DRQ service configurations
The existing localisation hook checks these shapes before Alchemy plans a Worker declared in protectedWorkers. The service register describes available controls; the hook does not infer protected-data use from application source or certify a handler merely because its binding exists.
| Configuration | Plan-time rule |
|---|---|
| Protected Worker | Bind the existing residency-pool / ResidentObject namespace; declare each storage use. |
| Declared D1 database | Read replication must be disabled or omitted (Alchemy converges omission to disabled), unless the database is explicitly none-protected. Enabled or unresolved replication is refused, including with a storage waiver and without a Worker binding. |
Native D1 or R2 with residency: verified |
Reach the active ledger for the exact taken physical ID. R2 must use the quarantine's default jurisdiction. |
| Service binding | The transport has a control implementation; the protected Worker still needs its pool binding and storage declarations. The application must use the runtime execution guard. |
| KV, native Queues, native Workflows, Static Assets, analytics, enabled logs/traces, Logpush or tail consumers | No qualified protected-data configuration yet. Refuse unless that specific use is explicitly none-protected. |
| Unknown emitted binding type | Refuse unless that specific use is explicitly none-protected. |
| Plain configuration, JSON configuration, secret-text credentials, version metadata | Control configuration; these do not grant application-data residency. |
For a native binding, the existing declaration key is Worker/Binding. If it references a declared storage resource, use that resource's key instead. Worker asset settings use Worker/assets; Worker logging settings use Worker/logs. Alchemy enables logs by default: disable observability explicitly for protected Workers, including enabled binding-contributed traces. Explicit Worker trace settings take precedence over binding contributions. none-protected means that use carries no protected application data. It does not qualify the native product or permit arbitrary payloads in credentials. Adding a waiver cannot qualify a not-yet service; a D1 storage waiver also cannot permit enabled or unresolved read replication. The existing location-waiver mechanism remains separate.
Present logging channels must be literally disabled; unresolved Output, Config or Effect settings cannot prove that a channel is off before planning. Empty tail-consumer lists are harmless; nonempty or unresolved lists use the same logging declaration.
The checks reuse registered resources, emitted bindings and the existing intent. They create no new ledger, waiver mechanism or consumer maintenance step. Unprotected control stacks retain their explicit classification. Native products stay unqualified until their own bounded experiments pass; a composed R2 or DO replacement must not relabel native KV, Queues or Workflows as qualified.
Runtime guards, handler wiring, arbitrary outbound requests and use of Cache API remain application implementation concerns. The shared queued-job interface still accepts synthetic jobs only; its separate, fixed ASIC, ABN and DFAT dispatches do not store or queue request bodies. The application guide explains that existing dispatch interface and the host binding required for another application. These declaration checks do not prove Cloudflare placement, hidden copies or runtime code adoption.
The dated composition assessment separates usable Worker/DO/storage paths, native-product limits and the remaining Cache API experiment. It does not promote an unqualified service.
Guarded Cache API supplies per-operation execution checks for native cache reads, writes and deletes. Its fixed operator probe is separate from stock and replenishment; consumer authentication, cache keys and downstream response caching remain application responsibilities.