Cloudflare Alert Triage Agent with OpenCode

The judgement in this template is small and very specific: two probe locations failing while six pass is a routing problem, failing everywhere is an origin problem, and those two sentences send a person somewhere completely different at three in the morning. OpenCode is light to point at that decision, and being model agnostic you can put something stronger behind the zones that carry revenue.

Loading preview…
Free to start · guided setup

Watch it work before it's live

Run a staged conversation — no account needed. The agent handles it for real while a simulated world answers its tool calls; nothing touches real accounts, and nothing is actually sent.

HTTP DDoS attack detected and mitigated

tienda.bellavia.mxBellavia Retail, account a91c4

Managed rule 6a2f began mitigating at 03:14 UTC. Peak 412,000 requests per second against /checkout/session, 94 percent from three autonomous systems. Mitigation is still active. Nothing in the payload about origin status.

Set up in minutes

Using this template drops you into a guided setup. It asks exactly this, nothing else:

  1. Connect Cloudflare

    One sign-in. The agent acts through your account, scoped to what this template uses.

  2. Connect Slack

    One sign-in. The agent acts through your account, scoped to what this template uses.

  3. Alert rules

    Which Cloudflare alerts deserve a channel post and what each kind means for you - your zones and who owns them, how seriously you take an attack alert next to a health check flip, and where somebody should look first when your origin throws errors or a certificate stops renewing.

  4. Runs on OpenCode

    Preselected for this page — connect your OpenCode account during setup, or switch to NoClick's built-in models with one click.

  5. Watch it handle a test run

    A staged conversation against a simulated world — then it’s live.

Why OpenCode for this agent

Six passing probes changes everything

Counting how many locations still succeed takes half a minute and almost never happens under pressure. Getting that ratio into the first line of the note is most of the value.

Stronger model where it earns it

The checkout zone and the marketing site do not deserve the same spend. Each fork sets its own model, so depth goes where an hour of confusion is expensive.

Before you fork

Analytics come back slowly during a real incident. What then?

The note is written from what actually returned, and a window that failed to load is stated rather than filled in. A struggling zone produces a later note, never a fabricated one. Where your alert rules say nothing about that alert type, it still posts what fired plus whatever numbers it has and hands the judgement to whoever owns the zone.

Run it with a different agent

Put Cloudflare Alert Triage Agent to work on OpenCode

Free to start. Guided setup, a test run against staged conversations, and it's live.