Edge Networking2 min read163 lines

Learning state

Track this guide

Saved in this browser only. No account required.

Cloudflare Infrastructure Master Class

Engineering-grade reference manual for Cloudflare infrastructure operations across DNS, tunnels, Zero Trust Access, WAF rules, cache controls, certificates, and observability.

Overview

Cloudflare often sits on the edge of production infrastructure. It can route traffic, protect applications, front private tunnels, enforce Access policy, cache assets, and terminate TLS. That makes every change high leverage: verify read-only state first, make reviewed changes, and confirm behavior from outside the origin.

This guide uses cloudflared, HTTP checks, and API examples. Prefer the Cloudflare dashboard or Terraform for reviewed changes when teams require approval workflows.

Tunnel and Connector Checks

Show the Cloudflared version:

cloudflared --version

List configured tunnels:

cloudflared tunnel list

Show tunnel details:

cloudflared tunnel info TUNNEL_NAME

Run a local tunnel for testing:

cloudflared tunnel --url http://127.0.0.1:8080

Validate ingress configuration:

cloudflared tunnel ingress validate --config ~/.cloudflared/config.yml

Route DNS to a tunnel after approval:

cloudflared tunnel route dns TUNNEL_NAME app.example.com

DNS Operations

List DNS records with the API:

curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
  "https://api.cloudflare.com/client/v4/zones/ZONE_ID/dns_records" | jq '.result[] | {name,type,content,proxied}'

Query public DNS:

dig app.example.com A

Query Cloudflare resolver:

dig @1.1.1.1 app.example.com A

Check whether traffic is proxied through Cloudflare:

curl -I https://app.example.com

Zero Trust Access

List Access applications with the API:

curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
  "https://api.cloudflare.com/client/v4/accounts/ACCOUNT_ID/access/apps" | jq '.result[] | {name,domain,type}'

List Access policies:

curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
  "https://api.cloudflare.com/client/v4/accounts/ACCOUNT_ID/access/policies" | jq '.result[] | {name,decision,include}'

Verify unauthenticated requests are intercepted:

curl -I --max-redirs 0 https://app.example.com

Check Access JWT headers from a protected origin only in a controlled test path:

curl -I https://app.example.com/protected-health

WAF, Rules, and Cache

List zone rulesets:

curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
  "https://api.cloudflare.com/client/v4/zones/ZONE_ID/rulesets" | jq '.result[] | {id,name,phase}'

Inspect firewall events:

curl -s -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
  "https://api.cloudflare.com/client/v4/zones/ZONE_ID/firewall/events?per_page=10" | jq '.result[] | {action,source,host,datetime}'

Check cache response headers:

curl -I https://www.example.com/static/app.js

Purge a single URL after approval:

curl -s -X POST -H "Authorization: Bearer CLOUDFLARE_API_TOKEN" \
  -H "Content-Type: application/json" \
  "https://api.cloudflare.com/client/v4/zones/ZONE_ID/purge_cache" \
  --data '{"files":["https://www.example.com/static/app.js"]}'

TLS and Origin Validation

Check public certificate chain:

openssl s_client -connect app.example.com:443 -servername app.example.com </dev/null

Check HTTPS response:

curl -I https://app.example.com

Check the origin directly only from an approved network path:

curl -I http://127.0.0.1:8080

Production Checklist

  • DNS record, proxied state, and target origin are documented.
  • Access app and allow policy are read back after changes.
  • Tunnel connector is running on the expected host.
  • WAF/cache rules are reviewed before production deployment.
  • TLS behavior is verified externally.
  • Rollback path is documented before changing DNS, tunnel routes, WAF rules, or Access policies.