Self-hosted here means your Cloudflare account
Awesome Cloudflare Self-Hosted uses a narrower definition than its name may suggest. Every listed application must run in the user's Cloudflare account and replace a product someone might otherwise pay for. A Docker service on your VPS is out. So are frameworks, SDKs, starter templates, Cloudflare administration dashboards, API relays, and runtimes that replace Cloudflare itself. The tree contains 130 entries across 15 categories.
That focus is the list's advantage. Each row names the SaaS role and shows declared Cloudflare bindings such as D1, R2, KV, Durable Objects, Workers AI, or Cron. You can quickly see whether a bookmark manager is a small D1 deployment or an application spread across several platform services. The tradeoff is vendor dependence: owning the account and data does not give you a portable server stack.
The audit reads repositories instead of trusting descriptions
For every entry, the audit resolves the license from the project's own license file, looks for a Wrangler or Alchemy deployment configuration, extracts declared bindings, and checks the last push, latest release, and archive status. It recognizes ordinary Wrangler files, committed example variants, and alchemy.run.ts. A separate stale check flags projects without a commit in the last 12 months.
The parser exists because configuration is messy. Commented template bindings can look active, while a binding whose identifier is intentionally commented until local setup can still be real. Path globs can resemble block comments. The project documents these past misreads and pins them with tests. Entry data is the source of truth; README and issue forms are generated so concurrent submissions do not silently overwrite each other's output.
What happened when we ran it
Our run at commit 804c39b used a fresh unprivileged Node 22 container with 3 CPUs and 8 GB of RAM. Installation completed in 7 seconds, added 0 packages, and occupied 2 MB. The checkout contained 168 files and roughly 2,300 lines of source. Its lack of installed dependencies matches the maintainer's claim that the tooling is plain Node.
The build completed in 5 seconds. Node's test runner then passed all 61 tests in another 5 seconds, with 0 failures. Npm audit reported 0 known vulnerabilities across every severity level. The repository has 5 CI workflow files. It has no Dockerfile and no tests directory because the test files sit with the scripts rather than under a dedicated folder.
Our test method covered repository installation, README generation, and the supplied parser suite. It did not execute the 130 listed applications or inspect their production deployments. A full live audit also needs authenticated GitHub CLI access and current upstream repository data. The clean 61-test result supports the parser, not the security, usability, pricing, or maintenance quality of every catalog entry.
Warning badges report licenses without filtering them out
The list prefers stated licenses but does not require an OSI-approved license. Its rules retain source-available projects and even unlicensed repositories, then place a warning marker beside terms readers should inspect. The contributing guide explains the rationale: some source-available terms permit private self-hosting, while excluding every unfamiliar license would also reject legitimate open-source choices that a small allowlist forgot.
That policy is defensible only if readers notice the badge. An unlicensed public repository reserves the usual rights; visible code does not grant permission to deploy or modify it. PolyForm Noncommercial can also bar internal company use. The list automates detection, but the adoption decision stays with you. Open the actual license before entering credentials, importing data, or building a business process around an entry.
A deploy button is a convenience signal, not approval
The data model records whether a project's README contains a Deploy to Cloudflare button. It deliberately stores the fact rather than the URL, because readers should visit the repository and read instructions before launching anything. The audit documentation says 45 of 118 entries carried this marker when that page was written; the current tree has grown to 130 entries, so that older ratio should not be treated as a current count.
A button does not answer which paid Cloudflare products an app activates, how it handles secrets, whether migrations are reversible, or what happens when free-tier limits are crossed. Bindings help frame those questions. An app using D1, R2, Queues, Workers AI, and Cron has a different billing and failure surface from a tiny Worker. Read the project's own deployment files before clicking.
Human approval remains the meaningful quality gate
A submission issue supplies only the repository, category, and replacement claim. Automation checks deploy evidence, recent activity, duplicates, the license, and bindings, but it never runs the submitted code. A maintainer must comment /approve before tooling creates an entry branch and pull request. The repository's maintainer list controls who may perform that step from the default branch.
This division is sensible. A machine can confirm that wrangler.toml exists, yet it cannot decide whether a project is a finished Calendly replacement or a starter kit wearing that label. GitHub showed 12 open issues and 0 open pull requests on October 4, 2026; the open queue consisted of proposed additions. The last push was October 1, and the repository had 1,139 stars, signs of an active but very young list.
Start here only after choosing Cloudflare
The list is best used as a shortlist generator. Choose a category, discard licenses you cannot accept, compare binding footprints, then inspect the surviving repositories for authentication, backups, migrations, costs, and issue activity. Our 61 passing tests give confidence that the local config parser behaves as its fixtures expect. They do not transfer trust to the applications it catalogs.
If you have not chosen a host, compare the same product category in Awesome Self-Hosted before committing. A VPS or Docker deployment may offer more portability and a larger project pool. If Cloudflare is already the target, this repository's strict inclusion rules and derived metadata save real research time. The useful output is a smaller set of candidates, not a one-click production decision.

