Cloudflare

To make DDNS, Dockflare and Cloudflared work we need some data from Cloudflare

Before continuing, please follow

triangle-exclamation

Generate your API key

This API key will be used for Dockflare, Dynamic DNS and Crowdsec

  1. Click Create Token > Custom Token

  2. Name your token Pelican, and set the below

    1. permissions

      Account

      Cloudflare Tunnel

      Edit

      Account

      Account Filter Lists

      Edit

      Account

      Firewall Access Rules

      Edit

      Account

      Account Settings

      Read

      Account

      Access: Apps and Policies

      Edit

      User

      User Details

      Read

      Zone

      DNS

      Read

      Zone

      Firewall Services

      Edit

      Zone

      Zone

      Edit

    2. Account Resources

      Field
      Data

      Include

      All Account

    3. Zone Resources You can have additional domains

      Include

      Specific Zone

      Your Domain

    4. Click on Continue to Summary

  3. Save your API key to your notepad, CF_APITOKEN=

Get your Account ID

  1. Next to your name, click on the 3 dots and select Copy Account ID

  2. Save to your notepad, CF_ACCOUNTID=

Get your Zone ID

  1. Click manage next to your domain

  2. Scroll down and locate "API" on the right

  3. Save your Zone ID to your notepad, CF_ZONE_ID=

Security rules

Configure some security rules to reduce the risk of malicious actors accessing your domain

  1. Select your domain

  2. On the left, click expand Security and select rules

  3. Click on create rule > custom rule

    1. Next to Expression Preview, click on 'edit expression' to get the free text field

  4. Create a rule for each of the below

Block bots

This policy will show a Captcha challenge to any IPs suspected of botting

Field
Data

Rule Name

Block Bots

Expression

(cf.client.bot)

Choose action

Managed Challenge

Place at

First

Challenge Threat Score

These IPs are potentially malicious. These addresses will be prompted for Captcha

Field
Data

Rule Name

Challenge Threat Score

Expression

(cf.threat_score gt 10)

Choose action

Managed Challenge

Place at

Custom - after 'Block Bots'

Block Threat Score

These IPs are very likely to be malicious. These addresses will be blocked

Field
Data

Rule Name

Challenge Threat Score

Expression

(cf.threat_score gt 50)

Choose action

Block

Place at

Custom - after 'Challenge Threat Score'

circle-info

An additional rule will be created by the Crowdsec CF Bouncer container after the Compose file is ran

Last updated