12-Step Cloudflare Security Checklist You Can Run From the Terminal
A developer at guushu.com has published a 12-point Cloudflare zone security checklist after discovering an unexpected WAF rule blocking curl requests on one of their zones. Each check uses a single read-only API token and a curl command, replacing guesswork with verifiable terminal output. The checklist covers critical settings including minimum TLS version, HSTS, WAF managed rules, DNSSEC, email authentication records, and scoped API tokens. It also flags common oversights such as orphaned DNS records, unprotected admin paths, and non-expiring API keys. The author notes that manual checks take roughly ten minutes per zone, making automation worthwhile for anyone managing multiple zones.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in