CloudflareStatic-verified

Cloudflare Zero Trust Access

Access application with policies, identity provider wiring, and a cloudflared tunnel to private origins.

terraformEdge & DNScloudflare

Compare Zero Trust Application Access across clouds →

cloudflare-zero-trust-accessvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • No applicable security policies for this provider
  • Plan tests (mocked: validation rules · outputs)

Provenance

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-06-28 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o cloudflare-zero-trust-access-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/cloudflare-zero-trust-access/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle cloudflare-zero-trust-access-1.0.0.sigstore.json \
  cloudflare-zero-trust-access-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "2fcf82ccd14b978bff65c389c6fadee0370e5cae8191553b117c930a68071a9b  cloudflare-zero-trust-access-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "zero_trust_access" {
  source  = "www.iac-bazaar.com/iac-bazaar/cloudflare-zero-trust-access/cloudflare"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads static-verified because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: static-verified](https://www.iac-bazaar.com/api/artifacts/cloudflare-zero-trust-access/badge)](https://www.iac-bazaar.com/catalog/cloudflare-zero-trust-access?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, static-verified on IaC Bazaar: [Cloudflare Zero Trust Access](https://www.iac-bazaar.com/catalog/cloudflare-zero-trust-access?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "zero_trust_access" {
  source  = "www.iac-bazaar.com/iac-bazaar/cloudflare-zero-trust-access/cloudflare"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: static-verified

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

cloudflare-zero-trust-access

Status: static-validated, live-test pending. Ships under live-test quarantine — Zero Trust Access provisioning needs a Cloudflare account token, at least one configured identity provider, and (to verify the tunnel) a running cloudflared connector, none of which exist in a CI sandbox yet. The full apply → verify → destroy gate runs once a Cloudflare sandbox account is wired up. Schema is validated against the auto-generated provider v5 docs.

An account-level Cloudflare Zero Trust Access application with reusable Access policies and an optional cloudflared tunnel to private origins. Built directly against the v5 schema (cloudflare_zero_trust_access_application, cloudflare_zero_trust_access_policy, cloudflare_zero_trust_tunnel_cloudflared), not the v4 cloudflare_access_* resource names that break on upgrade. Works with Terraform and OpenTofu (>= 1.6), Cloudflare provider >= 5.0, < 6.0.

Design & secure defaults

  • Identity-first, deny-by-default. Policies are reusable account-level objects attached to the application by ID, with precedence derived from sorted policy keys. The default policy admits a single email domain (not everyone) — a request that matches no allow policy is denied by Access.
  • Account-scoped throughout. Access is an account product, so the application, its policies, and the tunnel are all account_id-scoped, which lets the application reference reusable policies cleanly.
  • Short sessions. session_duration defaults to 1h to limit token lifetime; set 0s to force re-auth on every request.
  • Private origins, not public ones. The optional cloudflared tunnel (create_tunnel = true) is remotely managed (config_src = "cloudflare") so origins are reached over the tunnel instead of being exposed publicly. Cloudflare generates the tunnel secret when you do not supply one; the connector run token is returned as a sensitive output.
  • No permissive CORS by default. CORS is unmanaged unless you set the cors object; prefer explicit allow-lists over allow_all_*.
  • App not advertised. app_launcher_visible defaults to false so the app is not surfaced to every enrolled user.
  • No hardcoded secrets. tunnel_secret is optional and sensitive; pass it via TF_VAR_tunnel_secret or a secrets manager, or omit it.

License

Commercial — LicenseRef-IaCBazaar-Commercial

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs
  • Requirements & notes

Related modules

Static validatedLive test pending

cloudflare-turnstile

The widget secret is the whole check: whoever holds it mints passing verifications for your forms; domains is an allow list of hostnames, so a widget made for production does not render on staging until staging is listed; and the mode decides whether visitors see a checkbox, a spinner or nothing. Hostnames required, the mode validated, and the secret exposed only as a sensitive output.

View module
Static validatedLive test pending

cloudflare-waf

A paid plan makes the Cloudflare Managed Ruleset and the OWASP Core Ruleset available; a zone runs them only when a rule in the managed phase executes them, so a subscribed zone with no such rule is protected by the free ruleset alone. Both executed here with the OWASP threshold set, custom rules that block rather than log, and a per-client rate limit in its own phase.

View module
Static validatedLive test pending

cloudflare-bot-management

Bot Fight Mode is zone-wide with no path exclusion and no allow list: it challenges CI runners, monitoring, mobile apps and every API client that worked yesterday. Off unless accepted by name, Super Bot Fight Mode with an action per class on paid plans (challenge the definitely automated, admit the rest), AI crawlers blocked, and an output that says whether API clients will be challenged.

View module
Static validatedLive test pending

cloudflare-zone-hardening

ssl = flexible encrypts the visitor's half and speaks plain HTTP to the origin while showing a padlock; DNSSEC is off until turned on at Cloudflare and again at the registrar; and TLS 1.0, HTTP without redirect and no HSTS are the defaults. Strict SSL with weaker modes accepted by name, TLS 1.2 minimum, HTTPS forced, HSTS (preload by name), DNSSEC on with the DS record exposed.

View module
Static validatedLive test pending

gcp-iap-web

Identity-Aware Proxy access to a web backend service: the httpsResourceAccessor binding that decides who gets through (nobody by default), re-authentication every eight hours by the method you choose, the Host header check against your domains, and a troubleshooting link on the denied page. IAP guards the path through the load balancer and no other; the backend must still verify the signed header.

View module
Static validatedLive test pending

aws-verified-access

Per-request access to internal applications evaluated against identity and device posture, with Cedar policy groups, endpoints and logging that records which identity and posture produced each decision.

View module