DWG RG-002 · SIDE PROJECT · PRIVATE

Can Do
Crew

A ready-to-launch booking site for a kid-run curbside bin-cleaning business.

STATUS: PRIVATE · BUILT 2026

DETAIL B — SHOWN IN THE PROJECT'S OWN FINISH

private · waiting on its owner
Can Do Crew
  • Cloudflare Worker
  • Static assets
  • D1
  • Turnstile
  • Email Routing
  • Access
Can Do Crew request routing Visitors get the prebuilt page from Cloudflare's static assets and post bookings to the Worker. Admins pass through Cloudflare Access before reaching the Worker. The Worker uses D1, Turnstile and Email Routing, and calls the US Census geocoder in the background. CLOUDFLARE · custom domain Visitor's phone page + booking form Admins booking dashboard Static assets prebuilt HTML, CSS, JS no Worker invocation Cloudflare Access email one-time PIN Worker POST /api/book /admin /api/admin/* re-checks the Access JWT shared form validation service-area street list launch / regular pricing D1 bookings table Turnstile siteverify Email Routing booking alerts US Census geocoder GET POST /api/book + JWT in the request after the response (waitUntil)
Page views never wake the Worker. Dashed arrows run after the booking is saved, so a flaky email or geocoder can't lose a customer.

SECTION C–C · SCOPE

This one is built ahead of its owner. It's a working mockup for a bin-cleaning business my kid might run next summer, ready to switch on if he wants it.

A small business needs a page that loads fast on a phone, takes a booking, and tells someone about it. That's the whole job, so the architecture stays that small: one Cloudflare Worker serving a prebuilt page, a single D1 table, and an admin page for working through the week's bookings.

The booking form is protected by Turnstile and a honeypot. Each booking is matched against the service area, priced at the launch rate or the regular rate, and saved before anything else happens. An email alert and a geocode for future route planning follow in the background.

The admin side sits behind Cloudflare Access, and the Worker re-verifies the Access token itself, so a misconfigured policy still can't expose customer data. From there, bookings get grouped by weekend day, marked confirmed or done, and annotated.

DESIGN DECISIONS

  1. FREE TIER, ONE DEPLOYABLE

    The Worker, D1, Turnstile, Email Routing and Access all fit Cloudflare's free plan. One deploy command builds and ships the whole thing.

  2. STATIC BY DEFAULT

    The marketing page is prebuilt HTML. Only the booking API and the admin page run code, so page views cost nothing.

  3. SAVE FIRST, THEN NOTIFY

    The booking row is committed before the email alert and geocoding run in the background. A broken email setup can't lose a customer.

  4. ONE SET OF FORM RULES

    The same validation module runs in the browser and the Worker, so both enforce identical rules with identical error text.

  5. CONTENT IN ONE FILE

    Prices, the launch offer and the FAQ live in one JSON file and are baked in at build time. Changing a price is an edit and a deploy, never a code change.

  6. FLAG, DON'T REJECT

    Addresses are checked against a hand-reviewed list of served streets. Out-of-area bookings are saved and flagged so a person makes the call on edge cases.

FULL SIZE · DRAG TO PAN