Key Files in the CFnew Repository for Worker Logic and Configuration

The CFnew repository centers on three critical files: 明文源吗 (the human-readable Worker source), 少年你相信光吗 (the obfuscated production build), and wrangler.toml (the deployment configuration), with supplementary CI workflows handling build automation and testing. This Cloudflare Workers-based proxy service implements a full-stack subscription management system through a carefully organized codebase that separates readable development source from optimized production artifacts.

Core Worker Implementation (明文源吗)

The 明文源吗 file serves as the plain-source entry point containing all runtime logic for request handling, protocol selection, and subscription generation. Located at the repository root, this JavaScript module implements the complete Worker behavior before obfuscation.

Request Routing and Protocol Selection

After importing the Cloudflare Sockets API (import { connect } from 'cloudflare:sockets';), the script initializes global variables that map directly to environment variables. These globals control protocol enablement flags (ev for VLESS, et for Trojan, ex for xhttp) and configuration parameters (u for UUID path, p for custom ProxyIP, s for SOCKS5 proxy).

The request router handles multiple endpoints:

  • Subscription generation for clients including Clash, Surge, Sing-Box, Loon, Quantumult X, and V2Ray
  • REST API endpoints under /api/preferred-ips for managing custom IP lists
  • ECH/ALPN feature exposition via specialized headers

Key helper functions include isValidIP for IP validation, createNodeNamer and createCompactNodeNamer for generating client-specific node names, and normalizeALPN for ALPN value standardization.

KV-Based Configuration Management

The script implements a two-tier configuration system where environment variables override KV store values, which in turn override hardcoded defaults. The configuration loader uses a 30-second cache window to minimize KV read operations:

// Load KV configuration with short-term caching
async function loadConfig() {
  const now = Date.now();
  if (kvConfig && now - kvConfigLastLoad < KV_CACHE_TTL) return kvConfig;

  const kv = await C.get('config', { type: 'json' });
  kvConfig = kv || {};
  kvConfigLastLoad = now;
  return kvConfig;
}

The KV namespace must be bound to the variable C in the Cloudflare dashboard, as referenced by await C.get('config') throughout the request handling flow.

Region-Aware ProxyIP Selection

The 明文源吗 file contains a regionMapping table that translates Cloudflare region codes to human-readable names. When enableRegionMatching is true, the script performs intelligent ProxyIP selection based on the incoming request's Cloudflare region, optimizing latency by matching users to geographically appropriate exit nodes.

Production Build Artifact (少年你相信光吗)

The 少年你相信光吗 file contains the obfuscated and minified version actually deployed to Cloudflare Workers. Generated automatically by the obfuscate.yml workflow, this artifact reduces the script size to under 150KB while hiding implementation details. The obfuscation process transforms the readable 明文源吗 source into a compact form without altering runtime behavior, ensuring the production Worker executes the same logic through a more efficient payload.

Deployment Configuration (wrangler.toml)

The wrangler.toml file provides minimal but essential Cloudflare Workers configuration:

compatibility_date = "2026-01-20"

This compatibility date ensures access to latest runtime features including WebSocket support and fetch streaming capabilities. While the file does not declare the KV binding directly (this happens via dashboard configuration), it is required for the wrangler publish command to function correctly.

Environment Variable Reference (README.md)

The README.md file serves as the authoritative documentation for deployment configuration, enumerating all environment variables that control Worker behavior:

  • u: UUID path for authentication
  • p: Custom ProxyIP override
  • s: SOCKS5 proxy configuration
  • d: Custom path definition
  • wk: Forced worker region selection
  • ech: Encrypted Client Hello settings
  • alpn: Application-Layer Protocol Negotiation values

The documentation also describes the configuration UI, supported protocols (VLESS, Trojan, xhttp), and step-by-step deployment instructions for new users.

CI/CD and Build Automation

Obfuscation Workflow (.github/workflows/obfuscate.yml)

The obfuscation workflow automates the transformation from development source to production artifact. Triggered on pushes to the main branch, this GitHub Actions workflow runs the JavaScript obfuscator on 明文源吗 and commits the resulting 少年你相信光吗 file back to the repository. This ensures the production script stays synchronized with source changes without manual intervention.

Testing Pipeline (.github/workflows/test.yml)

The test workflow runs linting and syntax validation against the plain source. By verifying 明文源吗 remains syntactically valid after modifications, this CI check prevents broken builds from reaching the obfuscation stage. The workflow typically executes eslint or similar tools to catch syntax errors before they propagate to production.

Summary

  • 明文源吗 contains the complete, human-readable Worker implementation with functions like isValidIP, createNodeNamer, and the region-aware routing logic.
  • 少年你相信光吗 is the obfuscated production build generated by CI, optimized for size and deployed to Cloudflare Workers.
  • wrangler.toml sets the compatibility_date to 2026-01-20, enabling modern runtime features required by the socket connections.
  • README.md documents all environment variables (u, p, s, d, wk, etc.) and deployment procedures.
  • .github/workflows/obfuscate.yml automates the build process from source to production artifact.
  • .github/workflows/test.yml validates source syntax before obfuscation.

Frequently Asked Questions

What is the difference between 明文源吗 and 少年你相信光吗?

明文源吗 is the plain-text source code containing readable JavaScript with comments and clear variable names, serving as the development entry point. 少年你相信光吗 is the obfuscated and minified version produced by the CI pipeline, which compacts the code to under 150KB and obscures implementation details while maintaining identical runtime behavior for production deployment.

How does CFnew handle configuration storage?

CFnew implements a hierarchical configuration system where path parameters take highest priority, followed by environment variables, then KV store values (await C.get('config')), and finally hardcoded defaults. The script caches KV configuration for 30 seconds (KV_CACHE_TTL) to reduce read operations while maintaining configuration freshness.

What environment variables does CFnew support?

According to the README.md and source code in 明文源吗, CFnew recognizes variables including u (UUID path), p (custom ProxyIP), s (SOCKS5 proxy), d (custom path), wk (forced worker region), ev (VLESS enable), et (Trojan enable), ex (xhttp enable), ech (Encrypted Client Hello), and alpn (protocol negotiation), with boolean flags defaulting to true or false depending on the specific protocol.

How do I deploy the CFnew worker to Cloudflare?

First, bind a KV namespace to the variable C in your Cloudflare dashboard. Then run wrangler publish which reads wrangler.toml (setting compatibility date to 2026-01-20) and uploads 少年你相信光吗 as the Worker script. Alternatively, deploy the plain source directly by replacing the script reference with 明文源吗 during development testing.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →