Operations
Site Modes
STUDIO_SITE_MODE is a plaintext Worker Variable. It is not a site content setting, and Studio does not change it automatically. Missing or unknown values block normal access.
| Mode | Normal sign-in and product APIs | Purpose |
|---|---|---|
initial |
Blocked | Install an uninstalled Studio database |
operational |
Available when configuration and database state are ready | Authoring, settings, imports, publishing, and permitted online operations |
maintenance |
Blocked | Database upgrades, backups, restore, and planned destructive work |
recovery |
Blocked | Account or database recovery outside normal authentication |
Initial
Use initial with an uninstalled database, STUDIO_INSTALL_TOKEN, and STUDIO_AUTH_SECRET. After installing, remove the install-token binding, set the mode to operational, and apply the configuration. An empty install token is still configured and is not a valid post-installation state.
Operational
Use operational for normal use. It does not override database compatibility: an uninstalled, older, newer, malformed, or incomplete schema can still block access. Upgrade an older supported Studio schema through maintenance mode.
An administrator can rebuild a required search index from the Dashboard while continuing to edit. Operations can also expose permitted online actions, including Clear Content, compatible Edge DB upgrade and Edge backup, and Cloudflare Access configuration. Each keeps its own prerequisites.
Maintenance
Maintenance blocks normal Studio login and product requests, including those from existing sessions. Use it for Studio schema upgrades, Edge installation or adoption, target reconciliation, Reset, Uninstall, and appropriate SQL backup or restore workflows.
The entry screen links to Operations even when its IP and token settings need configuration. Follow that setup guide, then use the permitted database tools. See Operations access.
Pause public Edge requests separately with EDGE_MAINTENANCE_MODE=true before Edge database maintenance. Studio’s mode cannot stop the other Worker.
Recovery
Recovery supports administrator access recovery, available SQL backup/restore paths, and disabling a broken Studio-side Cloudflare Access requirement. Its IP and Operations-token boundary provides access when normal account credentials are unavailable.
Recovery does not expose Clear Content, Reset, or Uninstall. Complete required Studio upgrades in maintenance mode after recovering administrator access.
Typical Transitions
| Situation | Sequence |
|---|---|
| New installation | Initial → install → remove install token → operational |
| Studio schema upgrade | Operational → maintenance → backup and upgrade → operational |
| Lost administrator access | Recovery → recover credentials → operational |
| Lost access and outdated schema | Recovery → recover credentials → maintenance → backup and upgrade → operational |
Apply each mode change through the Worker configuration. The current database state and operation prerequisites determine which controls are available.