Deploy EmDash on Cloudflare Workers: The Real 5-Minute Guide

Deploy EmDash on Cloudflare Workers in 5 minutes with this step-by-step guide covering paid plans, bindings, and cost management.

By Central
A step-by-step guide to deploying EmDash on Cloudflare Workers, including paid plan setup and binding configuration.
Highlights
  • Deploying EmDash requires four Cloudflare products: Workers, D1, R2, and KV.
  • The sandboxed plugin feature requires the Paid Workers plan at $5 per month.
  • Without a spending cap, a DDoS attack or misbehaving plugin can spike your bill from $5 to $500.

You have three minutes of CLI time and two minutes of configuration. That’s the promise. But the non-obvious part isn’t running npm create emdash@latestcodecode — it’s wiring Cloudflare’s paid infrastructure correctly so the sandboxed plugins actually work.

Deploying EmDash on Cloudflare Workers means you’re not just deploying a CMS. You’re provisioning four separate Cloudflare products: Workers (compute), D1 (database), R2 (file storage), and KV (session state). Each requires its own API token scope. Miss one, and the deployment fails silently after the build step.

A DDoS attack or a misbehaving plugin can spike your bill.

What You Actually Need Before You Start

Skip the free tier. The sandboxed plugin feature that makes EmDash superior to WordPress requires Dynamic Workers, which only run on the Paid Workers plan ($5/month minimum).

You also need:

  • A Cloudflare account with the Workers Paid plan enabled
  • API tokens with Workers, D1, R2, and KV permissions (all Edit scope)
  • Node.js 22.12+ installed locally
  • A domain on Cloudflare (or use the workers.dev subdomain for testing)

Step 1: Set Up the Paid Plan

Go to your Cloudflare dashboard → Workers & Pages → Plans. Switch to Paid. This unlocks Dynamic Workers and the ability to deploy EmDash with plugin isolation.

Without this step, npm create emdash@latestcodecode will succeed, but your deployment will return error 10195 when it tries to spin up a sandboxed plugin.

Step 2: Create the Project with the Right Template

Run:

“`bash

npm create emdash@latest my-site

“`

When prompted, choose Cloudflare Workers as the deployment target. Select a template (Blog, Marketing, or Portfolio — I recommend Blog for testing). The CLI will ask for your Cloudflare API token. Use the one with the four scopes above.

Step 3: Configure Bindings (The Tricky Part)

After the project is created, open astro.config.mjscodecode. You’ll see something like:

“`js

database: {

type: ‘d1’,

binding: ‘DB’

},

storage: {

type: ‘r2’,

binding: ‘MEDIA’

},

kv: {

type: ‘kv’,

binding: ‘SESSION’

}

“`

These bindings must match the actual resources in your Cloudflare account. If you haven’t created them yet, the CLI usually does it automatically — but not always. Verify in your Cloudflare dashboard that three resources exist:

  • A D1 database named emdash-dbcodecode
  • An R2 bucket named emdash-mediacodecode
  • A KV namespace named emdash-sessioncodecode

If any are missing, create them manually and update astro.config.mjscodecode with the correct names.

Step 4: Deploy and Verify

Run:

“`bash

npx astro build

npx wrangler deploy

“`

The first deploy takes about 30 seconds. After it completes, visit your site’s URL. Add /admincodecode to see the login screen. Set up your passkey (WebAuthn) — no passwords.

Now test the sandbox. Create a simple plugin (follow the EmDash docs) and install it. If it runs without errors, Dynamic Workers are active. You can verify by checking the Workers dashboard for a new emdash-plugin-executorcodecode worker.

Common Pitfalls and How to Avoid Them

  • Forgetting to enable the Paid plan — The CLI won’t warn you. The error only surfaces after deployment.
  • API token scope mismatch — Use a token with all four Edit scopes, not just Workers.
  • D1 database not auto-created — This happens in about 1 in 5 deployments. Check the dashboard.
  • Cold start latency — V8 isolates are millisecond-fast, but D1 queries can add 200ms on the first request. Pre-warm by hitting your site with a simple GET request after deploy.

The Cost Surprise Nobody Talks About

Deploying EmDash is cheap — $5/month for the paid plan covers 10 million requests. But the billing model is serverless per-request, not flat-rate. A DDoS attack or a misbehaving plugin can spike your bill. Cloudflare offers no global spending cap. You must manually set CPU time limits per Worker and configure WAF rate limiting to prevent runaway costs. That’s a task most beginners overlook, and it can turn a $5 month into a $500 surprise.

Questions answered
  • What Cloudflare products are needed to deploy EmDash?You need Workers for compute, D1 for database, R2 for file storage, and KV for session state.
  • Why is the Paid Workers plan required for EmDash?The sandboxed plugin feature requires Dynamic Workers, which only run on the Paid Workers plan.
  • How can I prevent unexpected costs when using EmDash on Cloudflare?Set CPU time limits per Worker and configure WAF rate limiting to prevent runaway costs from DDoS attacks or misbehaving plugins.
Share This Article