Skip to content
Brolly

Protect yourself from runaway Cloudflare spend

Brolly is a free and open source monitor and circuit breaker that covers all billable Cloudflare services.

Installation is per account. Your policies, credentials, incidents, and audit history are private and stay within your assigned Cloudflare account.

Brolly covers every billable Cloudflare service.

Durable ObjectsWorkersD1R2KVQueuesWorkers AIAI Gateway

See runaway usage while there is time to respond.

A single undetected runaway loop can result in a five-figure invoice. Brolly defends your wallet with robust alerts and a configurable circuit breaker.

A durable Cloudflare usage ledger with granular protection.

Brolly retains daily account, product, namespace, Worker, and individual-resource history in your D1 database. Eligible Workers and Durable Objects support audited reversible quarantine.

Explore stored usage

Drill from account totals into products, namespaces, Workers, exact object IDs, metrics, and daily evidence quality.

Set explicit limits

Create ordered alert levels with per-level thresholds for account-local days or Cloudflare billing cycles.

Contain exact runaways

Prepare or Auto entries can contain eligible Workers, Durable Objects, and Queues after a qualified breach.

Restore quarantined objects

Restore quarantined objects after fixes are applied. Brolly preserves the resource, storage, messages, and history with no data loss.

Deploy Brolly to your Cloudflare account

Install Brolly in the Cloudflare account you want to protect. When deployment finishes, open your private dashboard and sign in with Cloudflare.

Runs in your Cloudflare accountYour limits, incidents, and controls stay in your own deployment. Deploy to Cloudflare
  1. 1Deploy to Cloudflare.

    Choose your Cloudflare account and a name for the Brolly Worker, then click Deploy.

  2. 2Open Brolly and sign in.

    Visit the private Brolly URL created for you and authorize the Cloudflare account you want it to protect.

  3. 3Review what Brolly found.

    See your Workers, Durable Object namespaces, individual objects, current usage, and any monitoring gaps.

  4. 4Choose your protection.

    Connect labeled channels, arrange alert levels, set per-level limits, and review action eligibility.

You are ready to protect your accountReview your channel delivery, alert-level entries, limits, and runtime evidence before using Auto actions.

How do updates work? Save the GitHub repository name in Settings. While you use Brolly, it checks at most hourly and shows a banner for new releases. The button runs a repo-local workflow that opens a pull request for you to review; it never silently deploys. Private repositories work normally, no GitHub token is stored in Brolly, and your D1 binding, variables, and secrets are preserved.

Who can sign in later? A Cloudflare member who can authorize Brolly's requested scopes for the bound account may sign in. A user who authorizes a different account is rejected. Changing accounts requires deliberately resetting the installation's D1 binding or deploying a new instance; the latest successful authorization supplies the revocable Cloudflare grant Brolly uses for monitoring and controls.

What passes through Brolly's login service? Only the one-time Cloudflare authorization result. The separate stateless relay verifies the requesting installation, returns the short-lived code to that exact deployment, and never receives the access or refresh token stored in your D1 database.

Billing reconciliation is optional but highly recommended. Start with one bounded monitoring-access check. Brolly shows the results first, then reveals OAuth reconnection or a prefilled, account-scoped Billing Read user-token form when needed. A verified billing token is encrypted inside your D1. You can add or replace it later in Settings. Risk tolerance uses imported history to seed each daily and billing-cycle chart.

Set period limits throughout the resource hierarchy

Choose one shared risk tolerance curve for every alert level. Each empty chart starts from the median historical usage for its scope. Daily limits use the account timezone. Cycle limits use reconciled Cloudflare boundaries. Saved chart values remain independent of later tolerance changes.

Additive levels

A firing level includes channel and action entries from every level before it.

Prepared actions

Prepare entries create an audited action for operator approval.

Auto actions

Auto entries require fresh evidence, eligible resources, and verified runtime controls.

A zero-I/O deployment fuse

Monitoring works without application changes. Exact Worker and Durable Object quarantine uses the tiny @standardagents/brolly-runtime package. Its hot path only parses a deployment binding and compares IDs. It performs no HTTP, KV, D1, or Durable Object storage operation.

Give the install to your coding agentBrolly's final setup step builds one resource-aware prompt for Claude Code, Codex, Cursor, or another coding agent. It edits and tests your code, then stops before deployment so you can review and verify the result.
Install
pnpm add @standardagents/brolly-runtime

One line in a Durable Object constructor

TypeScript
constructor(ctx: DurableObjectState, env: Env) {
  super(ctx, env)
  brollyDurableObject(ctx, env)
}

Stop ingress before waking the object

TypeScript
brollyWorker(env)
const id = env.ROOMS.idFromName(name)
brollyWorker(env, { durableObjectId: id.toString() })
return env.ROOMS.get(id).fetch(request)
Preserved

Object SQLite rows, messages, queues, and history remain intact.

Isolated

Only the named target ejects; unrelated object IDs continue serving.

Reversible

Resume removes the fuse target through a new audited deployment.

Wake the people who can respond

Configure Cloudflare Email, Discord, Postmark, Resend, Slack, Twilio SMS, or a generic HTTPS webhook with labeled channels and reusable provider accounts. Cloudflare Email, Resend, and Postmark channels can group multiple recipients under one label. Channels sharing a provider account remain distinct groups. Twilio uses one destination number per channel.

DiscordStructured incident webhooks
SlackIncoming webhook summaries
Email, SMS, and webhooksCloudflare Email, Resend, and Postmark support recipient groups. Twilio uses one destination number per channel. Generic HTTPS delivery uses an endpoint.

The monitor must not become the runaway workload

Every pass defaults to hard limits of 300 GraphQL dataset queries, 50 REST requests, 100,000 D1 rows read, 50,000 D1 rows written, and 45 seconds. Operators can configure each ceiling within a fixed product maximum. Durable Object and Worker usage is collected in stable 10,000-row pages without waking objects or reading customer storage.

  • Unknown telemetry raises a coverage incident. Brolly never records it as zero or healthy.
  • Brolly and its notification path are protected from automatic shutdown.
  • Projected dollars never authorize a stop; automatic action requires fresh raw usage.
  • Controls preserve resources and data and record rollback state before execution.

Put the umbrella up before the next spike.

Deploy one self-hosted Brolly per Cloudflare account.

Deploy to Cloudflare