Cloudflare
29 items · source
Secrets Management & Cryptography
- Identify Cloudflare tokens.
Common Web Attack Classes
- Search Cloudflare logs.
DNS, CDN, Edge & WAF
- Verify Cloudflare is authoritative for intended zones.
- Verify the origin is not directly reachable from the public internet when it should be Cloudflare-only.
- Verify Cloudflare proxying is enabled for intended web/API hosts.
- Set Cloudflare SSL/TLS to Full (strict) where appropriate.
- Inventory all Cloudflare API tokens.
- Verify resource/zone restrictions.
- Verify Cloudflare Transform Rules do not modify security-sensitive values unexpectedly.
Monitoring, Detection & Incident Response
- Monitor Cloudflare DNS changes.
- Monitor Cloudflare token changes.
- Document how to rotate Cloudflare tokens.
Pre-Release Gates
- Any exposed Cloudflare/API/cloud credential with production privileges.
- Cloudflare API key
- Cloudflare API token
- Verify production Cloudflare configuration.
- Cloudflare DNS audit complete.
- Cloudflare WAF/rate-limit audit complete.
AI Security Architecture & Identity
- AI does not receive Cloudflare administrator credentials.
Tool Calling & Excessive Agency
- Cloudflare DNS changes
AI Data Access & Privacy
- AI cannot bypass Cloudflare/WAF intentionally.
AI Output Handling
- Never directly use model output as a Cloudflare rule.
AI Testing & Red-Team Pack
Test whether an attacker can cause an agent to reveal:
- Cloudflare tokens
AI-Generated Crypto, Dependency & Config Bugs
Review every AI-generated:
- Cloudflare rules
Review Blind Spots
- Verify outdated Cloudflare configuration is not copied.
- Compare Cloudflare behavior.
Agent Prompts & PR Review
- Identify DNS/Cloudflare changes.
Can an attacker reach the same operation another way?
- Cloudflare API.
Vibe-Coding Release Gate
- AI changed Cloudflare.
# Cloudflare ## Secrets Management & Cryptography * [ ] Identify Cloudflare tokens. ## Common Web Attack Classes * [ ] Search Cloudflare logs. ## DNS, CDN, Edge & WAF * [ ] Verify Cloudflare is authoritative for intended zones. * [ ] Verify the origin is not directly reachable from the public internet when it should be Cloudflare-only. * [ ] Verify Cloudflare proxying is enabled for intended web/API hosts. * [ ] Set Cloudflare SSL/TLS to Full (strict) where appropriate. * [ ] Inventory all Cloudflare API tokens. * [ ] Verify resource/zone restrictions. * [ ] Verify Cloudflare Transform Rules do not modify security-sensitive values unexpectedly. ## Monitoring, Detection & Incident Response * [ ] Monitor Cloudflare DNS changes. * [ ] Monitor Cloudflare token changes. * [ ] Document how to rotate Cloudflare tokens. ## Pre-Release Gates * [ ] Any exposed Cloudflare/API/cloud credential with production privileges. * [ ] Cloudflare API key * [ ] Cloudflare API token * [ ] Verify production Cloudflare configuration. * [ ] Cloudflare DNS audit complete. * [ ] Cloudflare WAF/rate-limit audit complete. ## AI Security Architecture & Identity * [ ] AI does not receive Cloudflare administrator credentials. ## Tool Calling & Excessive Agency * [ ] Cloudflare DNS changes ## AI Data Access & Privacy * [ ] AI cannot bypass Cloudflare/WAF intentionally. ## AI Output Handling * [ ] Never directly use model output as a Cloudflare rule. ## AI Testing & Red-Team Pack Test whether an attacker can cause an agent to reveal: * [ ] Cloudflare tokens ## AI-Generated Crypto, Dependency & Config Bugs Review every AI-generated: * [ ] Cloudflare rules ## Review Blind Spots * [ ] Verify outdated Cloudflare configuration is not copied. * [ ] Compare Cloudflare behavior. ## Agent Prompts & PR Review * [ ] Identify DNS/Cloudflare changes. Can an attacker reach the same operation another way? * [ ] Cloudflare API. ## Vibe-Coding Release Gate * [ ] AI changed Cloudflare. 29 items · https://github.com/FarzamHabibi/pre-production-checklist · CC BY 4.0