v0.1.0Early, open and moving fast

Write it like Laravel.Run it on the edge.

Flying Worker is a full-stack framework for Cloudflare Workers. Guards, sessions, middleware, controllers and flash messages, rendered with Hono, React and Inertia.

  • MIT licensed
  • Strict TypeScript
  • Hono, React and Inertia

The code

Controllers return pages, not JSON.

If you have written Laravel, you already know how to read this. Routes, guards, sessions and data, with no API boilerplate between your Worker and your React pages.

Routes that read like Laravel

routes/web.tsx
Route.get("/dashboard", [DashboardController, "index"], ["auth"]); Route.group("/admin", () => {  Route.get("/dashboard", [AdminController, "index"]);   Route.group("/users", () => {    Route.get("/", [UserController, "index"]);      // /admin/users  }, ["can:manage-users"]);}, ["auth"]);
  • Nested groups stack their prefixes and middleware.
  • Controllers are [Class, "method"] pairs with a fresh instance per request.
  • An unknown middleware alias throws at boot, not halfway through a request.

Life of a request

Order matters. Watch it run.

Every request walks the pipeline you configure: global middleware, then the web or api bucket, then route aliases, then your controller. Session always runs before CsrfToken.

Step 1 of 8

edge

Request

GET /dashboard reaches your Worker. Boot already happened once for this isolate.

config/middlewares.ts
export const middlewaresConfig: MiddlewaresConfig = {  global: [MaintenanceMode],                     // every request  web:    [Session, CsrfToken, HandleInertiaRequests],  // everything except api/*  api:    [Cors],                                // api/* only  aliases: { auth: RequireLogin },               // referenced by name on routes};

What is in the box

Everything you reach for in Laravel. Sized for a Worker.

One coherent set of tools instead of a pile of packages to glue together.

  • Routes and groups

    Route.get, post, put, delete and all, with nested groups that stack prefixes and middleware.

  • Middleware buckets

    Global, web, api and named aliases. Write your own by extending BaseMiddleware.

  • Guards that know roles

    Session or JWT guards with roles, permissions and social sign-in for Google, GitHub, LinkedIn and X.

  • Sessions and flash

    KV or signed-cookie drivers. Flash messages live for exactly one request.

  • BREACH-aware CSRF

    The token cookie is XOR-encoded with a per-request nonce, mirroring Laravel.

  • D1 through Drizzle

    DB() is cached per request and fully typed through declaration merging.

  • R2 file storage

    Upload, list, copy, move and delete, with size and MIME limits from config.

  • Boots once per isolate

    Memoized, atomic and self-healing. A failed boot simply retries on the next request.

  • Tested on real requests

    Vitest runs real Hono request cycles with in-memory stand-ins for KV and D1.

Built on Cloudflare Workers, Hono 4, React 19, Inertia 2, Cloudflare D1, Drizzle ORM, Workers KV, R2, Zod, Vite 7, Wrangler, TypeScript.

Quick start

Up and running in six commands.

  1. 1

    Clone and install

    One monorepo: the framework package and an example app to build on.

  2. 2

    Create your D1 database

    Paste its id into framework/wrangler.json, then run the local migrations.

  3. 3

    Start building

    npm run dev reloads the Worker and the React app together.

  4. 4

    Ship it

    Run npx wrangler deploy from framework/ and you are live on the edge.

Terminal
git clone https://github.com/flying-worker/flying-worker.gitcd flying-workernpm installnpx wrangler d1 create flying-worker-db   # copy the id into framework/wrangler.jsonnpm run db:migrate:localnpm run dev# the Worker and the React app now reload together
Made with Modulify