$npx skillfedfor your agent

cloudflare-one

Cloudflare One helps you architect and operate zero trust deployments spanning identity, traffic control, private networking, and data protection. It covers Access for app authorization, Gateway for traffic filtering, WARP for device connectivity, Tunnel for private network on-ramps, plus DLP, CASB, device posture, and identity federation. Use it to design topology, configure policies, troubleshoot connectivity, and review security posture across your infrastructure.

Cloudflare One guides zero trust architecture design, deployment, and troubleshooting across Access, Gateway, WARP, Tunnel, and related security services.

AI-generated summary based on this skill's SKILL.md

★ 2,499  235 Apache-2.0updated by cloudflare

Decision gist · record as of 2026-07-24

Cloudflare One guides zero trust architecture design, deployment, and troubleshooting across Access, Gateway, WARP, Tunnel, and related security services. Cloudflare One helps you architect and operate zero trust deployments spanning identity, traffic control, private networking, and data protection. It covers Access for app authorization, Gateway for traffic filtering, WARP for device connectivity, Tunnel for private network on-ramps, plus DLP, CASB, device posture, and identity federation. Use it to design topology, configure policies, troubleshoot connectivity, and review security posture across your infrastructure.

manual: git clone https://github.com/cloudflare/skills → cp -r skills/skills/cloudflare-one ~/.claude/skills/cloudflare-one
skills/cloudflare-one/SKILL.md · version 39a3457b

Use it when

  • Cloudflare Access lets you configure application authorization policies tied to identity providers via SAML, OIDC.
  • Cloudflare Tunnel creates a secure outbound connection from your origin to Cloudflare's edge.

Verify before relying

Read SKILL.md below before installing (1 file). Open directory: indexed for reading, not audited.

Same gist for agents: .md · .json

Install

cloudflare/skills/cloudflare-one · repository language: Shell

Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.

Frequently asked questions

AI-generated answers based on this skill's SKILL.md and metadata

What is Cloudflare One zero trust setup?

Cloudflare One is a zero trust platform that helps you design and deploy secure network architecture spanning identity, traffic control, private networking, and data protection. It integrates Access for app authorization, Gateway for DNS and HTTP filtering, WARP for device connectivity, and Tunnel for private network on-ramps. Use Cloudflare One to architect topology, configure policies, and enforce compliance controls across your infrastructure without relying on perimeter-based security.

How do I configure Cloudflare Access policies and identity federation?

Cloudflare Access lets you configure application authorization policies tied to identity providers via SAML, OIDC, or other federation methods. Define access rules using identity selectors, device posture checks, and contextual attributes. Cloudflare One supports multi-factor authentication, single sign-on integration, and role-based access control. Test policies in staging before deploying to production, and use audit logs to review access decisions and troubleshoot policy mismatches.

What's the difference between Cloudflare tunnel vs mesh for private network connectivity?

Cloudflare Tunnel creates a secure outbound connection from your origin to Cloudflare's edge, routing traffic through a single connector without opening inbound ports. Mesh extends that model to connect multiple private networks and devices directly, enabling site-to-site and device-to-network connectivity. Tunnel suits on-premises apps behind NAT; mesh scales to hybrid and multi-cloud topologies. Cloudflare One supports both; choose based on your topology complexity and connectivity needs.

How do I troubleshoot Cloudflare tunnel connector and device client issues?

Cloudflare One provides diagnostic tools for tunnel and WARP client troubleshooting. Check connector logs for authentication, DNS resolution, and upstream connectivity errors. Verify tunnel routes and load-balancing configuration. For WARP clients, review device posture compliance, split tunnel rules, and gateway policy matches. Use Cloudflare's analytics dashboard to monitor traffic flows, identify dropped packets, and correlate client errors with policy changes or network outages.

What DLP and CASB controls does Cloudflare One provide?

Cloudflare One implements Data Loss Prevention (DLP) to detect and block sensitive data in HTTP/HTTPS traffic, email, and file uploads. Cloud Access Security Broker (CASB) scans SaaS applications for misconfigurations, shadow IT, and compliance violations. Device posture checks enforce endpoint security requirements before granting access. Together, these controls help you meet compliance mandates, prevent data exfiltration, and maintain security posture across managed and unmanaged devices.

How do I set up Cloudflare Gateway DNS filtering and TLS inspection?

Cloudflare Gateway filters DNS queries at the edge and on-device via WARP, blocking malware, phishing, and policy-violating domains. Enable TLS inspection to decrypt HTTPS traffic for deeper content inspection and DLP scanning. Configure identity-aware policies using gateway identity selectors to apply rules per user, device, or location. Cloudflare One logs all filtered requests for audit and compliance reporting, helping you enforce acceptable-use policies and detect threats.

SKILL.md

Rendered from the published skill. Quoted content, verbatim.

Cloudflare One

Before citing limits, settings, API fields, category IDs, or exact UI paths, retrieve current information from the Cloudflare One docs, the Cloudflare docs MCP server, or the Cloudflare API schema.

Workflow

  1. Classify the ask: architecture, configuration, troubleshooting, migration, or review.
  2. Gather context: account ID, users/sites/apps, identity provider, SCIM/group sync, device management, traffic path, compliance constraints, and rollout blast radius.
  3. Retrieve only the current docs needed for the products involved: Access, Gateway, WARP/device client, Tunnel/Mesh, Cloudflare WAN, DLP, CASB, device posture, or identity.
  4. If account access is available, inspect existing resources before proposing or making changes: Access

(truncated - see the full file via the links below)

File tree — 1 file
skills/cloudflare-one/SKILL.md

Let your AI agent find skills like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.

wish › “Design and deploy zero trust network architecture with Cloudflare One”

Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →

Related skills

cloudflare-zero-trust
by BagelHole · BagelHole/DevOps-Security-Agent-Skills

Replace VPN access to internal services using Cloudflare's Zero Trust platform, which combines identity verification, device compliance checks, and encrypted tunnels to protect dashboards, admin panels, and on-premises apps. Enforce DNS-level threat filtering and support remote teams without opening inbound ports.

MITupdated May 2026
★ 44repo stars
cloudflare-one-migrations
by cloudflare · cloudflare/skills

This skill guides you through migrating from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE environments to Cloudflare One. It covers migration assessments, policy mapping, dependency sequencing, and safe rollout staging with source-specific guidance for each platform.

Apache-2.0updated Jul 2026
★ 2,499repo stars
Cloudflare Tunnel Publish
by Starchild-ai-agent · Starchild-ai-agent/official-skills

Expose any local HTTP service to the internet using your own domain through Cloudflare Tunnel, with zero inbound firewall configuration or certificate hassle. The skill handles tunnel creation, DNS setup, and cloudflared installation automatically while you manage the Cloudflare account and API token. Supports multiple sites on a single tunnel for efficient resource use.

no license declared → metadata onlyupdated Jul 2026
★ 18repo stars
Cloudflare
by pedronauck · pedronauck/skills

Navigate Cloudflare's full platform—from serverless compute and data storage to AI inference and edge security. This skill maps your use case to the right product via decision trees, then points you to authoritative references for APIs, limits, and configuration. Always retrieves current docs over cached knowledge.

no license declared → metadata onlyupdated Jul 2026
★ 541repo stars
cloudflare
by cloudflare · cloudflare/skills

This skill provides structured guidance for building across Cloudflare's full platform—from edge compute with Workers and Pages to data storage, AI inference, and security. Decision trees route you to the right product for your use case, while retrieval-first design ensures you get current API details, limits, and pricing from official docs rather than stale knowledge.

Apache-2.0updated Jul 2026
★ 2,499repo stars
cloudflare-deploy
by fcakyon · fcakyon/claude-codex-settings

cloudflare-deploy is a comprehensive guide to building on Cloudflare's platform, covering compute (Workers, Pages, Durable Objects), storage (KV, D1, R2), AI services (Workers AI, Vectorize), and infrastructure-as-code tools. Decision trees help you find the right product for your use case, while retrieval-first guidance ensures you access current API docs, limits, and configuration options rather than relying on outdated knowledge.

Apache-2.0updated Jul 2026
★ 820repo stars

More skills cloudflare-vpc-services (MIT) · homelab-network-readiness (MIT) · Cloudflare Tunnel Troubleshoot (unlicensed) · networking (MIT)

Tags
zero-trust-networksase-platformidentity-federationtraffic-inspectionprivate-connectivitydevice-managementdata-protectioncloud-securitynetwork-access-controlenterprise-vpn-replacement