Cloudflare Zero Trust
Secure access to internal services without exposing public VPN endpoints.
Core Workflow
- Register application in Cloudflare Access.
- Integrate identity provider (Google Workspace, Okta, Entra ID).
- Define access policies by group, email domain, and device posture.
- Add logging and alerts for blocked requests.
Tunnel Setup
cloudflared tunnel login
cloudflared tunnel create internal-app
cloudflared tunnel route dns internal-app app.example.com
cloudflared tunnel run internal-app
Best Practices
- Enforce MFA and managed-device posture checks.
- Use service tokens for CI/CD automation.
- Review app policies quarterly.
Related Skills
- zero-trust - Zero trust architecture fundamentals
- dns-management - DNS routing concepts