cloudflare-one
Cloudflare One helps you architect and operate zero trust deployments spanning identity, traffic control, private networking, and data protection. It covers Access for app authorization, Gateway for traffic filtering, WARP for device connectivity, Tunnel for private network on-ramps, plus DLP, CASB, device posture, and identity federation. Use it to design topology, configure policies, troubleshoot connectivity, and review security posture across your infrastructure.
Cloudflare One guides zero trust architecture design, deployment, and troubleshooting across Access, Gateway, WARP, Tunnel, and related security services.
AI-generated summary based on this skill's SKILL.md
Decision gist · record as of 2026-07-24
Cloudflare One guides zero trust architecture design, deployment, and troubleshooting across Access, Gateway, WARP, Tunnel, and related security services. Cloudflare One helps you architect and operate zero trust deployments spanning identity, traffic control, private networking, and data protection. It covers Access for app authorization, Gateway for traffic filtering, WARP for device connectivity, Tunnel for private network on-ramps, plus DLP, CASB, device posture, and identity federation. Use it to design topology, configure policies, troubleshoot connectivity, and review security posture across your infrastructure.
Use it when
- Cloudflare Access lets you configure application authorization policies tied to identity providers via SAML, OIDC.
- Cloudflare Tunnel creates a secure outbound connection from your origin to Cloudflare's edge.
Verify before relying
Read SKILL.md below before installing (1 file). Open directory: indexed for reading, not audited.
Install
cloudflare/skills/cloudflare-one · repository language: Shell
Open directory. Skills are indexed for reading, not audited. Review a skill's body before installing it.
Frequently asked questions
AI-generated answers based on this skill's SKILL.md and metadata
What is Cloudflare One zero trust setup?
Cloudflare One is a zero trust platform that helps you design and deploy secure network architecture spanning identity, traffic control, private networking, and data protection. It integrates Access for app authorization, Gateway for DNS and HTTP filtering, WARP for device connectivity, and Tunnel for private network on-ramps. Use Cloudflare One to architect topology, configure policies, and enforce compliance controls across your infrastructure without relying on perimeter-based security.
How do I configure Cloudflare Access policies and identity federation?
Cloudflare Access lets you configure application authorization policies tied to identity providers via SAML, OIDC, or other federation methods. Define access rules using identity selectors, device posture checks, and contextual attributes. Cloudflare One supports multi-factor authentication, single sign-on integration, and role-based access control. Test policies in staging before deploying to production, and use audit logs to review access decisions and troubleshoot policy mismatches.
What's the difference between Cloudflare tunnel vs mesh for private network connectivity?
Cloudflare Tunnel creates a secure outbound connection from your origin to Cloudflare's edge, routing traffic through a single connector without opening inbound ports. Mesh extends that model to connect multiple private networks and devices directly, enabling site-to-site and device-to-network connectivity. Tunnel suits on-premises apps behind NAT; mesh scales to hybrid and multi-cloud topologies. Cloudflare One supports both; choose based on your topology complexity and connectivity needs.
How do I troubleshoot Cloudflare tunnel connector and device client issues?
Cloudflare One provides diagnostic tools for tunnel and WARP client troubleshooting. Check connector logs for authentication, DNS resolution, and upstream connectivity errors. Verify tunnel routes and load-balancing configuration. For WARP clients, review device posture compliance, split tunnel rules, and gateway policy matches. Use Cloudflare's analytics dashboard to monitor traffic flows, identify dropped packets, and correlate client errors with policy changes or network outages.
What DLP and CASB controls does Cloudflare One provide?
Cloudflare One implements Data Loss Prevention (DLP) to detect and block sensitive data in HTTP/HTTPS traffic, email, and file uploads. Cloud Access Security Broker (CASB) scans SaaS applications for misconfigurations, shadow IT, and compliance violations. Device posture checks enforce endpoint security requirements before granting access. Together, these controls help you meet compliance mandates, prevent data exfiltration, and maintain security posture across managed and unmanaged devices.
How do I set up Cloudflare Gateway DNS filtering and TLS inspection?
Cloudflare Gateway filters DNS queries at the edge and on-device via WARP, blocking malware, phishing, and policy-violating domains. Enable TLS inspection to decrypt HTTPS traffic for deeper content inspection and DLP scanning. Configure identity-aware policies using gateway identity selectors to apply rules per user, device, or location. Cloudflare One logs all filtered requests for audit and compliance reporting, helping you enforce acceptable-use policies and detect threats.
SKILL.md
Rendered from the published skill. Quoted content, verbatim.
Cloudflare One
Before citing limits, settings, API fields, category IDs, or exact UI paths, retrieve current information from the Cloudflare One docs, the Cloudflare docs MCP server, or the Cloudflare API schema.
Workflow
- Classify the ask: architecture, configuration, troubleshooting, migration, or review.
- Gather context: account ID, users/sites/apps, identity provider, SCIM/group sync, device management, traffic path, compliance constraints, and rollout blast radius.
- Retrieve only the current docs needed for the products involved: Access, Gateway, WARP/device client, Tunnel/Mesh, Cloudflare WAN, DLP, CASB, device posture, or identity.
- If account access is available, inspect existing resources before proposing or making changes: Access
(truncated - see the full file via the links below)
File tree — 1 file
skills/cloudflare-one/SKILL.md
Let your AI agent find skills like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 56,283 agent skills by what they can do, searchable in plain language.
wish › “Design and deploy zero trust network architecture with Cloudflare One”
Give your agent the search over MCP, or paste the wish link into any chat. No install? Search from any chat →
Related skills
Replace VPN access to internal services using Cloudflare's Zero Trust platform, which combines identity verification, device compliance checks, and encrypted tunnels to protect dashboards, admin panels, and on-premises apps. Enforce DNS-level threat filtering and support remote teams without opening inbound ports.
This skill guides you through migrating from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE environments to Cloudflare One. It covers migration assessments, policy mapping, dependency sequencing, and safe rollout staging with source-specific guidance for each platform.
Expose any local HTTP service to the internet using your own domain through Cloudflare Tunnel, with zero inbound firewall configuration or certificate hassle. The skill handles tunnel creation, DNS setup, and cloudflared installation automatically while you manage the Cloudflare account and API token. Supports multiple sites on a single tunnel for efficient resource use.
Navigate Cloudflare's full platform—from serverless compute and data storage to AI inference and edge security. This skill maps your use case to the right product via decision trees, then points you to authoritative references for APIs, limits, and configuration. Always retrieves current docs over cached knowledge.
This skill provides structured guidance for building across Cloudflare's full platform—from edge compute with Workers and Pages to data storage, AI inference, and security. Decision trees route you to the right product for your use case, while retrieval-first design ensures you get current API details, limits, and pricing from official docs rather than stale knowledge.
cloudflare-deploy is a comprehensive guide to building on Cloudflare's platform, covering compute (Workers, Pages, Durable Objects), storage (KV, D1, R2), AI services (Workers AI, Vectorize), and infrastructure-as-code tools. Decision trees help you find the right product for your use case, while retrieval-first guidance ensures you access current API docs, limits, and configuration options rather than relying on outdated knowledge.
More skills cloudflare-vpc-services (MIT) · homelab-network-readiness (MIT) · Cloudflare Tunnel Troubleshoot (unlicensed) · networking (MIT)