All skills
openai avatar

/cloudflare-deploy

@bf9e226 official
by openaiopenai/skills28k stars
1,891

Deploy applications and infrastructure to Cloudflare using Workers, Pages, and related platform services. Use when the user asks to deploy, host, publish, or set up a project on Cloudflare.

Use this Skill: https://skilld.dev/gh/openai/skills/cloudflare-deploy

This session only. Nothing lands on disk.

referencesddosgotchas.md

≈978 tokens on demand. Your agent reads this file only when SKILL.md points to it.

DDoS Gotchas

Common Errors

"False positives blocking legitimate traffic"

Cause: Sensitivity too high, wrong action, or missing exceptions
Solution:

  1. Lower sensitivity for specific rule/category
  2. Use log action first to validate (Enterprise Advanced)
  3. Add exception with custom expression (e.g., allowlist IPs)
  4. Query flagged requests via GraphQL Analytics API to identify patterns

"Attacks getting through"

Cause: Sensitivity too low or wrong action
Solution: Increase to default sensitivity and use block action:

const config = {
  rules: [{
    expression: "true",
    action: "execute",
    action_parameters: { id: managedRulesetId, overrides: { sensitivity_level: "default", action: "block" } },
  }],
};

"Adaptive rules not working"

Cause: Insufficient traffic history (needs 7 days)
Solution: Wait for baseline to establish, check dashboard for adaptive rule status

"Zone override ignored"

Cause: Account overrides conflict with zone overrides
Solution: Configure at zone level OR remove zone overrides to use account-level

"Log action not available"

Cause: Not on Enterprise Advanced DDoS plan
Solution: Use managed_challenge with low sensitivity for testing

"Rule limit exceeded"

Cause: Too many override rules (Free/Pro/Business: 1, Enterprise Advanced: 10)
Solution: Combine conditions in single expression using and/or

"Cannot override rule"

Cause: Rule is read-only
Solution: Check API response for read-only indicator, use different rule

"Cannot disable DDoS protection"

Cause: DDoS managed rulesets cannot be fully disabled (always-on protection)
Solution: Set sensitivity_level: "eoff" for minimal mitigation

"Expression not allowed"

Cause: Custom expressions require Enterprise Advanced plan
Solution: Use expression: "true" for all traffic, or upgrade plan

"Managed ruleset not found"

Cause: Zone/account doesn't have DDoS managed ruleset, or incorrect phase
Solution: Verify ruleset exists via client.rulesets.list(), check phase name (ddos_l7 or ddos_l4)

API Error Codes

Error Code Message Cause Solution
10000 Authentication error Invalid/missing API token Check token has DDoS permissions
81000 Ruleset validation failed Invalid rule structure Verify action_parameters.id is managed ruleset ID
81020 Expression not allowed Custom expressions on wrong plan Use "true" or upgrade to Enterprise Advanced
81021 Rule limit exceeded Too many override rules Reduce rules or upgrade (Enterprise Advanced: 10)
81022 Invalid sensitivity level Wrong sensitivity value Use: default, medium, low, eoff
81023 Invalid action Wrong action for plan Enterprise Advanced only: log action

Limits

Resource/Limit Free/Pro/Business Enterprise Enterprise Advanced
Override rules per zone 1 1 10
Custom expressions ✗ ✗ ✓
Log action ✗ ✗ ✓
Adaptive DDoS ✗ ✓ ✓
Traffic history required - 7 days 7 days

Tuning Strategy

  1. Start with log action + medium sensitivity
  2. Monitor for 24-48 hours
  3. Identify false positives, add exceptions
  4. Gradually increase to default sensitivity
  5. Change action from log → managed_challenge → block
  6. Document all adjustments

Best Practices

  • Test during low-traffic periods
  • Use zone-level for per-site tuning
  • Reference IP lists for easier management
  • Set appropriate alert thresholds (avoid noise)
  • Combine with WAF for layered defense
  • Avoid over-tuning (keep config simple)

See patterns.md for progressive rollout examples.

Source: SKILL.md on GitHub

2 warnings17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill provides comprehensive guidance for deploying and managing infrastructure on the Cloudflare platform. It includes extensive educational material on secure development practices, such as preventing SQL injection and managing secrets effectively. No malicious patterns or security risks were identified.

  • Socket17d

    2 alerts: gptAnomaly

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    310/310 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at bf9e226. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Activeupdated 8 months ago

README badge

README badge for openai/skills/cloudflare-deploy

Deploys applications and infrastructure to Cloudflare's platform, including Workers, Pages, D1, R2, Durable Objects, KV, and other services. Use decision trees to route to the right Cloudflare product based on compute, storage, AI, networking, security, or media needs.

Generated from the current SKILL.md.

Does this skill cover all Cloudflare products?
The skill is a consolidated index covering compute, storage, AI, networking, security, media, and developer tools on Cloudflare. It uses decision trees to route you to the right product reference, then loads detailed guidance for that product.
What authentication is required before deploying?
Run `npx wrangler whoami` to check if authenticated. For local deployment, use `wrangler login` (one-time OAuth). For CI/CD, set the `CLOUDFLARE_API_TOKEN` environment variable.
What should I do if deployment fails due to network issues?
Rerun the deploy with `sandbox_permissions=require_escalated` to grant elevated network access, which is required for outbound requests to Cloudflare during deployment.
How long does a Cloudflare deployment typically take?
Deployments may take several minutes. Use appropriate timeout values in your configuration or CI/CD environment.

Generated from the current SKILL.md. These answers refresh after source changes.