Self-host a bookmark manager on Cloudflare
CloudMark is a bookmark manager that runs as one Cloudflare Worker with a D1 database, so there is no VPS or Docker host to maintain. It covers saving, categorizing and searching links; it does not claim tags, full-text page search, permanent copies or team roles. Free-tier fit is conditional on a small collection.
By Cloudsteading · Sources checked 2026-10-06 · Independent guide
Why most self-hosted bookmark lists assume a server
Roundups of self-hosted bookmark managers, such as linkding, Linkwarden and Shiori, mostly start from a Docker host or a VPS you keep patched and backed up. That is a fair choice if you already run one. If you do not, the server is the main cost of self-hosting a bookmark manager, not the software.
CloudMark is built the other way round. Its pinned configuration declares a single Cloudflare Worker and one D1 database. This guide goes through what that configuration contains, what you would need to change before running your own copy, and where it stops short of a SaaS like Raindrop.io.
What CloudMark's pinned config declares
Our snapshot is pinned to commit 7a3ee47. In wrangler.jsonc at that commit:
- One Worker (
./src/worker/index.ts, built with Hono) serves the API. - A
DBbinding to D1, which holds collections, bookmark rows, token hashes and rate-limit rows. - An
ASSETSbinding for the bundled React frontend, with single-page-app fallback. Requests to/api/*run the Worker first; everything else is served as static assets. - No R2, KV, cron triggers or external services in the core deployment.
The architecture diagram on the project page is derived from this file. It shows declared infrastructure, not a deployment we ran.
What to change before you deploy your own copy
The repository ships with the author's identifiers. Replace them with your own:
- Create your own D1 database and put its ID in the
DBbinding. - Replace the author's custom-domain routes and
BASE_URL. Aworkers.devaddress avoids buying a domain. - Apply every D1 migration to your database before the first deploy.
- Back up the data and your write tokens, since there is no account recovery.
The optional Chrome extension is a separate, unpacked install and was not audited. Favicons load through Google by default, so treat them as an external request.
What it replaces from Raindrop.io, and what it does not
In our catalog, CloudMark is mapped to Raindrop.io for a narrow job: saving URLs with titles and notes, organizing them by category, and filtering and searching a personal collection. The Raindrop.io alternatives page has the wider comparison, so it is not repeated here.
We did not establish these features in CloudMark, so do not plan around them. We have not reviewed Raindrop.io's documentation for them, so compare against its own docs:
- tags
- full-text search of saved pages
- permanent copies of pages
- automated broken-link checks
- team permissions and private read-only invitations
The demo screenshot on the project page comes from the author's seeded demo. We searched it read-only. We did not save bookmarks, install the extension or test a fresh deployment.
Access and privacy: read this before saving anything private
Collections default to public: anyone who knows the URL can read them. The source supports private collections that require the same token that allows writes, but there are no user accounts and no separate read-only invitations.
Write tokens are kept in browser localStorage and in the bookmarklet. The bookmarklet sends the token in a query string, so it can end up in browser history and access logs. Some legacy collections can issue a write token on the first read until their migration is finished, so review that path before exposing an old collection URL.
Cloudflare free-tier limits that matter here
Free hosting is conditional, not guaranteed. The relevant published limits at the time of review:
| Resource | Free allowance | Why it matters for CloudMark |
|---|---|---|
| Worker requests | 100,000 per day, account-wide | Every API call counts; static assets are free and unlimited |
| Worker CPU | 10 ms per invocation | Token hashing and bulk imports need measuring |
| D1 rows read | 5 million per day | A collection read loads all its bookmarks, so filtering in the browser does not cut the database scan |
| D1 rows written | 100,000 per day | Imports, rate-limit rows and index updates all write |
| D1 storage | 5 GB total, account-wide | Not the constraint for a small collection |
The source limits a collection to 1,000 bookmarks and an import request to 500 items. If those caps suit you, a personal collection fits inside the free plan on paper. We have not measured it, and the limits behave differently. Daily read and write quotas reset each day. Storage does not reset, so you would need to delete data or upgrade. Your domain, backups and maintenance time are separate costs.
Checklist before you rely on it
- Deploy to
workers.devwith your own D1 database and migrations. - Create a collection and decide public or private on purpose.
- Import a small export, then confirm the count and categories.
- Check search against links you know are saved.
- Open the collection URL in a private window to see what a stranger can read.
- Read the AGPL v3 license guide if you change the code and share the result.
Common questions
Does a self-hosted bookmark manager need a server?
Not for CloudMark. The reviewed configuration is one Worker serving a bundled React frontend and an API, plus one D1 database binding. There is no container, VPS or external database in that configuration.
Is CloudMark free to run on Cloudflare?
It is eligible for Workers Free and D1 Free if the collection stays small, but this is a reading of the source and Cloudflare's published limits, not a measured deployment. Passing a daily read or write quota makes those queries fail until the daily reset or a paid plan. Storage is different: it does not reset daily, so you would need to delete data or upgrade.
Are my bookmarks private by default?
No. Collections default to public, meaning anyone with the collection URL can read them. The source also supports private collections that need the same token that allows writes. Test the access behavior you configure before saving anything sensitive.
Does CloudMark replace Raindrop.io?
For saving URLs with titles and notes, sorting them into categories and searching a personal collection, it is a reasonable fit. We did not establish tags, full-text page search, permanent copies, broken-link checks or team permissions in CloudMark, so check what you need against Raindrop.io's own documentation before assuming parity.
What license is CloudMark under?
AGPL-3.0. If you modify it and let others use it over a network, you must offer them the corresponding source of your version. Read the license page before running a modified copy for other people.
Sources and review
- CloudMark pinned README ↗
- CloudMark wrangler.jsonc at the reviewed commit ↗
- CloudMark bookmark limits (constants.ts) ↗
- Cloudflare Workers pricing and limits ↗
- Cloudflare D1 pricing ↗
- Cloudflare Workers static assets billing ↗
Recommendations are Cloudsteading’s editorial assessment. Repository review establishes documented capabilities; it does not prove a fresh deployment or complete feature parity. Prices and platform limits can change.