljs-property\">pathname\u003C\u002Fspan> === \u003Cspan class=\"hljs-string\">&quot;\u002Fhealth&quot;\u003C\u002Fspan>) {\n    \u003Cspan class=\"hljs-keyword\">return\u003C\u002Fspan> \u003Cspan class=\"hljs-keyword\">new\u003C\u002Fspan> \u003Cspan class=\"hljs-title class_\">Response\u003C\u002Fspan>(\u003Cspan class=\"hljs-string\">&quot;ok&quot;\u003C\u002Fspan>);\n  }\n\n  \u003Cspan class=\"hljs-keyword\">if\u003C\u002Fspan> (url.\u003Cspan class=\"hljs-property\">pathname\u003C\u002Fspan> === \u003Cspan class=\"hljs-string\">&quot;\u002Fapi\u002Fecho&quot;\u003C\u002Fspan> &amp;&amp; req.\u003Cspan class=\"hljs-property\">method\u003C\u002Fspan> === \u003Cspan class=\"hljs-string\">&quot;POST&quot;\u003C\u002Fspan>) {\n    \u003Cspan class=\"hljs-keyword\">const\u003C\u002Fspan> body = \u003Cspan class=\"hljs-keyword\">await\u003C\u002Fspan> req.\u003Cspan class=\"hljs-title function_\">json\u003C\u002Fspan>();\n    \u003Cspan class=\"hljs-keyword\">return\u003C\u002Fspan> \u003Cspan class=\"hljs-title class_\">Response\u003C\u002Fspan>.\u003Cspan class=\"hljs-title function_\">json\u003C\u002Fspan>({ \u003Cspan class=\"hljs-attr\">received\u003C\u002Fspan>: body });\n  }\n\n  \u003Cspan class=\"hljs-keyword\">return\u003C\u002Fspan> \u003Cspan class=\"hljs-keyword\">new\u003C\u002Fspan> \u003Cspan class=\"hljs-title class_\">Response\u003C\u002Fspan>(\u003Cspan class=\"hljs-string\">&quot;Not found&quot;\u003C\u002Fspan>, { \u003Cspan class=\"hljs-attr\">status\u003C\u002Fspan>: \u003Cspan class=\"hljs-number\">404\u003C\u002Fspan> });\n}\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Anything that reads environment variables, files or Deno KV goes behind a small interface you pass in, not a direct \u003Ccode>Deno.env.get()\u003C\u002Fcode>. That is the only refactor most small apps need.\u003C\u002Fp>\n\u003Ch2>Exit A: Cloudflare Workers\u003C\u002Fh2>\n\u003Cp>This is the path the announcement points to, and the one with migration support for paying customers. A Worker is a module whose default export has a \u003Ccode>fetch\u003C\u002Fcode> method:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"ts\">\u003Ccode class=\"hljs language-typescript\">\u003Cspan class=\"hljs-comment\">\u002F\u002F worker.ts\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">import\u003C\u002Fspan> { handler } \u003Cspan class=\"hljs-keyword\">from\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;.\u002Fapp.ts&quot;\u003C\u002Fspan>;\n\n\u003Cspan class=\"hljs-keyword\">export\u003C\u002Fspan> \u003Cspan class=\"hljs-keyword\">default\u003C\u002Fspan> {\n  \u003Cspan class=\"hljs-title function_\">fetch\u003C\u002Fspan>(\u003Cspan class=\"hljs-attr\">req\u003C\u002Fspan>: \u003Cspan class=\"hljs-title class_\">Request\u003C\u002Fspan>): \u003Cspan class=\"hljs-title class_\">Promise\u003C\u002Fspan>&lt;\u003Cspan class=\"hljs-title class_\">Response\u003C\u002Fspan>&gt; {\n    \u003Cspan class=\"hljs-keyword\">return\u003C\u002Fspan> \u003Cspan class=\"hljs-title function_\">handler\u003C\u002Fspan>(req);\n  },\n};\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Add a Wrangler config next to it:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"json\">\u003Ccode class=\"hljs language-json\">\u003Cspan class=\"hljs-punctuation\">{\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-attr\">&quot;name&quot;\u003C\u002Fspan>\u003Cspan class=\"hljs-punctuation\">:\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;my-deno-app&quot;\u003C\u002Fspan>\u003Cspan class=\"hljs-punctuation\">,\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-attr\">&quot;main&quot;\u003C\u002Fspan>\u003Cspan class=\"hljs-punctuation\">:\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;worker.ts&quot;\u003C\u002Fspan>\u003Cspan class=\"hljs-punctuation\">,\u003C\u002Fspan>\n  \u003Cspan class=\"hljs-attr\">&quot;compatibility_date&quot;\u003C\u002Fspan>\u003Cspan class=\"hljs-punctuation\">:\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;2026-10-01&quot;\u003C\u002Fspan>\n\u003Cspan class=\"hljs-punctuation\">}\u003C\u002Fspan>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Save it as \u003Ccode>wrangler.jsonc\u003C\u002Fcode>, then run it locally and deploy:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">npx wrangler dev\nnpx wrangler deploy\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Cloudflare's docs say that with a compatibility date of 2026-08-04 or later, Node.js compatibility is on by default, so \u003Ccode>node:\u003C\u002Fcode> imports work without extra flags. For an older date you add \u003Ccode>\"compatibility_flags\": [\"nodejs_compat\"]\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cp>What changes on Workers:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>No \u003Ccode>Deno.*\u003C\u002Fcode> APIs.\u003C\u002Fstrong> Environment variables arrive as the second \u003Ccode>env\u003C\u002Fcode> argument to \u003Ccode>fetch\u003C\u002Fcode>, not through \u003Ccode>Deno.env\u003C\u002Fcode>.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>No Deno KV.\u003C\u002Fstrong> Pick Workers KV for simple key-value data, D1 for SQL, or Durable Objects for per-key state. The Deno announcement does not mention what happens to KV data on Deploy, so export it yourself early.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Cron.\u003C\u002Fstrong> \u003Ccode>Deno.cron\u003C\u002Fcode> jobs become Cron Triggers: a \u003Ccode>triggers.crons\u003C\u002Fcode> list in the config and a \u003Ccode>scheduled\u003C\u002Fcode> handler on the same default export.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>It is not a long-running server.\u003C\u002Fstrong> Deno's tutorial \"Deploying Deno to Cloudflare Workers\" (in Sources) notes you can deploy module workers, not arbitrary web servers. A handler like the one above is fine; anything that keeps sockets or timers open between requests is not.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Exit B: keep Deno, run it yourself in Docker\u003C\u002Fh2>\n\u003Cp>If your app leans on Deno APIs, the shortest move is to keep the runtime and host it on a VPS or any container platform. You still get a year of patches, and you can switch runtimes later without a deadline. Keep the entry point thin:\u003C\u002Fp>\n\u003Cfigure data-post-media=\"6ac9c185dbaf8c2bc523a10d\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac9c185dbaf8c2bc523a112-0-5d9e3ab7.png\" alt=\"Running Deno in a container provides a bridge to self-hosting on your own infrastructure.\" loading=\"lazy\">\u003Cfigcaption>Running Deno in a container provides a bridge to self-hosting on your own infrastructure.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cpre class=\"code-block\" data-lang=\"ts\">\u003Ccode class=\"hljs language-typescript\">\u003Cspan class=\"hljs-comment\">\u002F\u002F main.ts\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">import\u003C\u002Fspan> { handler } \u003Cspan class=\"hljs-keyword\">from\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;.\u002Fapp.ts&quot;\u003C\u002Fspan>;\n\n\u003Cspan class=\"hljs-title class_\">Deno\u003C\u002Fspan>.\u003Cspan class=\"hljs-title function_\">serve\u003C\u002Fspan>({ \u003Cspan class=\"hljs-attr\">port\u003C\u002Fspan>: \u003Cspan class=\"hljs-number\">8000\u003C\u002Fspan> }, handler);\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>A Dockerfile based on the \"Deno and Docker\" guide in Deno's docs, running as a non-root user as that guide recommends:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"dockerfile\">\u003Ccode class=\"hljs language-dockerfile\">\u003Cspan class=\"hljs-keyword\">FROM\u003C\u002Fspan> denoland\u002Fdeno:latest\n\u003Cspan class=\"hljs-keyword\">WORKDIR\u003C\u002Fspan>\u003Cspan class=\"language-bash\"> \u002Fapp\u003C\u002Fspan>\n\n\u003Cspan class=\"hljs-keyword\">COPY\u003C\u002Fspan>\u003Cspan class=\"language-bash\"> deno.json deno.lock .\u002F\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">RUN\u003C\u002Fspan>\u003Cspan class=\"language-bash\"> deno install --frozen\u003C\u002Fspan>\n\n\u003Cspan class=\"hljs-keyword\">COPY\u003C\u002Fspan>\u003Cspan class=\"language-bash\"> . .\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">RUN\u003C\u002Fspan>\u003Cspan class=\"language-bash\"> deno cache main.ts\u003C\u002Fspan>\n\n\u003Cspan class=\"hljs-keyword\">USER\u003C\u002Fspan> deno\n\n\u003Cspan class=\"hljs-keyword\">EXPOSE\u003C\u002Fspan> \u003Cspan class=\"hljs-number\">8000\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">CMD\u003C\u002Fspan>\u003Cspan class=\"language-bash\"> [\u003Cspan class=\"hljs-string\">&quot;deno&quot;\u003C\u002Fspan>, \u003Cspan class=\"hljs-string\">&quot;run&quot;\u003C\u002Fspan>, \u003Cspan class=\"hljs-string\">&quot;--allow-net&quot;\u003C\u002Fspan>, \u003Cspan class=\"hljs-string\">&quot;--allow-env&quot;\u003C\u002Fspan>, \u003Cspan class=\"hljs-string\">&quot;main.ts&quot;\u003C\u002Fspan>]\u003C\u002Fspan>\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>\u003Ccode>deno install --frozen\u003C\u002Fcode> installs the dependencies in \u003Ccode>deno.json\u003C\u002Fcode> and fails if the lockfile would change, which is what you want in a build. The official image already contains an unprivileged \u003Ccode>deno\u003C\u002Fcode> user, so \u003Ccode>USER deno\u003C\u002Fcode> covers the non-root advice in Deno's guide without creating one yourself.\u003C\u002Fp>\n\u003Cp>The guide's example uses \u003Ccode>latest\u003C\u002Fcode>; for production, replace it with the exact 2.x version tag you tested against (Docker Hub lists them), so a rebuild doesn't silently change the runtime. If you don't have a \u003Ccode>deno.lock\u003C\u002Fcode> yet, generate one first with \u003Ccode>deno install\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">docker build -t my-deno-app .\ndocker run --\u003Cspan class=\"hljs-built_in\">rm\u003C\u002Fspan> -p 8000:8000 my-deno-app\ncurl http:\u002F\u002Flocalhost:8000\u002Fhealth\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Narrow the permission flags where you can, as the Deno guide recommends: \u003Ccode>--allow-net=api.example.com\u003C\u002Fcode> beats a bare \u003Ccode>--allow-net\u003C\u002Fcode> for outbound calls. Deno KV and \u003Ccode>Deno.cron\u003C\u002Fcode> still work when self-hosted, but both sit behind unstable flags (\u003Ccode>--unstable-kv\u003C\u002Fcode>, \u003Ccode>--unstable-cron\u003C\u002Fcode>), and KV then lives in a local SQLite file you must put on a volume and back up. On Deploy that was the platform's job; now it is yours.\u003C\u002Fp>\n\u003Cp>Treat this as a bridge, not a destination. When the patch year ends, an internet-facing runtime with no security fixes is a liability.\u003C\u002Fp>\n\u003Ch2>Exit C: Node\u003C\u002Fh2>\n\u003Cp>If you want a runtime with no end date in sight, Node is the long-term option. Deno's announcement itself says Node compatibility \"became an important part\" of the project's work, so many apps already run with few changes. Node's built-in server doesn't take a fetch handler directly; the small \u003Ccode>@hono\u002Fnode-server\u003C\u002Fcode> package does the translation:\u003C\u002Fp>\n\u003Cpre class=\"code-block\" data-lang=\"ts\">\u003Ccode class=\"hljs language-typescript\">\u003Cspan class=\"hljs-comment\">\u002F\u002F server.ts\u003C\u002Fspan>\n\u003Cspan class=\"hljs-keyword\">import\u003C\u002Fspan> { serve } \u003Cspan class=\"hljs-keyword\">from\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;@hono\u002Fnode-server&quot;\u003C\u002Fspan>;\n\u003Cspan class=\"hljs-keyword\">import\u003C\u002Fspan> { handler } \u003Cspan class=\"hljs-keyword\">from\u003C\u002Fspan> \u003Cspan class=\"hljs-string\">&quot;.\u002Fapp.ts&quot;\u003C\u002Fspan>;\n\n\u003Cspan class=\"hljs-title function_\">serve\u003C\u002Fspan>({ \u003Cspan class=\"hljs-attr\">fetch\u003C\u002Fspan>: handler, \u003Cspan class=\"hljs-attr\">port\u003C\u002Fspan>: \u003Cspan class=\"hljs-number\">3000\u003C\u002Fspan> });\n\u003Cspan class=\"hljs-variable language_\">console\u003C\u002Fspan>.\u003Cspan class=\"hljs-title function_\">log\u003C\u002Fspan>(\u003Cspan class=\"hljs-string\">&quot;listening on http:\u002F\u002Flocalhost:3000&quot;\u003C\u002Fspan>);\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cpre class=\"code-block\" data-lang=\"bash\">\u003Ccode class=\"hljs language-bash\">npm init -y\nnpm install @hono\u002Fnode-server\nnpm install -D tsx\nnpx tsx server.ts\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Rewrite \u003Ccode>jsr:\u003C\u002Fcode> and URL imports as npm packages (many JSR packages can also be installed through npm). Replace Deno KV with whatever database you'd use anyway, such as SQLite or Postgres, and move cron jobs to the host's scheduler or a job library.\u003C\u002Fp>\n\u003Ch2>Which one to pick\u003C\u002Fh2>\n\u003Cfigure data-post-media=\"6ac9c185dbaf8c2bc523a117\">\u003Cimg src=\"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac9c185dbaf8c2bc523a11c-0-7e9ea463.png\" alt=\"Choosing the right migration path depends on your long-term maintenance goals.\" loading=\"lazy\">\u003Cfigcaption>Choosing the right migration path depends on your long-term maintenance goals.\u003C\u002Ffigcaption>\u003C\u002Ffigure>\n\u003Cul>\n\u003Cli>\u003Cstrong>Stateless API, no Deno KV:\u003C\u002Fstrong> Workers. The handler moves over almost unchanged, and paying Deploy customers get migration help.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Heavy on Deno APIs, deadline pressure:\u003C\u002Fstrong> Docker now, then Workers or Node within the patch year.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Long-running server, websockets held open, or you want no vendor tie:\u003C\u002Fstrong> Node on your own box.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>A dated checklist\u003C\u002Fh2>\n\u003Col>\n\u003Cli>\u003Cstrong>This week:\u003C\u002Fstrong> list every project on Deploy, and note which ones use Deno KV, \u003Ccode>Deno.cron\u003C\u002Fcode> or custom domains.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>This month:\u003C\u002Fstrong> export KV data and move routing into a \u003Ccode>Deno\u003C\u002Fcode>-free \u003Ccode>handler\u003C\u002Fcode> as shown above.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Before the end of the year:\u003C\u002Fstrong> deploy to the new target, point a staging subdomain at it and run the same requests against both.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Before roughly April 2027:\u003C\u002Fstrong> switch DNS, then delete the Deploy project once traffic has drained.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Before roughly October 2027:\u003C\u002Fstrong> any self-hosted Deno must have moved to a maintained runtime, or you need a plan to patch it yourself.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdeno.com\u002Fblog\u002Fcloudflare\">Deno joins Cloudflare (Ryan Dahl, deno.com, 9 Oct 2026)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.deno.com\u002Fruntime\u002Ftutorials\u002Fcloudflare_workers\">Deploying Deno to Cloudflare Workers (Deno docs)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdocs.deno.com\u002Fruntime\u002Freference\u002Fdocker\u002F\">Deno and Docker (Deno docs)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fdevelopers.cloudflare.com\u002Fworkers\u002Fruntime-apis\u002Fnodejs\u002F\">Node.js compatibility (Cloudflare Workers docs)\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fnews.ycombinator.com\u002Fitem?id=50019911\">Hacker News discussion\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>","Deno is joining Cloudflare: Deploy has six months left and the runtime gets a year of fixes. Write your app as one fetch handler and you can run it on Workers, in a Deno container or on Node. Code for all three, plus what does not carry over.",[9,10,11,12,13],"deno","cloudflare-workers","migration","docker","ai-assisted","if.codes","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac9c181dbaf8c2bc523a0fd-0-caa268de.png","2026-10-10T05:47:19.665Z","Deno Deploy is shutting down: move to Workers, Docker or Node","Deno Deploy has six months left. Rewrite your app as one fetch handler and run it on Cloudflare Workers, self-hosted Deno or Node, with code for each.",6,[21,34,45],{"slug":22,"title":23,"type":24,"summary":25,"tags":26,"author":14,"cover_url":31,"published_at":32,"updated_at":33},"durable-object-alarm-loop-guards","The Durable Object alarm that cost $10,000: guarding setAlarm() loops with backoff, idempotency and a kill switch","blog","Durable Object alarms are at-least-once, retried, and usually rescheduled from inside the handler, which makes a billing loop easy to write. Four guards in TypeScript, a kill switch, and a Vitest test that proves the loop stops.",[27,28,29,30,13],"cloudflare","durable-objects","typescript","cost-control","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac8709b392a85804f209fb3-0-9143ed0c.png","2026-10-09T06:09:10.127Z","2026-10-09T06:09:10.128Z",{"slug":35,"title":36,"type":24,"summary":37,"tags":38,"author":14,"cover_url":43,"published_at":44,"updated_at":44},"cctld-hijack-counterfeit-certs-caa-accounturi-ct-watch","Counterfeit certs via hijacked ccTLDs: CAA with accounturi and a CT watch for your domains in 15 minutes","Attackers took over the .gh, .sl and .as registries and got 12 valid certificates for Google domains. CAA would not have stopped the hijack. Here is the CAA record that limits the damage afterwards, and a CT watch script that tells you within a day.",[39,40,41,42,13],"tls","caa","certificate-transparency","dns","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac75337392a85804f207d25-0-12f538ac.png","2026-10-08T22:47:12.408Z",{"slug":46,"title":47,"type":24,"summary":48,"tags":49,"author":14,"cover_url":54,"published_at":55,"updated_at":56},"embeddinggemma-2-qdrant-truncation-recall","EmbeddingGemma 2 in Qdrant: one 740M model for text, images and audio, and what truncating 768 to 128 dims costs your recall","Google's open multimodal embedder runs locally and truncates from 768 to 128 dims. Index one Qdrant collection at three sizes from a single encode pass, then measure recall@10 on your own queries instead of trusting a benchmark.",[50,51,52,53,13],"embeddings","qdrant","rag","open-models","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac5cceedf0d655df505306e-0-d17d0fef.png","2026-10-07T07:21:20.071Z","2026-10-07T07:21:20.072Z",[58,61,64,66,68,80,91,101,112,125,139,151,163,174,185,193,204,215,224,235,245,254,264],{"slug":4,"title":5,"type":24,"summary":7,"tags":59,"author":14,"cover_url":15,"published_at":16,"updated_at":60,"reading_minutes":19},[9,10,11,12,13],"2026-10-10T05:47:19.666Z",{"slug":22,"title":23,"type":24,"summary":25,"tags":62,"author":14,"cover_url":31,"published_at":32,"updated_at":33,"reading_minutes":63},[27,28,29,30,13],7,{"slug":35,"title":36,"type":24,"summary":37,"tags":65,"author":14,"cover_url":43,"published_at":44,"updated_at":44,"reading_minutes":19},[39,40,41,42,13],{"slug":46,"title":47,"type":24,"summary":48,"tags":67,"author":14,"cover_url":54,"published_at":55,"updated_at":56,"reading_minutes":19},[50,51,52,53,13],{"slug":69,"title":70,"type":24,"summary":71,"tags":72,"author":14,"cover_url":76,"published_at":77,"updated_at":78,"reading_minutes":79},"cloudflare-access-strict-service-token-auth-migration","Strict service token auth in Cloudflare Access: moving your scripts and CI over before it bites","Cloudflare Access now has a strict mode for service tokens: 401\u002F403 instead of a 302 to the login page, only Service Auth policies count, and no CF_Authorization cookie. New orgs get it forced on from 5 October. A 15-minute check and switch for existing orgs.",[27,73,74,75,13],"zero-trust","ci-cd","authentication","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac4a8860956594c947bd197-0-f768b25b.png","2026-10-06T08:30:13.154Z","2026-10-06T08:30:13.155Z",5,{"slug":81,"title":82,"type":24,"summary":83,"tags":84,"author":14,"cover_url":88,"published_at":89,"updated_at":90,"reading_minutes":19},"cloudflare-traces-trace-rules-debug-one-customer","Why was that request blocked? Tracing one customer at 100% with Cloudflare Traces and Trace Rules","Cloudflare Traces (open beta) shows a request's path through WAF rules, transforms, cache, Workers and origin as one trace. A recipe: low baseline sampling, a 100% Trace Rule for one host or debug header, traceparent to your origin, OTLP export to your own collector, and what December pricing means.",[27,85,86,87,13],"observability","opentelemetry","tracing","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac338052cb6b40613ac2b7c-0-2294d114.png","2026-10-05T06:22:19.055Z","2026-10-05T06:22:19.056Z",{"slug":92,"title":93,"type":24,"summary":94,"tags":95,"author":14,"cover_url":99,"published_at":100,"updated_at":100,"reading_minutes":79},"copyescape-cve-2026-17106-patch-docker-cp","CopyEscape (CVE-2026-17106): patch docker cp, and stop copying out of running containers","A race in docker cp lets a malicious container write files anywhere the copying process can write on the host. That matters for CI runners and AI-agent sandboxes that copy results out. Check your versions, patch, and change copy-out jobs to stop the container first.",[12,96,97,98,13],"security","cve","ci","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218ebfd770659725abe68-0-eee7c8f7.png","2026-10-04T23:51:14.689Z",{"slug":102,"title":103,"type":24,"summary":104,"tags":105,"author":14,"cover_url":108,"published_at":109,"updated_at":110,"reading_minutes":111},"protected-quick-tunnels-vs-tailscale-funnel","Share localhost with three named people: Cloudflare's Protected Quick Tunnels vs Tailscale Funnel","cloudflared 2026.9.3 adds --allowed-mail: your quick tunnel now sits behind an email one-time PIN, checked against an allow-list on your own machine, free and without a Cloudflare account. The commands, what it protects, and when Tailscale Serve or Funnel is the better fit.",[27,106,107,96,13],"tailscale","tunnels","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6ac218d8fd770659725abe3a-0-40f8cb2e.png","2026-10-04T23:19:14.764Z","2026-10-04T23:19:14.765Z",4,{"slug":113,"title":114,"type":24,"summary":115,"tags":116,"author":14,"cover_url":122,"published_at":123,"updated_at":124,"reading_minutes":19},"si-domains-super-intelligence-data",".si after 'Super Intelligence': did one UN speech move a ccTLD?","Trump renamed AI 'super intelligence' at the UN on 22 September 2026 and Slovenia's .si went from about 190,000 names to almost 276,000 in a month. Registry numbers, prices, and 87 WHOIS checks: the obvious AI names were gone years ago; the compounds went in days.",[117,118,119,120,121,13],"domains","si","tld","data","ai","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaee53e21d5cbd14d442d-0-d6243bc5.png","2026-10-04T22:36:14.598Z","2026-10-04T22:36:14.599Z",{"slug":126,"title":127,"type":24,"summary":128,"tags":129,"author":14,"cover_url":135,"published_at":136,"updated_at":137,"reading_minutes":138},"palantir-agent-stack-python","Steal Palantir's agent stack: typed tools, one LLM gateway, swappable models","An X thread boils Palantir's AIP docs down to four agent patterns. We check each one against the docs, then build them in one stdlib-only Python file: typed business-object tools, a gateway that masks PII, caches and retries, a model set in config, and schedule\u002Fevent\u002FAPI triggers.",[130,131,132,133,134,13],"ai-agents","llm","python","architecture","palantir","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88f9c951ea7137fa3872-0-48eb7eee.png","2026-10-01T23:05:10.531Z","2026-10-01T23:05:10.532Z",10,{"slug":140,"title":141,"type":24,"summary":142,"tags":143,"author":14,"cover_url":147,"published_at":148,"updated_at":149,"reading_minutes":150},"claude-code-effort-levels","Effort levels in Claude Code: when max effort pays off and when it just burns tokens","Anthropic's effort deep dive (Terminal-Bench 3.0 plus three builds) shows higher effort mostly buys verification and edge-case testing, not smarter code. A rule of thumb per task type, the commands to set effort, and a script to measure cost vs pass rate on your own repo.",[144,145,131,146,13],"claude-code","ai-coding","developer-tools","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88edc951ea7137fa3804-0-2716005a.png","2026-10-01T22:32:14.139Z","2026-10-02T04:44:58.001Z",9,{"slug":152,"title":153,"type":24,"summary":154,"tags":155,"author":14,"cover_url":159,"published_at":160,"updated_at":161,"reading_minutes":162},"agentic-inbox-cloudflare-setup","Self-host an AI email agent on Cloudflare Workers: agentic-inbox set up and costed","Cloudflare's open-source agentic-inbox runs a full email client on Workers, with one SQLite Durable Object per mailbox and a Kimi K2.5 agent that drafts replies. Covers the post-deploy steps people miss (Access, sending, routing, mailbox first) and the cost.",[27,156,130,157,158,13],"workers","email","self-hosting","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abd88dac951ea7137fa378b-0-5b0ec96d.png","2026-10-01T08:17:18.646Z","2026-10-05T05:56:11.919Z",8,{"slug":164,"title":165,"type":24,"summary":166,"tags":167,"author":14,"cover_url":171,"published_at":172,"updated_at":173,"reading_minutes":162},"audit-ai-agent-public-traces","Nearly a million leaked links: auditing what your AI agents leave on the public web","OpenAI's agent swarm left almost a million public shortener URLs holding credentials. Here's a tested shell + gitleaks audit to find the shortlinks, pastes and webhooks your own agents created, scan them for secrets and close the channels.",[96,168,169,170,131,13],"agents","secrets","gitleaks","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaad873e21d5cbd14d4397-0-0f4f51f7.png","2026-10-01T07:43:19.642Z","2026-10-01T08:44:43.041Z",{"slug":175,"title":176,"type":24,"summary":177,"tags":178,"author":14,"cover_url":182,"published_at":183,"updated_at":184,"reading_minutes":162},"mikrotrick-check-patch-mikrotik","MikroTrick: check and patch your MikroTik in 15 minutes","Two chained RouterOS bugs give anyone who can reach SSH full admin, no password needed, and attacks started before the patch. Find exposed SSH, check the version, grep for the published IoCs, patch and move management behind WireGuard.",[96,179,180,181,158,13],"mikrotik","routeros","ssh","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c0838b650cb96b3d10-0-6cd107e0.png","2026-10-01T07:02:15.03Z","2026-10-01T08:44:41.391Z",{"slug":186,"title":187,"type":24,"summary":188,"tags":189,"author":14,"cover_url":190,"published_at":191,"updated_at":192,"reading_minutes":162},"agent-sandbox-dns-egress-lockdown","Your agent sandbox leaks through DNS: lock down egress in 15 minutes","An OpenAI model escaped its sandbox by tunnelling questions through DNS. Here is a tested Docker Compose setup for coding agents: a DNS allowlist, a logging egress proxy and a kill switch that actually fires.",[96,12,168,42,158,13],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abaaca13e21d5cbd14d4306-0-cb93fe1b.png","2026-10-01T03:00:15.943Z","2026-10-01T08:44:43.165Z",{"slug":194,"title":195,"type":24,"summary":196,"tags":197,"author":14,"cover_url":201,"published_at":202,"updated_at":203,"reading_minutes":63},"who-blocks-ai-crawlers-robots-txt","Who blocks AI crawlers? robots.txt vs the network edge, with numbers","I scanned robots.txt on the top 300 sites: 33 of 138 block GPTBot, 14 block training but allow AI search. What each AI bot directive controls, why robots.txt is only a request, and a copy-paste policy plus nginx rule for small SaaS sites.",[121,198,199,27,200,13],"robots-txt","seo","saas","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abcd9c1838b650cb96b3d1b-0-11f94198.png","2026-09-30T21:00:20.673Z","2026-10-01T20:47:34.092Z",{"slug":205,"title":206,"type":24,"summary":207,"tags":208,"author":14,"cover_url":212,"published_at":213,"updated_at":214,"reading_minutes":111},"bullet-time-with-first-last-frame-video","Bullet time with first\u002Flast-frame video: orbiting a frozen moment from three stills","A freeze-frame camera orbit built from generated stills: one action shot, two camera-move angles, two first\u002Flast-frame clips between them, stitched and ping-ponged. The pipeline, the seams, and where the model re-imagines the water.",[121,209,210,211],"comfyui","video-generation","flowdsl","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abae46c45201648bfd477a7-0-6f4d036e.png","2026-09-28T22:42:41Z","2026-09-28T22:42:41.6Z",{"slug":216,"title":217,"type":24,"summary":218,"tags":219,"author":14,"cover_url":221,"published_at":222,"updated_at":223,"reading_minutes":63},"an-ai-media-pipeline-that-shows-its-work","An AI media pipeline that shows its work: ComfyUI presets, FlowDSL routing and the misses","How the images on my sites are generated: four ComfyUI presets behind one Go module, job rows as state, FlowDSL flows for routing, per-post media in the admin — and the bugs and model misses I hit shipping it. This post's own images were made the same way.",[121,211,209,220],"image-generation","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6aba8ba317ceba3543925be4-0-2f6b8a5c.png","2026-09-28T15:57:50Z","2026-10-01T20:47:34.327Z",{"slug":225,"title":226,"type":24,"summary":227,"tags":228,"author":14,"cover_url":231,"published_at":232,"updated_at":233,"reading_minutes":234},"openai-embeddings-python-mongodb","Transforming Text into Vectors: OpenAI Embeddings in Python","Learn how to generate text embeddings with the OpenAI API in Python to power semantic search, recommendations, and more. Includes practical examples with MongoDB integration and cost analysis.",[229,121,132,230],"openai","mongodb","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c2d-0-2e60b732.png","2024-11-23T00:00:00Z","2026-09-28T22:31:01.385Z",3,{"slug":236,"title":237,"type":24,"summary":238,"tags":239,"author":14,"cover_url":241,"published_at":242,"updated_at":243,"reading_minutes":244},"check-pricing-availability-ing-domains","Last Chance to Grab Short .ING Domains: The Extended List Part II","Welcome back to the second part of our exciting exploration into the .ING domain zone! This time, I've expanded our horizons to bring you an even larger selection of .ING domain names. List of over 24,000 domain names inside.",[117,240],"business","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c38-0-c55f4c8d.png","2023-12-14T00:00:00Z","2026-09-28T22:31:01.453Z",1,{"slug":246,"title":247,"type":24,"summary":248,"tags":249,"author":14,"cover_url":250,"published_at":251,"updated_at":252,"reading_minutes":253},"impressive-ing-domains","Unveiling the Impressive .ING Domains","Discover the vast potential of the new .ING domain zone in my latest blog post! I've used AI and a Python script to unearth a treasure trove of available domain names. From budget-friendly picks to exclusive premium domains, there's something for every ambition. Plus, a special list of unique, lesser-known domains awaits.",[117,240],"https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c43-0-03be24b7.png","2023-12-11T00:00:00Z","2026-09-28T22:31:01.527Z",2,{"slug":255,"title":256,"type":24,"summary":257,"tags":258,"author":14,"cover_url":261,"published_at":262,"updated_at":263,"reading_minutes":234},"secured-web-server-in-5-minutes","Fortify Web Server Security in 5 Minutes with Tailscale","Tailscale revolutionizes secure networking with its user-friendly approach, effortlessly connecting devices across diverse networks.",[259,106,260],"firewall","webserver","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c4e-0-eae6f62d.png","2023-11-03T00:00:00Z","2026-09-28T22:31:01.597Z",{"slug":265,"title":266,"type":24,"summary":267,"tags":268,"author":14,"cover_url":271,"published_at":272,"updated_at":273,"reading_minutes":19},"lets-encrypt-free-ssl","How to Secure Your Website with Free SSL Certificates for a Lifetime","Let’s Encrypt certificates have revolutionized internet security by providing free, automated, and widely trusted SSL\u002FTLS certificates. The non-profit Certificate Authority (CA) has significantly contributed to a more secure web environment by simplifying the process of securing websites with HTTPS.",[269,270,260],"ssl","https","https:\u002F\u002Fmedia.stufio.com\u002Fmedia\u002Fifcodes\u002Fmediagen\u002F6a\u002F6abad0fa45201648bfd46c59-0-bf2a9a0a.png","2023-11-01T00:00:00Z","2026-09-28T22:39:13.555Z"]