Learning state
Track this guide
Saved in this browser only. No account required.
Cloudflare Infrastructure Master Class
Engineering-grade reference manual for Cloudflare infrastructure operations across DNS, tunnels, Zero Trust Access, WAF rules, cache controls, certificates, and observability.
Overview
Cloudflare often sits on the edge of production infrastructure. It can route traffic, protect applications, front private tunnels, enforce Access policy, cache assets, and terminate TLS. That makes every change high leverage: verify read-only state first, make reviewed changes, and confirm behavior from outside the origin.
This guide uses cloudflared, HTTP checks, and API examples. Prefer the Cloudflare dashboard or Terraform for reviewed changes when teams require approval workflows.
Tunnel and Connector Checks
Show the Cloudflared version:
cloudflared --version
List configured tunnels:
cloudflared tunnel list
Show tunnel details:
cloudflared tunnel info TUNNEL_NAME
Run a local tunnel for testing:
cloudflared tunnel --url http://127.0.0.1:8080
Validate ingress configuration:
cloudflared tunnel ingress validate --config ~/.cloudflared/config.yml
Route DNS to a tunnel after approval:
cloudflared tunnel route dns TUNNEL_NAME app.example.com
DNS Operations
List DNS records with the API:
curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
"https://api.cloudflare.com/client/v4/zones/ZONE_ID/dns_records" | jq '.result[] | {name,type,content,proxied}'
Query public DNS:
dig app.example.com A
Query Cloudflare resolver:
dig @1.1.1.1 app.example.com A
Check whether traffic is proxied through Cloudflare:
curl -I https://app.example.com
Zero Trust Access
List Access applications with the API:
curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
"https://api.cloudflare.com/client/v4/accounts/ACCOUNT_ID/access/apps" | jq '.result[] | {name,domain,type}'
List Access policies:
curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
"https://api.cloudflare.com/client/v4/accounts/ACCOUNT_ID/access/policies" | jq '.result[] | {name,decision,include}'
Verify unauthenticated requests are intercepted:
curl -I --max-redirs 0 https://app.example.com
Check Access JWT headers from a protected origin only in a controlled test path:
curl -I https://app.example.com/protected-health
WAF, Rules, and Cache
List zone rulesets:
curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
"https://api.cloudflare.com/client/v4/zones/ZONE_ID/rulesets" | jq '.result[] | {id,name,phase}'
Inspect firewall events:
curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
"https://api.cloudflare.com/client/v4/zones/ZONE_ID/firewall/events?per_page=10" | jq '.result[] | {action,source,host,datetime}'
Check cache response headers:
curl -I https://www.example.com/static/app.js
Purge a single URL after approval:
curl -s -X POST -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
-H "Content-Type: application/json" \
"https://api.cloudflare.com/client/v4/zones/ZONE_ID/purge_cache" \
--data '{"files":["https://www.example.com/static/app.js"]}'
TLS and Origin Validation
Check public certificate chain:
openssl s_client -connect app.example.com:443 -servername app.example.com </dev/null
Check HTTPS response:
curl -I https://app.example.com
Check the origin directly only from an approved network path:
curl -I http://127.0.0.1:8080
Production Checklist
- DNS record, proxied state, and target origin are documented.
- Access app and allow policy are read back after changes.
- Tunnel connector is running on the expected host.
- WAF/cache rules are reviewed before production deployment.
- TLS behavior is verified externally.
- Rollback path is documented before changing DNS, tunnel routes, WAF rules, or Access policies.