---
title: "Workers"
description: "Use Playstack's Web-standard domain contracts and edge adapters in Cloudflare Workers and other constrained runtimes."
tags: ["frameworks","workers","cloudflare","edge","web-standards"]
---

Many Playstack domain packages target Web platform primitives so they can run in Node.js and Workers without separate business logic. Worker compatibility is tested per package; Node framework adapters and provider SDK assumptions remain outside the Worker bundle.

[Start with the Workers guide](/docs/frameworks/workers/getting-started) to compose Web Crypto and a native streaming response inside a fetch handler.

## Good Worker starting points

| Capability                                          | Package                                                                                                      | Worker boundary                                                                                          |
| --------------------------------------------------- | ------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------- |
| Shared errors, results, time, and operation context | [`@playstack/core`](/docs/packages/foundation/core)                                                          | Dependency-free contracts.                                                                               |
| Encryption, digests, signatures, and tokens         | [`@playstack/crypto`](/docs/packages/foundation/crypto)                                                      | Injects `globalThis.crypto`; key configuration remains application-owned.                                |
| Validation                                          | [`@playstack/validation`](/docs/packages/foundation/validation)                                              | Portable schemas and HTTP validation errors.                                                             |
| Domain events                                       | [`@playstack/events`](/docs/packages/events-operations/events)                                               | In-process bridge with application-owned durable delivery.                                               |
| Authentication and accounts                         | [`@playstack/auth`](/docs/packages/identity/auth), [`@playstack/accounts`](/docs/packages/identity/accounts) | Portable services with injected persistence and request handling.                                        |
| Rate limiting                                       | [`@playstack/rate-limit`](/docs/packages/events-operations/rate-limit)                                       | Atomic store contract with a [`Durable Object adapter`](/docs/packages/events-operations/rate-limit-do). |
| Feeds and sitemaps                                  | [`@playstack/feeds`](/docs/packages/content-intelligence/feeds)                                              | Native streams, `Response`, and structural R2 storage.                                                   |
| Audit                                               | [`@playstack/audit`](/docs/packages/identity/audit)                                                          | Append-only chains with application-owned storage.                                                       |

Check each package reference before importing infrastructure or framework adapters. A portable core package may be Worker-compatible while one of its database or NestJS bindings is intentionally Node-only.

## Runtime rules

- Prefer Web `Request`, `Response`, `ReadableStream`, and `crypto.subtle` at the boundary.
- Construct services once at module scope when their dependencies are safe to reuse across requests.
- Derive request-specific operation context inside `fetch` and pass it into domain commands.
- Keep secrets in Worker bindings and parse them into narrow package configuration at composition time.
- Use Durable Objects, queues, R2, or another service through explicit structural adapters.
- Use `ctx.waitUntil()` only for observational work that is safe outside the response transaction.

## Deployment boundaries stay visible

Playstack does not hide Cloudflare bindings behind ambient globals. The Worker entry receives `env` and decides which binding satisfies each package contract. Native clients or bindings remain exposed where an application needs provider-specific capabilities.

## Cloudflare queue bindings

Use `@playstack/queues/cloudflare` for typed producers and Worker batch handlers. [Cloudflare Queues](/integrations/cloudflare-queues) documents individual acknowledgements, bounded JSON batches, durable quarantine and explicit unsupported operations. It does not replace arbitrary ingestion payloads automatically or install a Nest worker.

[Localization](/docs/packages/foundation/i18n) also runs through the portable policy/catalog boundary; choose an ICU runtime compatible with the selected Worker deployment.
