Cloudflare Infrastructure-as-Code modules
16 verified ansible / terraform modules for Cloudflare, spanning Cloud Tooling, Edge & DNS. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
1 of 16 Cloudflare modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 15 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Cloudflare modules
ansible-cloudflared-tunnel
cloudflared from Cloudflare's signed repository (a 2025 key rpm on EL 10 accepts), pinned, run as a hardened unit that reads the tunnel token from a root-only file, not from the unit or ps. Never self-updating. The live test greps the unit and the connector's command lines for the token and expects nothing. Original role, live-tested on Rocky Linux 10.
cloudflare-d1-database
Where a D1 primary lives is decided at creation, near whoever ran the create unless a hint or jurisdiction says otherwise; read replication is off by default; and backups are Time Travel with a window the plan decides (30 days paid, 7 free) and no export schedule. Hint or jurisdiction set, replication by name, the recovery window as an output, and an output that says no export is scheduled.
cloudflare-load-balancer
A pool with no monitor is healthy forever and keeps sending traffic to a dead origin; the fallback pool is required and the easiest value is the same pool that just failed; the notification email that says a pool went down is optional. Every pool uses the module's HTTPS monitor, a fallback that is also a default is refused, an address is told, and the balancer is proxied so origins stay hidden.
cloudflare-pages-project
Every branch pushed gets a public preview URL by default, the half-finished pricing page included; an environment variable is readable in the dashboard unless stored as a secret; and the production branch is whatever the repository's default was. Previews limited to the branches you list (every branch by name), each variable marked secret or plain, bindings per environment, and custom domains.
cloudflare-turnstile
The widget secret is the whole check: whoever holds it mints passing verifications for your forms; domains is an allow list of hostnames, so a widget made for production does not render on staging until staging is listed; and the mode decides whether visitors see a checkbox, a spinner or nothing. Hostnames required, the mode validated, and the secret exposed only as a sensitive output.
cloudflare-waf
A paid plan makes the Cloudflare Managed Ruleset and the OWASP Core Ruleset available; a zone runs them only when a rule in the managed phase executes them, so a subscribed zone with no such rule is protected by the free ruleset alone. Both executed here with the OWASP threshold set, custom rules that block rather than log, and a per-client rate limit in its own phase.
cloudflare-origin-ca-certificate
A certificate for the hop between Cloudflare and your origin. It is trusted by Cloudflare and by nothing else, so it is right only when the origin accepts Cloudflare alone. A CSR is required precisely so the key stays where it was generated, and the validity is one year rather than the fifteen the API offers, since that is how long a leaked key stays usable.
cloudflare-health-check
A health check on an origin with allow_insecure false, since an origin whose certificate expired last week passes a check that was told not to look. expected_body is what tests the application rather than the web server, because an error page, a maintenance page and a page saying the database is unreachable are all 200s. Two consecutive failures, not one.
cloudflare-r2-bucket
R2 has no versioning: an overwrite or delete is the end of the object, and the only control that refuses deletion is a bucket lock rule, which a bucket without one needs to accept by name. Abandoned multipart uploads bill until a lifecycle rule aborts them. Private with no domain attached, lock rules taken, incomplete uploads freed after a week, and the EU or FedRAMP jurisdiction set at creation.
cloudflare-bot-management
Bot Fight Mode is zone-wide with no path exclusion and no allow list: it challenges CI runners, monitoring, mobile apps and every API client that worked yesterday. Off unless accepted by name, Super Bot Fight Mode with an action per class on paid plans (challenge the definitely automated, admit the rest), AI crawlers blocked, and an output that says whether API clients will be challenged.
cloudflare-cdn
Cloudflare caches by file extension out of the box, so the hashed assets are cached and the HTML is not, and every page view still reaches the origin while the dashboard reports a healthy hit ratio. A rule that caches is what changes that; a ruleset holding none is refused, and a caching rule matching every request is refused separately.
cloudflare-dns
Zone DNS records, security settings, and managed WAF rulesets for a Cloudflare zone - provider v5 ready.
cloudflare-notification-policy
An origin marked unreachable, a certificate that failed to renew, a DDoS mitigation on your zone: each is an event the account can notify about and none does until a policy exists, and a policy whose mechanisms block is empty is accepted and notifies nobody. Origin health, certificate and DDoS policies by default, more by alert type, and at least one email or webhook required for all of them.
cloudflare-workers-platform
Worker with KV/R2/D1 bindings, routes, custom domain, and secrets - full edge app scaffold.
cloudflare-zero-trust-access
Access application with policies, identity provider wiring, and a cloudflared tunnel to private origins.
cloudflare-zone-hardening
ssl = flexible encrypts the visitor's half and speaks plain HTTP to the origin while showing a padlock; DNSSEC is off until turned on at Cloudflare and again at the registrar; and TLS 1.0, HTTP without redirect and no HSTS are the defaults. Strict SSL with weaker modes accepted by name, TLS 1.2 minimum, HTTPS forced, HSTS (preload by name), DNSSEC on with the DS record exposed.
Compare across clouds
All solutions →See how the services Cloudflare covers here compare on other providers.