Claude Fable 5.1 & GPT-6 Astra packages are live

Cloudflare

Free

Cloudflare as CDN, WAF and edge platform — DNS and proxying, cache rules that actually cache, origin protection, Workers limits, and rate limiting.

205 lines8.8 KB Glm DevOps
targetModels
GLM-5.3GLM-5.2GLM-5 FamilyGLM-4.6Future GLM Models
name
cloudflare
category
DevOps
description
Cloudflare as CDN, WAF and edge platform — DNS and proxying, cache rules that actually cache, origin protection, Workers limits, and rate limiting.
license
MIT
author
Agent.md maintainers
last-verified
reviewed-by
unreviewed
<!-- Generated from models/_canonical by scripts/build-model-variants.js. Edit the canonical source, not this file. Behavioural profile for GLM: scripts/model-profiles.json -->

#Task boundary

  1. Implement only what the task names; no extra abstractions or files.
  2. English-only comments and identifiers.
  3. Stop when the checklist passes.

#Purpose

Rules for putting Cloudflare in front of an application, and for running code at its edge. Three jobs, in descending order of value:

  1. Caching — serve static assets from the edge and never touch the origin.
  2. Protection — absorb volumetric attacks and block abuse before it costs you.
  3. Compute — Workers for logic that belongs at the edge, not for everything.

#Proxying and origin protection

A proxied (orange-cloud) record hides the origin IP. A grey-cloud record publishes it, and an attacker who knows it bypasses every protection you configured.

  1. Proxy every public hostname. Audit for grey-cloud records — a legacy direct. or origin. record is the standard way the origin IP leaks.
  2. Lock the origin down so it only accepts Cloudflare traffic. Otherwise the WAF and rate limits are optional from an attacker's point of view:
  • Allow only Cloudflare IP ranges at the firewall, or
  • Use Cloudflare Tunnel (cloudflared) so the origin has no inbound ports at all — the stronger option, and it removes IP-range maintenance.
  1. Authenticated Origin Pulls (mTLS) so the origin can verify the request came from your Cloudflare account, not just from Cloudflare.
  2. SSL mode Full (strict). Flexible means Cloudflare talks plaintext HTTP to your origin while showing users a padlock — it is unencrypted transport with a misleading indicator.

#Caching: the defaults cache almost nothing

By default Cloudflare caches a list of static file extensions and nothing with a query string or a cookie. Most applications therefore see a low hit ratio and conclude the CDN is not helping.

sql
# Cache rule: hashed assets, cached hard, everywhere
When  URI Path matches ^/(assets|_next/static)/
Then  Cache eligibility: Eligible
      Edge TTL: 1 year   Browser TTL: 1 year

Set the origin headers to match:

arduino
Cache-Control: public, max-age=31536000, immutable      # content-hashed assets
Cache-Control: public, max-age=0, s-maxage=300, stale-while-revalidate=86400   # HTML
Cache-Control: private, no-store                        # authenticated responses

Rules that matter:

  1. s-maxage controls the CDN; max-age controls the browser. HTML usually wants a short shared TTL and no browser cache, so a deploy is visible immediately.
  2. Never cache an authenticated response. One user's page served to another is the highest-impact CDN bug there is, and it is entirely a Cache-Control mistake. → API/api-security
  3. Vary on any header that changes the response, but avoid Vary: Cookie — it fragments the cache per user and effectively disables it.
  4. Purge by tag or URL on deploy, never purge everything: a full purge sends every request to the origin at once.
  5. Tiered Cache reduces origin load; Cache Reserve helps for large, rarely-changing objects.

Measure the hit ratio. Below ~80% on static assets means the rules are wrong, not that caching does not apply.


#WAF, bots and rate limiting

  1. Enable the managed WAF rulesets, then watch the logs before enforcing. Shipping a ruleset straight to block will break a legitimate integration whose payload looks like an attack.
  2. Rate limit at the edge for volumetric abuse — a request blocked here costs you nothing. Keep application-level limits too, for per-account quotas the edge cannot see. → API/rate-limiting
  3. Bot Fight Mode and challenges interact badly with API clients and webhooks: exempt /api/* and known partner paths, or expect a support ticket.
  4. Never rely on a Cloudflare-added header for authorization decisions unless the origin is locked to Cloudflare — otherwise a direct request forges it. This applies to CF-Connecting-IP, CF-IPCountry and Access JWTs.
  5. Take the client IP from CF-Connecting-IP, not the leftmost X-Forwarded-For, which is client-controlled.
  6. Cloudflare Access for internal tools: identity-aware proxy in front of the origin, so there is no public admin panel at all.

#Workers: know the constraints

ConstraintValueConsequence
CPU time~10–30 ms typical, configurableNot for heavy computation
Memory128 MBNo large in-memory work
RuntimeV8 isolates, not NodeNode built-ins need nodejs_compat
SubrequestsBounded per requestFan-out is limited
KV consistencyEventually consistent, ~60sNot for read-after-write
  1. Workers suit routing, header rewriting, auth checks, A/B assignment, and personalisation at the edge. They do not suit image processing or anything CPU-heavy.
  2. Storage: KV for read-heavy, eventually-consistent data; Durable Objects for strongly-consistent coordination; D1 for relational; R2 for objects, with no egress fees.
  3. Secrets via wrangler secret put, never in wrangler.toml — which is committed.
  4. Version and roll back deployments (wrangler versions), and use gradual deployments for risky changes. → DevOps/rollback
toml
# wrangler.toml — bindings, not secrets. Secrets go in `wrangler secret put`.
name = "edge-router"
main = "src/index.ts"
compatibility_date = "2026-08-01"
compatibility_flags = ["nodejs_compat"]

[[kv_namespaces]]
binding = "CONFIG"
id = "…"

[[durable_objects.bindings]]
name = "RATE_LIMITER"
class_name = "RateLimiter"

[observability]
enabled = true
  1. No global mutable state across requests: isolates are recycled unpredictably, so a module-scope cache is neither reliable nor per-user-safe.

#Anti-patterns

Anti-patternWhy it failsFix
Grey-cloud DNS recordsOrigin IP published; protections bypassedProxy everything; audit records
Origin open to the internetThe WAF becomes optionalIP allowlist or Cloudflare Tunnel
SSL mode FlexiblePlaintext to origin behind a padlockFull (strict)
Assuming defaults cache HTMLLow hit ratio; origin carries the loadExplicit cache rules
Caching authenticated responsesOne user's data served to anotherprivate, no-store
Vary: CookieCache fragmented per userVary only on what matters
Purging everything on deployOrigin stampedePurge by tag or URL
WAF rules enforced without observationBreaks legitimate integrationsLog-only first
Bot protection on API pathsPartner integrations and webhooks failExempt them
Trusting CF-* headers with an open originForgeable by a direct requestLock the origin first
Leftmost X-Forwarded-For as client IPClient-controlled; limits bypassableCF-Connecting-IP
Heavy computation in a WorkerCPU limit exceededOrigin or a queue
KV used for read-after-writeEventually consistentDurable Objects
Secrets in wrangler.tomlCommitted to version controlwrangler secret
Module-scope state in a WorkerIsolates recycle; state is not yoursStateless handlers
No cache-hit-ratio monitoringThe CDN silently does nothingTrack and alert

#Checklist

  • Every public hostname is proxied; no grey-cloud records remain
  • The origin accepts traffic only from Cloudflare, or has no inbound ports
  • Authenticated Origin Pulls are enabled
  • SSL mode is Full (strict) end to end
  • Cache rules explicitly cover static assets and HTML
  • Origin Cache-Control distinguishes max-age from s-maxage
  • Authenticated responses are never cacheable
  • Vary is minimal and never varies on cookies
  • Deploys purge by tag or URL, not globally
  • Cache hit ratio is monitored and alerted on
  • WAF rulesets ran in log-only mode before enforcement
  • Edge rate limiting complements, not replaces, application limits
  • Bot protection exempts API and webhook paths
  • Client IP is read from CF-Connecting-IP
  • No authorization decision trusts a CF-* header on an unlocked origin
  • Internal tools sit behind Cloudflare Access
  • Worker CPU, memory and subrequest limits are understood and respected
  • Worker storage choice matches the consistency requirement
  • Worker secrets are set with wrangler secret, not committed
  • Worker deployments are versioned and rollable