Cloudflare has introduced Streamline, a new developer playground and open-source initiative designed to demonstrate how developers can build bespoke, real-time video processing pipelines on top of the company’s developer platform. While Cloudflare Stream is widely utilized as a powerful out-of-the-box broadcasting platform, certain advanced use cases—such as rendering dynamic annotations on an active livestream or generating alternate video versions with burned-in subtitles—require a specialized, customizable video pipeline. Streamline bridges this gap by showing how Cloudflare Workers, Containers, and various media protocols can be orchestrated to modify video streams and instantly publish the resulting output as a new livestream or hosted video asset.
The core engineering challenge of any video processing pipeline is the requirement for a durable, long-running runtime environment capable of executing specialized, compiled code with predictable memory and CPU capacity. Because video streams routinely run for minutes or even hours, the underlying media process must maintain a lifecycle independent of the initial HTTP request that triggered it. Applications need the ability to spin up a pipeline, feed data into it, monitor its progress, and shut it down without keeping a single request channel open for the entire duration.
Cloudflare’s infrastructure provides the necessary foundational primitives to solve this architectural challenge. Containers serve as the long-lived runtimes optimized for intensive media processing tasks, Durable Objects handle precise orchestration, and Workers manage control signaling and monitoring. By combining these elements, Streamline operates a real-time media engine within a Container, governed by a Worker that exposes control, preview, and testing endpoints to users or automated agents. Crucially, processing continues uninterrupted even if the controlling Worker disconnects, ensuring reliability during unstable network conditions. The architecture is intentionally modular, allowing the underlying media engine to be swapped out for dedicated encoding products as technology evolves.
Architecture
A Streamline deployment is structured around two primary components: the Media Engine, which is responsible for handling media input, output, and direct processing, and the controlling Application, which creates, configures, observes, and stops individual media sessions.
The Media Engine, hosted within a Container, manages all inbound and outbound media streams. It possesses the versatility to pull Real-Time Messaging Protocol Secure (RTMPS) playback over the network from a Stream Live input and publish RTMPS output back to another Stream Live input. Additionally, it can ingest Cloudflare Stream HTTP Live Streaming (HLS) manifests and their respective segments to utilize pre-hosted video assets as raw input. The engine can also accept video feeds from sources supplied directly by the controlling application, such as webcams, and stream preview footage over an outbound WebSocket to a Durable Object relay for client observation.
The controlling application is built using Cloudflare Workers and can manifest as a full-stack browser application, an automated agent, or an embedded system. During local development, the system runs with minimal friction: the container operates as a local Docker instance, Durable Objects are bypassed, authentication requirements are relaxed, and video previews connect directly to a localhost WebSocket. In remote production deployments on Cloudflare, an authorized user or agent interacts with the Worker to initiate a session. This action automatically spins up and manages the Streamline container lifecycle, exposes a comprehensive API for video manipulation operations, and routes media streams seamlessly to and from Cloudflare Stream.
Container Lifecycle and Session Management
Managing long-running video tasks requires specialized lifecycle logic, particularly because Cloudflare Containers are natively designed to sleep automatically after a defined interval of inactivity. For real-time media pipelines, however, processing must persist even when the controlling application disconnects. To achieve this, the architecture overrides the onActivityExpired() callback on the container. If a session’s predetermined expiry time has not yet been reached, the container actively renews its activity timeout; otherwise, it safely terminates and destroys the container instance. A strict maximum session duration is also enforced to guarantee that pipelines cannot run indefinitely without external oversight, and active containers remain isolated to a single application session at any given time.
The system’s low-level interface is governed by an HTTP server implemented via a Go harness alongside the Durable Object associated with the container. To abstract away unnecessary backend complexity, Streamline provides clean client libraries. For remote deployments, the controlling Worker imports the @streamline/cloudflare package to define application-specific logic and storage, while local development environments utilize a lightweight adapter that maintains the session-based API while communicating directly with a local Docker instance.
Through these client interfaces, developers can execute standard lifecycle operations, including creating new Streamline instances, initiating processing sessions, resuming connections to existing sessions, streaming chunks of raw video data, updating transparent overlay annotations, retrieving session performance metrics, and halting execution when processing is complete.

Defining and Running Video Processing Pipelines
When an application invokes the session start routine, it passes a JSON configuration object that dictates the exact parameters of the video processing pipeline. Streamline supports a variety of input sources, including RTMP broadcasts, HLS manifests from Cloudflare Stream, and direct ingest methods such as webcams or automated camera feeds.
For instance, a pipeline can ingest an incoming live broadcast feed, apply a transparent overlay image positioned in a specific corner of the frame, re-encode the video with targeted codec and bitrate specifications, and route the modified output to an RTMP destination for simultaneous recording or rebroadcasting. Similarly, video-on-demand assets hosted on Cloudflare Stream can be ingested via HLS, allowing the pipeline to extract embedded closed caption subtitles, burn them directly into the video frames as readable text, and export the enhanced video through RTMP.
To facilitate quick testing and real-time interactive use cases, Streamline allows applications to send video data directly from a web browser’s webcam or an embedded Internet of Things device. This capability is particularly valuable for scenarios like feeding factory floor camera footage into an artificial intelligence analysis pipeline or stitching multiple camera streams into a single composite view. By specifying a WebSocket output mode, the pipeline generates a low-latency preview feed encoded in fragmented MP4 format. Simultaneously, applications can utilize dynamic annotation endpoints to update transparent PNG overlay images in real time, enabling animated graphics, tickers, or interactive UI elements to be rendered directly onto the video stream on the fly.
Security Considerations
Security is deeply integrated into the architectural foundation of Streamline rather than treated as an afterthought. Protecting sensitive media streams requires strict isolation between sessions, robust authentication for session creation and control, and the safeguarding of Stream RTMPS input and output credentials so they are never exposed to the controlling application or client-side browser storage.
Owner deployments are kept private through the integration of Cloudflare Access. The Worker verifies user identities before accepting control requests, binding the active session to a verified principal and preventing unauthorized users from interrupting or overtaking an ongoing media session. Stream Live Input and Output keys are stored securely within Worker secrets or as write-only shared overrides inside Durable Object storage, ensuring they never leak through settings APIs.
Preview video streams utilize a dual-credential security model. A Cloudflare Access service token authenticates the container workload to the publisher endpoint, while a random per-session capability token authorizes publishing strictly for the currently active relay. The service token is injected dynamically by the container’s outbound Worker and never resides in the container’s memory, ensuring robust data protection throughout the pipeline’s operation.
Playground and Open Source Release
Alongside the architectural announcement, Cloudflare has released Streamline as an open-source project alongside a fully functional public developer playground. The Streamline container can be deployed locally or hosted directly within a developer’s Cloudflare account, exporting the Worker API required for custom control applications.
Cloudflare has also provided a reference Worker application featuring an Astro web frontend that illustrates common implementation patterns, including image overlays, subtitle decoding, video filters, and picture-in-picture displays. The reference application includes diagnostic probing tools that supply detailed performance metrics and system traces to assist with debugging. Both the container and frontend repositories are available as open source on Cloudflare’s GitHub organization.
By making Streamline publicly available, Cloudflare aims to showcase the immense flexibility of combining managed media services like Stream with foundational infrastructure primitives. While current iterations rely on Container CPU for media processing—which can introduce bottlenecks at extremely high frame rates or resolutions—future iterations are expected to expand into computer vision pipelines, hardware-accelerated media processing, ultra-low-latency real-time experiences utilizing next-generation protocols like WebRTC and Media over QUIC, and native video encoding and decoding primitives directly within Cloudflare Workers.
Leave a Reply