skillfed

cloudflare-one

Cloudflare One helps you architect and operate zero trust deployments spanning identity, traffic control, private networking, and data protection. It covers Access for app authorization, Gateway for traffic filtering, WARP for device connectivity, Tunnel for private network on-ramps, plus DLP, CASB, device posture, and identity federation. Use it to design topology, configure policies, troubleshoot connectivity, and review security posture across your infrastructure.

Cloudflare One guides zero trust architecture design, deployment, and troubleshooting across Access, Gateway, WARP, Tunnel, and related security services.

AI-generated summary based on this skill's SKILL.md

2,499 235 Apache-2.0 updated by cloudflare

Install

cloudflare/skills/cloudflare-one · repository language: Shell

git clone https://github.com/cloudflare/skills
cp -r skills/skills/cloudflare-one ~/.claude/skills/cloudflare-one
npx skillfed install cloudflare/skills/cloudflare-one

Frequently asked questions

AI-generated answers based on this skill's SKILL.md and metadata

What is Cloudflare One zero trust setup?

Cloudflare One is a zero trust platform that helps you design and deploy secure network architecture spanning identity, traffic control, private networking, and data protection. It integrates Access for app authorization, Gateway for DNS and HTTP filtering, WARP for device connectivity, and Tunnel for private network on-ramps. Use Cloudflare One to architect topology, configure policies, and enforce compliance controls across your infrastructure without relying on perimeter-based security.

How do I configure Cloudflare Access policies and identity federation?

Cloudflare Access lets you configure application authorization policies tied to identity providers via SAML, OIDC, or other federation methods. Define access rules using identity selectors, device posture checks, and contextual attributes. Cloudflare One supports multi-factor authentication, single sign-on integration, and role-based access control. Test policies in staging before deploying to production, and use audit logs to review access decisions and troubleshoot policy mismatches.

What's the difference between Cloudflare tunnel vs mesh for private network connectivity?

Cloudflare Tunnel creates a secure outbound connection from your origin to Cloudflare's edge, routing traffic through a single connector without opening inbound ports. Mesh extends that model to connect multiple private networks and devices directly, enabling site-to-site and device-to-network connectivity. Tunnel suits on-premises apps behind NAT; mesh scales to hybrid and multi-cloud topologies. Cloudflare One supports both; choose based on your topology complexity and connectivity needs.

How do I troubleshoot Cloudflare tunnel connector and device client issues?

Cloudflare One provides diagnostic tools for tunnel and WARP client troubleshooting. Check connector logs for authentication, DNS resolution, and upstream connectivity errors. Verify tunnel routes and load-balancing configuration. For WARP clients, review device posture compliance, split tunnel rules, and gateway policy matches. Use Cloudflare's analytics dashboard to monitor traffic flows, identify dropped packets, and correlate client errors with policy changes or network outages.

What DLP and CASB controls does Cloudflare One provide?

Cloudflare One implements Data Loss Prevention (DLP) to detect and block sensitive data in HTTP/HTTPS traffic, email, and file uploads. Cloud Access Security Broker (CASB) scans SaaS applications for misconfigurations, shadow IT, and compliance violations. Device posture checks enforce endpoint security requirements before granting access. Together, these controls help you meet compliance mandates, prevent data exfiltration, and maintain security posture across managed and unmanaged devices.

How do I set up Cloudflare Gateway DNS filtering and TLS inspection?

Cloudflare Gateway filters DNS queries at the edge and on-device via WARP, blocking malware, phishing, and policy-violating domains. Enable TLS inspection to decrypt HTTPS traffic for deeper content inspection and DLP scanning. Configure identity-aware policies using gateway identity selectors to apply rules per user, device, or location. Cloudflare One logs all filtered requests for audit and compliance reporting, helping you enforce acceptable-use policies and detect threats.

SKILL.md

rendered from the published skill — quoted content, verbatim

Cloudflare One

Before citing limits, settings, API fields, category IDs, or exact UI paths, retrieve current information from the Cloudflare One docs, the Cloudflare docs MCP server, or the Cloudflare API schema.

Workflow

  1. Classify the ask: architecture, configuration, troubleshooting, migration, or review.
  2. Gather context: account ID, users/sites/apps, identity provider, SCIM/group sync, device management, traffic path, compliance constraints, and rollout blast radius.
  3. Retrieve only the current docs needed for the products involved: Access, Gateway, WARP/device client, Tunnel/Mesh, Cloudflare WAN, DLP, CASB, device posture, or identity.
  4. If account access is available, inspect existing resources before proposing or making changes: Access

(truncated - see the full file via the links below)

Read as markdown · JSON record · Browse the source repository

File tree — 1 file
skills/cloudflare-one/SKILL.md

Related skills

Tags

zero-trust-network sase-platform identity-federation traffic-inspection private-connectivity device-management data-protection cloud-security network-access-control enterprise-vpn-replacement