---
service: "Publicasta"
schema_version: "1.0"
article_id: 266
title: "Cloudflare OS 提出了企业 AI 绕不开的问题"
language: "zh"
default_language: "en"
canonical_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=zh"
json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=zh"
api_url: "https://publicasta.com/api/public/v1/channels/ai_practice/articles/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=zh"
channel_url: "https://publicasta.com/api/public/v1/channels/ai_practice"
channel_articles: "https://publicasta.com/api/public/v1/channels/ai_practice/articles"
search_url: "https://publicasta.com/api/public/v1/search"
documentation_url: "https://publicasta.com/api-docs#reading-publicasta"
openapi_url: "https://publicasta.com/api-docs/openapi.json"
published_at: "2026-08-06T10:15:27+00:00"
updated_at: "2026-08-06T10:15:27+00:00"
translations:
  - language: "ar"
    html_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=ar"
    markdown_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.md?lang=ar"
    json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=ar"
  - language: "de"
    html_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=de"
    markdown_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.md?lang=de"
    json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=de"
  - language: "en"
    html_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=en"
    markdown_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.md?lang=en"
    json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=en"
  - language: "es"
    html_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=es"
    markdown_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.md?lang=es"
    json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=es"
  - language: "fr"
    html_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=fr"
    markdown_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.md?lang=fr"
    json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=fr"
  - language: "pl"
    html_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=pl"
    markdown_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.md?lang=pl"
    json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=pl"
  - language: "ru"
    html_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=ru"
    markdown_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.md?lang=ru"
    json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=ru"
  - language: "zh"
    html_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06?lang=zh"
    markdown_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.md?lang=zh"
    json_url: "https://publicasta.com/ai_practice/cloudflare_os_enterprise_ai_workspace_governance_2026_08_06.json?lang=zh"
---

# Cloudflare OS 提出了企业 AI 绕不开的问题

> 这个 agent workspace 更像企业 AI 工作治理的 blueprint：permissions、sandboxes、Gatekeepers、audit logs，以及 app sprawl 风险。

Cloudflare OS 这个名字很容易引来反感：它不是传统意义上的操作系统。但这次发布对 AI Practice 仍然重要，因为它指向企业采用 AI 的下一个问题：公司不只需要更好的 chatbot，而是需要可治理的 workspace，让 agents 能读取公司上下文、构建小应用、请求权限、留下审计记录，并控制模型开销。

 ![企业 AI 工作空间，包含隔离应用、Gatekeepers、审批和安全数据 vault](https://publicasta.com/storage/projects/8/pages/266/2026/08/cec1797e-fee9-4076-a149-93051cdd1ace.webp)

 Cloudflare 在 8 月 5 日 13:00 UTC 发布 Cloudflare OS，称其为面向 agents、apps and work 的开放平台。Cloudflare 说，2026 年 5 月起公司内部已有数千名员工用早期版本创建文档、幻灯片、重复任务自动化和小应用。公开发布包括 `cloudflare-os` 和 `cloudflare-os-starter`；检查时主仓库约有 3,900 stars、270 forks、Apache-2.0 license，并在 8 月 6 日仍有更新。

 Hacker News 讨论也很热，约 561 points 和 270 comments。争议集中在“这算不算 OS”、Cloudflare lock-in、Workers 成本、安全模型、Sandstorm 对比，以及会不会产生新的 SharePoint 式应用混乱。

 ## 为什么普通聊天不够

 Chatbot 适合问答，但企业工作需要 state、permissions 和 side effects。Sales ops 需要 CRM 数据，finance 需要内部表格和定义，support 需要 ticket data 和 approvals。把上下文粘到聊天窗口，或给一个宽权限 API token，都不是可靠架构。

 企业 AI 需要的是 workspace：company context、skills、documents、generated apps、connected systems、logs、access control and budgets。Agent 不再只是聊天标签页，而是受治理的内部工作 runtime。

 ## Cloudflare 的方案

 Cloudflare 描述了三层。第一层是带公司上下文和 shared skills 的 agent workspace：流程、术语、模板和重复工作指令。第二层是 security/governance：agents start with no access，通过 service-specific Gatekeepers 获得具体 capabilities，credentials 与 generated code 隔离。Cloudflare 还说 server code 在 Dynamic Worker 中运行，global outbound networking disabled；client code 在 sandboxed browser frame 中运行。

 第三层是 personal modifiable apps。生成的应用默认私有，可以像文档一样共享，也可以作为 blueprints 分享，而不包含 SQLite data、conversation history、credentials 或 connected resources。重点不是“AI 会写代码”，而是应用本身要有窄权限和 sandbox。

 ## Gatekeepers 是核心

 Gatekeeper 是 agent 与外部服务之间的 Worker。它不是把宽权限 API key 交给 agent，而是暴露一个很窄的能力：读取这张表、创建这个 ticket、总结这个 folder、为这个动作请求 approval。Gatekeeper 可以 mask fields、rate-limit、在 side effects 前要求人工批准，并记录 agent 看过什么。

 这把问题从“agent 有没有 Salesforce access”改成“在谁的身份下，对哪些数据，执行哪个动作，有什么审批和日志”。这是企业 AI 的正确方向。但如果 Gatekeeper 写得太宽，它就只是另一个 over-permissioned connector。

 ## Policy 要跟着数据走

 Cloudflare 另一个重要说法是 policy follows what the agent has observed。如果 agent 读取 sensitive table 并创建 dashboard，共享 dashboard 不应绕过原表权限。如果 agent 读取 private document 并生成 summary，summary 也不应自动变成公共内容。

 这是企业 AI 的核心难题之一。AI 会产生 derived artefacts：summaries、charts、mini-apps、code。它们可能泄露来源数据，即使来源文件本身没有被共享。Observation logs 不能完美解决 data lineage，但至少能回答 agent 读过什么、谁发起请求、用了哪个模型、输出去了哪里。

 ## 合理的试点

 第一批试点应该是低调但有价值的内部工作：基于 approved CRM fields 的 weekly sales summaries、support dashboards、data cleaning workflows、internal FAQ、incident review templates、procurement tables 和小型 reporting apps。先从一两个 Gatekeepers 开始，read-only by default，严格日志，小范围用户，明确预算，写操作必须 human approval。

 ## 风险在哪里

 第一个风险是 lock-in。项目是 Apache-2.0 open source，但架构强依赖 Workers、Dynamic Workers、Durable Objects、Access 和 AI Gateway。对已经使用 Cloudflare 的客户，这可能是合理取舍；但它不等于完全可移植。

 第二是成本。AI Gateway 提供 attribution、budgets 和 rate limits，但 agents 可能产生大量 model calls。试点前就要有 hard budgets、per-user attribution 和 anomaly alerts。

 第三是 derived outputs 泄露数据。第四是 app sprawl：员工生成大量 personal apps，有些变成关键流程，却没人负责版本、维护和下线。没有 lifecycle rules，AI 只会加速 SharePoint problem。

 ## 如何评估

 先问 agent 默认能读什么。安全答案应该是：什么都不能，直到授予。再问 outbound networking 是否默认关闭，read-only 和 side effects 是否分离，approval 是否由基础设施强制执行，credentials 是否 scoped and short-lived，logs 是否可审计，generated apps 是否有 owners、versions 和 retirement process。

 Microsoft、Google、OpenAI、Anthropic、Retool、Appsmith、Zapier、n8n、Dify 和 Langflow 都在争夺这层 enterprise workflow。Cloudflare 的差异是 infrastructure and Zero Trust。真正的问题不是 Cloudflare OS 是否“真的是 OS”，而是企业是否准备好在员工把真实工作建到 agents 上之前，先定义清楚 operating rules。
