Knowledge

Publish your own OwnersClub-style wiki

A from-zero guide to deploy a Git-backed, OKF-compatible wiki on Cloudflare Workers — for humans and their AI agents. Copy this page's URL into an agent chat to automate the build. Owning your own AI Workshop.

playbooktemplatecloudflarehow-toagent-zero

Publish your own OwnersClub-style wiki

This page does two jobs:

  1. For the owner — get from nothing to a live public site. A custom domain is optional: you can ship on a free *.workers.dev URL first and add a domain later.
  2. For the owner's AI agent (Agent Zero or similar) — paste this page's URL into the chat and the agent can build and deploy it for you, asking only for the credentials it can't create itself.

The whole thing is Git + Markdown + a static build. No database, no CMS vendor. Content lives in knowledge/ as Markdown with YAML front matter; Astro renders it; Cloudflare Workers serves it.


Part A — For the owner (human)

A0. What you need

Requirement Notes
A computer with a terminal macOS, Linux, or Windows (WSL)
Node.js 20+ and pnpm 9 corepack enable && corepack prepare pnpm@9.12.0 --activate
A Cloudflare account Free tier is enough. Create one at https://dash.cloudflare.com/sign-up if you don't have it.
Optional: a domain Buy anywhere (Cloudflare Registrar, Namecheap, etc.). Not required to start.
Optional: an AI agent If you want the agent to run the CLI for you (Part B).

A1. Decide your path

  • Path 1 — No domain (fastest). You get a working public site at https://<worker-name>.<your-subdomain>.workers.dev. Perfect for a first look. Add a domain later.
  • Path 2 — Your own domain. You get https://yourdomain.com. Requires the domain to be added to Cloudflare as a zone (nameservers pointed at Cloudflare).

You can start with Path 1 and switch to Path 2 later without rebuilding anything.

A2. Create a Cloudflare API token (this is the only secret)

  1. Go to https://dash.cloudflare.com → click your avatar → My Profile → API Tokens → Create Token.

  2. Choose Create Custom Token (or the “Edit Cloudflare Workers” template).

  3. Give it these permissions (minimum):

    Scope Permission Needed for
    Account → Workers Scripts Edit Deploy the Worker
    Account → Workers KV / assets (auto) Static assets
    Zone → DNS Edit Only if attaching a custom domain
    Zone → Zone Read Listing your zone
    • Account resources: include your account.
    • Zone resources: include your domain's zone (if you have one).
  4. Create Token and copy it (shown once). Also copy your Account ID (dashboard right sidebar).

Keep the token out of Git. It goes into your shell environment or your agent's secret store — never a committed file.

A2b. Store the credentials with Agent Zero (no terminal needed)

You don't have to touch a shell. Agent Zero has a file browser and editor — use it to drop your credentials into the agent's secret store so the agent can deploy for you.

  1. In the Agent Zero WebUI, open the file browser for your project and go to the .a0proj/ folder.

  2. Open secrets.env with the built-in editor (create it if it doesn't exist).

  3. Add these two lines — each is just NAME=value on its own line:

    CLOUDFLARE_API_TOKEN=your-token-from-A2
    CLOUDFLARE_ACCOUNT_ID=your-account-id-from-A2
    
  4. Save. Do not commit it — .a0proj/ and .env files are git-ignored.

  5. Tell your agent: “The Cloudflare credentials are in the project secrets file — go ahead.”

File Purpose Committed?
.a0proj/secrets.env Agent Zero project secrets (your CF token + account id) No (git-ignored)
.dev.vars Local Wrangler dev vars (copy from .dev.vars.example) No
.env Never used for the token in this template No

The agent reads secrets.env as environment variables for its terminal commands, so no pasting into chat is required after that. Prefer this over pasting the token into the chat.

🔐 If you ever paste a token into a chat by accident, roll it (create a new one, delete the old one) in My Profile → API Tokens. Treat any token shown in a transcript as compromised.

A3. Hand off to your agent or run it yourself

If you have an Agent Zero — skip to Part B; paste the URL and follow its prompts.

If you're doing it yourself, the shape is:

# 1. Get the code and install
corepack enable && corepack prepare pnpm@9.12.0 --activate
pnpm install

# 2. Build and check locally
pnpm validate:okf && pnpm test:links && pnpm build
pnpm dev          # look at it on http://localhost:4321

# 3. Authenticate and deploy
export CLOUDFLARE_API_TOKEN=...        # from A2
export CLOUDFLARE_ACCOUNT_ID=...       # from A2
npx wrangler@4 deploy --config wrangler.jsonc

The deploy prints your live URL. Done — that's Path 1.

A4. (Optional) Add your own domain — Path 2

  1. In Cloudflare, make sure your domain is a zone (nameservers set to the ones Cloudflare gives you).

  2. Edit wrangler.jsonc and add your hostname(s):

    "routes": [
      { "pattern": "yourdomain.com", "custom_domain": true },
      { "pattern": "www.yourdomain.com", "custom_domain": true }
    ]
    
  3. Re-run npx wrangler@4 deploy --config wrangler.jsonc.

If Cloudflare complains the hostname “already has externally managed DNS records” (see A6), delete the old A/CNAME records for that hostname first (keep MX/TXT for email!), then redeploy.

A5. After you're live

  • The site is static and cached by Cloudflare automatically.
  • Edit content by adding Markdown files under knowledge/ (each needs a non-empty type in front matter), then pnpm build && pnpm deploy.
  • If a domain previously redirected somewhere (e.g. a Luma page), disable that redirect rule — a domain redirect is separate from DNS and will keep firing otherwise (see A6).

A6. Troubleshooting (learned the hard way)

Symptom Cause Fix
Your Worker has access... but assets 404 Wrangler v3 can't upload static assets Use wrangler v4: pnpm add -D -w wrangler@^4
*.workers.dev went empty after adding a domain Adding a custom domain disables the workers.dev URL by default Set "workers_dev": true in wrangler.jsonc and redeploy
Security headers missing on pages Static assets served directly, bypassing the Worker Set "run_worker_first": true in the assets block
“Hostname already has externally managed DNS records” Old A/CNAME on that hostname Delete those records first (keep MX/TXT), then redeploy
Site still redirects to the old destination An edge redirect rule, not DNS Disable it in Rules → Redirect Rules (also check Page Rules and account Bulk Redirects)
Authentication error on DNS/rules API Token lacks that scope Add Zone → DNS: Edit (or use the dashboard)

Part B — For the AI agent (paste this)

Owner: copy this block into your Agent Zero chat:

Read this page and follow it end-to-end to deploy my own copy of the
OwnersClub-style wiki: https://ownersclub.ai/knowledge/playbooks/deploy-your-own-wiki/

- I do NOT have a domain (use the *.workers.dev URL)  [change this line if I do]
- My Cloudflare credentials are in .a0proj/secrets.env (CLOUDFLARE_API_TOKEN,
  CLOUDFLARE_ACCOUNT_ID). Source that file before deploying; do NOT print the values.
- Work on a branch, validate and build before deploying, and report the live URL.

B1. What the agent should do

  1. Fetch this page and read it. (An agent can document_query the URL, or curl it.)

  2. Scaffold or clone the project. If starting fresh, reproduce this structure:

    apps/site      Astro static site (home, events, knowledge, projects, about, contact)
    apps/editor    dev-only Tiptap shell (optional)
    apps/worker    Worker adding security headers + /api/health
    packages/okf   front-matter parse/validate/index/JSON-LD
    packages/config
    scripts        validate-okf, check-links, build-index
    knowledge/     canonical Markdown + YAML front matter (source of truth)
    wrangler.jsonc  Cloudflare Workers static-assets config
    
  3. Install and verify locally before any deploy:

    corepack enable && corepack prepare pnpm@9.12.0 --activate
    pnpm install
    pnpm validate:okf && pnpm test:links && pnpm check && pnpm build
    
  4. Get the credentials from the project secrets file .a0proj/secrets.env (set by the owner via the file browser/editor, see A2b). Load them into the environment for your deploy commands — never commit them, never echo them:

    set -a; . /a0/usr/projects/<project>/.a0proj/secrets.env; set +a
    # or: export CLOUDFLARE_API_TOKEN=...  CLOUDFLARE_ACCOUNT_ID=...
    

    If the file is empty or missing, ask the owner to add the two variables (A2b) rather than pasting them in chat. For scope, they need Account → Workers Scripts: Edit; add Zone → DNS: Edit only if a custom domain is used.

  5. Deploy with Wrangler v4: npx wrangler@4 deploy --config wrangler.jsonc.

  6. Verify the live URL returns 200 on /, /events/, /knowledge/, /sitemap.xml, /api/health, and reports the live *.workers.dev URL.

B2. Hard rules for the agent (from this project's governance)

  • Canonical content is knowledge/. Never edit generated output (dist/, public/knowledge-index.json); regenerate with pnpm build.
  • Every knowledge document needs a non-empty type. Preserve unknown front-matter keys on parse/serialize.
  • Default to status: draft. Let the human promote to published/verified.
  • Every factual external claim needs a sources: entry or a clearly marked uncertainty. Never invent events, organizers, venues, links, or history.
  • Record agent-authored material as generated.by: agent-zero/<skill-or-version>.
  • Never set human verification metadata.
  • Do not merge, deploy, change DNS, or alter redirect rules without explicit human approval. Branch + reviewable commit for meaningful changes.
  • Run validation, link checks, and build before committing.

B3. Agent command reference

# Load deploy credentials first (from A2b), never echo them:
set -a; . .a0proj/secrets.env; set +a

pnpm install
pnpm dev              # local dev server
pnpm validate:okf     # front matter + Markdown validation
pnpm test:links       # internal link check
pnpm check            # type-check site + okf package
pnpm build            # static build + regenerate public/knowledge-index.json
pnpm preview          # preview the built site
pnpm deploy           # wrangler deploy (needs credentials)
pnpm deploy:preview   # wrangler versions upload (no traffic shift)

B4. Extracting real event data (optional, no API needed)

To turn a public Luma link into a sourced event entry without inventing anything:

curl -sSL -A 'Mozilla/5.0' 'https://lu.ma/<slug>' -o /tmp/luma.html -w 'http=%{http_code} url=%{url_effective}\n'
grep -oP '"(start_at|end_at|timezone)":"[^"]*"' /tmp/luma.html | sort -u
grep -oP '"(full_address|address|city)":"[^"]*"' /tmp/luma.html | sort -u
grep -oP '"name":"[^"]*"' /tmp/luma.html | sort -u    # filter out attendee names
grep -oP '"(is_free|ticket_types)":(\[[^]]*\]|true|false)' /tmp/luma.html

Transcribe the real values, put the Luma URL in sources:, and mark the entry status: draft.


How this site is built (reference)

  • Content: Markdown + YAML front matter under knowledge/ (OKF-compatible / OKF-oriented).
  • Build: Astro reads the corpus, generates public/knowledge-index.json, JSON-LD, sitemap, RSS, robots.
  • Hosting: Cloudflare Workers static assets via wrangler.jsonc; a tiny Worker adds security headers.
  • Governance: see the repository AGENTS.md.

This guide is itself part of the knowledge corpus. Copy the repo, point an agent here, and you have your own version of OwnersClub.ai.