Foundation CMS is built on Cloudflare. Every site is its own Worker with its own D1 database and R2 bucket, a client's domain is attached through Cloudflare for SaaS with one DNS record on their side, and Cloudflare Turnstile can guard every form.
Overview
This integration connects Foundation CMS with Cloudflare. Foundation CMS runs entirely on Cloudflare's developer platform: Workers for the admin, the sign-in and each site; a dispatch namespace that holds every site's Worker; D1 for each site's database; R2 for each site's media; KV for the hostname lookup; and Workers AI for drafting.
Business Context and Core Use Case
Agencies want sites that are fast everywhere, cannot take each other down, and attach to a client's own domain without moving the client's DNS. Cloudflare's platform makes each of those a property of the architecture rather than a hosting add-on: sites run at the edge, each in its own Worker, and a client's domain is a custom hostname on our zone.
The Applications Involved
Foundation CMS (Foundation CMS) provisions each site's Worker, database, bucket, lookup and hostname, and runs the admin.
Cloudflare (Cloudflare) runs all of it, terminates TLS for client domains, and provides Turnstile for forms.
How the Integration Works
A new site is created by API, not by deploy: a database and a bucket are made, the site is recorded, bound, its lookup published and its hostname registered. The client adds a CNAME from their domain to cname.foundationcms.org, and Cloudflare validates it over HTTP, so no second record is needed. A visitor's request reaches a small dispatcher, which maps the hostname to the site's own Worker. For forms, a site can turn on Turnstile, checked by the site Worker and by the Foundation CMS intake alike.
Immediate Operational Value
Each site is isolated: its own Worker and storage mean one site's traffic or fault does not touch another, and switching the CMS off leaves every site serving. Clients keep their DNS where it is.
Security, Access, and Governance
Unknown hostnames get a clean refusal, never a default site. Media uploads are rewritten so SVGs can draw but never run. Account-level operations go through scoped API tokens rather than personal logins.
Summary
Cloudflare is what Foundation CMS stands on: every site its own Worker and storage at the edge, client domains attached with a CNAME, and Turnstile available for every form.
Frequently asked questions
Does the client have to move their DNS to Cloudflare?
No. Their domain is attached as a Cloudflare for SaaS custom hostname; they add a CNAME where their DNS already lives.
Can one site's problem affect another?
Each site is its own Worker with its own database and bucket, so they are isolated from one another.
Does Foundation CMS support Turnstile?
Yes. A site can turn on Turnstile (or reCAPTCHA) as a human check for its forms.








