Skip to content

Add Cloudflare traffic hardening controls - #22

Merged
dills122 merged 3 commits into
mainfrom
codex/cloudflare-security-controls
Jun 10, 2026
Merged

dills122 merged 3 commits into
mainfrom
codex/cloudflare-security-controls

Conversation

@dills122

Copy link
Copy Markdown
Owner

Summary

  • Adds OpenTofu-managed Cloudflare traffic hardening for Forage hosted environments.
  • Protects staging web access while keeping API OAuth flows reachable.
  • Documents the Cloudflare UI, token, and plan-tier constraints discovered during deployment.

What Changed

  • Added WAF geo managed-challenge rules for staging and production web/API hostnames.
  • Added a Cloudflare Access application and allowlist policy for staging web.
  • Added a combined /auth/* and /api/* rate-limit ruleset compatible with the current Cloudflare plan.
  • Preserved existing Pages compatibility date/flags in OpenTofu to avoid unrelated Pages drift.
  • Added security outputs and example tfvars.
  • Updated hosting/security and IaC docs for setup, token permissions, and rate-limit limitations.

Validation

  • npm run check
  • npm run check:docs
  • npm run infra:fmt:check
  • npm run check:workspace
  • tofu validate
  • tofu apply
  • tofu plan
  • Manual staging test confirmed Cloudflare Access, GitHub OAuth, and import flow work.

Scope Notes

  • Cloudflare only allows one http_ratelimit rule on the current plan.
  • Rate limiting is deployed as 20 requests / 10 seconds with a 10 second block.
  • WAF geo controls still use managed challenge.
  • Final OpenTofu plan reported No changes.

@dills122
dills122 merged commit 64dc1e7 into main Jun 10, 2026
1 check passed
@dills122
dills122 deleted the codex/cloudflare-security-controls branch June 10, 2026 03:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant