Skip to content
Back to skills

Cloudflare

ASecurity

Protect and accelerate websites with Cloudflare. Use when a user asks to add CDN, DDoS protection, DNS management, SSL, WAF, or edge computing to a website or API.

  • 142 stars
  • 0 votes
  • 0 copies
  • 8 views
  • Added May 27, 2026
devopsjavascriptgojavabashterraformapidevopssecurity

Works with

  • terminal
  • cli
  • api

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned May 27, 2026

npx -y skills add TerminalSkills/skills --skill cloudflare --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cloudflare?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cloudflare
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/terminalskills-cloudflare/badge)](https://www.skillsdirectory.com/skills/terminalskills-cloudflare)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cloudflare
description: >-
  Protect and accelerate websites with Cloudflare. Use when a user asks to add
  CDN, DDoS protection, DNS management, SSL, WAF, or edge computing to a
  website or API.
license: Apache-2.0
compatibility: 'Any website or API'
metadata:
  author: terminal-skills
  version: 1.0.0
  category: devops
  tags:
    - cloudflare
    - cdn
    - dns
    - ddos
    - waf
    - ssl
---

# Cloudflare

## Overview

Cloudflare provides CDN, DDoS protection, DNS, SSL, WAF, and edge computing (Workers). Free tier includes unlimited bandwidth, DNS, basic DDoS protection, and SSL.

## Instructions

### Step 1: DNS Management

Point your domain nameservers to Cloudflare, then manage DNS via dashboard or API.

```bash
# Cloudflare API — manage DNS records
curl -X POST "https://api.cloudflare.com/client/v4/zones/ZONE_ID/dns_records" \
  -H "Authorization: Bearer CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  --data '{"type":"A","name":"app","content":"1.2.3.4","proxied":true}'
```

### Step 2: SSL/TLS

Always use **Full (Strict)** mode in production:
- Flexible: CF terminates SSL, HTTP to origin (insecure)
- Full: HTTPS to origin, self-signed OK
- Full (Strict): HTTPS to origin, valid cert required (recommended)

### Step 3: Terraform Management

```hcl
# cloudflare.tf — Infrastructure as code
resource "cloudflare_record" "app" {
  zone_id = var.cloudflare_zone_id
  name    = "app"
  content = "1.2.3.4"
  type    = "A"
  proxied = true
}
```

### Step 4: Workers (Edge Compute)

```javascript
// worker.js — Runs at the edge, <1ms cold start
export default {
  async fetch(request) {
    const url = new URL(request.url)
    if (url.pathname === '/api/health') {
      return new Response('OK', { status: 200 })
    }
    return fetch(request)    // pass through to origin
  }
}
```

## Guidelines

- Free tier: unlimited bandwidth, DDoS protection, DNS, shared SSL.
- Orange cloud (proxied) = traffic through Cloudflare. Grey cloud = DNS only.
- Workers: 100K requests/day free, <1ms cold starts.
- Always use Full (Strict) SSL — Flexible mode is a security risk.

Files in this skill

  • SKILL.md2.1 KB
  • _scores.json1.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…