메뉴
HN
Hacker News • 51일 전

클라우드플레어 OS: 에이전트를 위한 개방형 플랫폼

IMP
8/10
핵심 요약

클라우드플레어(Cloudflare)가 조직의 고유한 업무 맥락과 시스템을 이해하고 작동하는 '클라우드플레어 OS'의 새로운 버전을 오픈소스로 공개했습니다. 이 플랫폼은 내부 데이터에 대한 안전한 접근과 개인화된 앱 구축을 지원하여, 개발자뿐만 아니라 모든 구성원이 AI 에이전트를 활용해 업무 생산성을 크게 높일 수 있도록 설계되었습니다.

번역된 본문

모든 조직에는 존재 이유이자 미션이 있습니다. 조직은 이 미션과 함께 자체적인 용어, 절차, 시스템, 표준, 그리고 업무 방식을 직원들에게 전달합니다. 그리고 사람들은 자신의 경험과 이러한 맥락을 결합하여 미션을 향해 나아갑니다. 업무는 코드, 문서 및 슬라이드, 인간관계, 실제 세계의 결과물 등 다양한 형태를 띨 수 있습니다. 이 중 일부는 명확합니다. 코드는 실행되거나 실행되지 않거나 둘 중 하나입니다. 지난 몇 년 동안 AI 에이전트들은 이러한 피드백 루프를 활용하여 개발자들에게 '작동하는' 코드를 생성해 주었습니다. 하지만 개발자가 아닌 다른 부서의 직원들은 어떨까요? 조직의 나머지 구성원들에게도 같은 수준의 효율성을 가져오는 것은 더 어려운 문제입니다. 에이전트가 조직의 맥락을 이해하고, 사람들이 업무에 사용하는 시스템에 접근할 수 있어야 하기 때문입니다. 또한 그들은 그러한 맥락과 접근 권한을 활용해 조직이 미션을 달성하도록 돕는 실제 작업으로 변환해야 합니다. 이것이 바로 우리가 '클라우드플레어 OS(Cloudflare OS)'를 만든 이유입니다. 이 플랫폼은 회사의 운영 방식, 지식, 그리고 의존하는 시스템을 중심으로 구축된 에이전트와 워크스페이스를 모든 직원에게 제공합니다.

올해 5월, 저희는 클라우드플레어의 모든 직원에게 첫 번째 버전의 클라우드플레어 OS에 대한 접근 권한을 부여했습니다. 엔지니어링 부서를 넘어 다양한 부서의 수천 명의 직원들이 매일 이를 사용하여 문서와 슬라이드를 만들고, 반복 가능한 작업을 자동화하며, 데이터를 시각화하고 업무에 도움을 주는 소규모 앱을 구축하고 있습니다. 또한 클라우드플레어 OS는 내부 팀이 구축한 맥락과 기술의 공유 라이브러리를 모두에게 제공합니다. 이는 당사의 용어, 절차, 그리고 반복적인 업무를 수행하는 모범 사례를 에이전트가 따를 수 있는 지침으로 캡처합니다. 한 사람이 더 나은 업무 방식을 알아내면 다른 모든 사람도 그것을 사용할 수 있습니다.

오늘, 우리는 새로운 버전의 클라우드플레어 OS를 오픈소스로 공개합니다. 이제 모든 조직이 이를 배포하고, 내부 시스템과 연결하여 자신만의 맞춤형 플랫폼으로 만들 수 있습니다.

첫 번째 버전에서 얻은 교훈 오늘 오픈소스로 공개하는 클라우드플레어 OS는 내부적으로 첫 번째 버전을 운영하면서 얻은 학습을 기반으로 합니다. 이 여정에 대해서는 저희 CIO인 샘 리아(Sam Rhea)의 블로그 게시물에서 자세히 다루고 있습니다. 첫 번째 버전은 개인이 개인 워크스페이스에서 에이전트와 협업하는 데 중점을 두었습니다. 앱은 내부 시스템과 연결된 살아있는 소프트웨어라기보다는 정적이었으며, 대부분의 결정론적 작업(deterministic jobs)은 여전히 에이전트 기술을 다시 실행하고 더 많은 모델 토큰을 소비해야 했습니다.

협업은 더 근본적인 문제를 노출시켰습니다. MCP 서버에 대한 접근 권한은 에이전트가 호출할 수 있는 도구가 무엇인지 알려주었지만, 에이전트가 관찰한 기본 리소스가 무엇인지는 알려주지 않았습니다. 사람들이 워크스페이스, 앱, 결과물을 공유하기 시작하면서, 협업 과정에서 누군가 볼 권한이 없는 정보가 노출되지 않도록 보장해야 했습니다.

이러한 문제를 해결하기 위해 우리는 새로운 기반 위에 클라우드플레어 OS를 재구축했습니다. 보안은 앱을 구축하거나 에이전트를 사용하는 모든 사람이 올바르게 구현해야 하는 무언가가 아니라 플랫폼의 일부여야 합니다. 그 결과, 이를 운영하는 회사의 소유가 되도록 설계된 플랫폼이 탄생했습니다. 인터페이스를 사용자 정의하고, 도구를 연결하며, 조직의 업무 방식을 담아내는 기술과 맥락을 추가할 수 있습니다.

클라우드플레어 OS 소개 클라우드플레어 OS는 다른 많은 AI 도구와 마찬가지로 브라우저 내의 대화로 시작됩니다. 이 플랫폼을 다르게 만드는 것은 각 대화가 조직이 큐레이션한 맥락과 기술을 바탕으로 이루어진다는 점입니다. 워크스페이스에 목표를 부여하면, 에이전트는 해당 지식을 활용하고 조직이 이미 사용 중인 도구 및 데이터와 연동하여 그 목표를 달성할 수 있습니다.

클라우드플레어 OS는 세 가지 부분으로 구성됩니다:

  1. 회사가 구축한 맥락과 기술을 바탕으로 하는 에이전트 워크스페이스로, 에이전트가 코드를 작성하고 실행할 수 있는 격리된 런타임을 갖추고 있습니다.
  2. 내부 데이터 및 서비스에 안전하게 접근하기 위한 새로운 보안 및 거버넌스 프레임워크입니다.
  3. 사람들이 직접 구축하고, 공유하며, 계속해서 수정할 수 있는 개인용 맞춤형 앱 플랫폼입니다.

단순한 대화로 시작한 것이 문서, 앱, 또는 작업을 지속적으로 수행하는 워크플로우로 발전할 수 있습니다.

회사의 모든 구성원을 위한 에이전트 워크스페이스 에이전트 워크스페이스는 귀사의 모든 구성원을 위해 설계되었습니다.

원문 보기
원문 보기 (영어)
Every organization has a mission, a reason for being. Organizations pass that mission — along with their terminology, procedures, systems, standards, and ways of working — to their people. People, in turn, take this context together with their own experience and work towards the mission. Work can take many forms, from code, to documents and slides, to relationships, to outcomes in the physical world. Some of these are straightforward: code either runs or it doesn’t. Agents have been using this feedback loop to produce code that “works” for developers over the last couple of years. But what about the rest of us? Bringing the same leverage to the rest of the organization is a harder problem. Agents need to understand the context of the company and be able to reach the systems people use to do their jobs. They need to turn that context and access into work that moves the organization towards its mission. That’s why we created Cloudflare OS. It gives every person an agent and workspace built around their company: how it works, what it knows, and the systems it relies on. In May of this year, we gave every person at Cloudflare access to the first version of Cloudflare OS. Thousands of people across every function, many of them outside of engineering, use it every day to create documents and slides, automate repeatable tasks, and build small apps to visualize data and help them do their work. Cloudflare OS also gave everyone a shared library of context and skills built by teams at Cloudflare. It captures our terminology, procedures, and best-known ways of doing recurring work as instructions an agent can follow. When one person figures out a better way to do something, everyone else can use it. Today, we are open sourcing a new version of Cloudflare OS . Any organization can deploy it, connect it to internal systems, and make it their own. What we learned from the first version The Cloudflare OS we are open sourcing today is based on what we learned from running the first version internally, a journey our CIO, Sam Rhea, covers in his blog post . The first version centered on individuals working with agents through private workspaces. Apps were static rather than live software connected to internal systems, and mostly deterministic jobs still required running an agent skill again and consuming more model tokens. Collaboration exposed a more fundamental challenge. Access to an MCP server told us which tools an agent could call, but not which underlying resources the agent had observed. Once people began sharing workspaces, apps, and outputs, we needed to ensure that collaboration could not expose information someone was not permitted to see. We rebuilt Cloudflare OS on a new foundation to solve these problems. Security had to be part of the platform, not something every person building an app or using an agent has to implement correctly. The result is a platform designed to belong to the company running it. You can customize the interfaces, connect your tools, and add the skills and context that capture how your organization works. Introducing Cloudflare OS Cloudflare OS starts with a conversation in your browser, like many other AI tools. What makes it different is that each conversation is grounded in the context and skills your organization has curated. Give your workspace a goal, and it can draw on that knowledge and work with the tools and data your organization already uses to achieve it. Cloudflare OS combines three parts: An agent workspace grounded in context and skills your company curates, with an isolated runtime where agents can write and run code. A new security and governance framework for safe access to internal data and services. A platform for personal, modifiable apps that people can build, share, and continue changing. What begins as a conversation can become a doc, an app, or a workflow that continues doing the work. An agent workspace for everyone in your company Agent workspaces were designed for everyone in your organization to use. You interact with them in your browser, so you don’t have to be a developer or know how to use a terminal. A workspace combines agent sessions, persistent state, outputs and files, resource access, and an isolated runtime where the agent can write and run code. They come loaded with the curated context and skills your team or company has collected. No more reinventing the wheel for every task — if someone on your team has figured out the best way to do something, everyone benefits. People no longer have to explain the same process, terminology, and best practices to a model every time they start a task. A few things you can do: Research and ask questions Ask a workspace to research a topic using company context and the resources you make available to it. The agent can write code to search, filter, join, and analyze information instead of pulling an entire dataset into the model’s context window. Create docs, slides, and spreadsheets A workspace can turn its research into a document, presentation, or spreadsheet that you can continue editing. These outputs do not have to be static files. They can remain connected to live data, be updated as their sources change, and still be exported to familiar formats or services such as Google Drive. Create collaborative, connected apps for your team When a document or spreadsheet is not enough, the agent can build an app with its own interface, logic, and state. The app can use connected company resources and support multiple people working together. Run deterministic workflows Not every job needs a full agent session. Many are a known sequence of steps with one or two places where judgment is useful. A workspace can turn those jobs into mostly deterministic workflows, using code for the predictable steps and a model only where it adds value. Workflows can run on demand, on a schedule, or when an event occurs in a connected system. Cloudflare OS gives agents and apps governed access to systems of record through Gatekeepers (more on this in the security section below). It also supports existing Model Context Protocol (MCP) servers your organization already uses via MCP Server Portals . A new security and governance framework for safe access to internal data and services As people begin experimenting with AI at work, one of their first requests is often for API keys to company systems. This makes sense: AI isn’t much use at work if it doesn’t have access to the systems people use to do their jobs. But handing over API keys to people and agents is dangerous and does not scale. Keys often provide broad, long-lived access that is difficult to constrain, share safely, and audit. MCP gives agents a better way to use these systems. An MCP server can hold the credential and expose a defined set of tools instead of handing the key directly to the agent. But controlling which tools an agent can call is only the first step. MCP alone does not tell us which underlying resources an agent has observed. The agent can combine information across systems, send it somewhere less restricted, or expose it through apps and outputs to people who may not be allowed to see the original resources. Authorization has to account for where the data can go next. Agents start with no access Cloudflare Access controls who can enter Cloudflare OS. Inside, every agent and app starts with access to nothing. An agent can ask for access to a specific resource, which you can grant or deny. Generated code receives that resource as a typed binding: const issues = await env. PROJECT . listIssues ({ teamId: "ENG" , state: "open" , }); env.PROJECT is a capability representing permission to use a specific resource under a specific policy. The credential remains completely isolated from the agent and any generated code. Server code runs in a Dynamic Worker with global outbound networking disabled. Client code runs in a sandboxed frame in the browser. Neither can reach the Internet except through capabilities you e