Cloudflare Infrastructure-as-Code modules

16 verified ansible / terraform modules for Cloudflare, spanning Cloud Tooling, Edge & DNS. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

1 of 16 Cloudflare modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 15 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All Cloudflare modules

Live-tested

ansible-cloudflared-tunnel

cloudflared from Cloudflare's signed repository (a 2025 key rpm on EL 10 accepts), pinned, run as a hardened unit that reads the tunnel token from a root-only file, not from the unit or ps. Never self-updating. The live test greps the unit and the connector's command lines for the token and expects nothing. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

cloudflare-d1-database

Where a D1 primary lives is decided at creation, near whoever ran the create unless a hint or jurisdiction says otherwise; read replication is off by default; and backups are Time Travel with a window the plan decides (30 days paid, 7 free) and no export schedule. Hint or jurisdiction set, replication by name, the recovery window as an output, and an output that says no export is scheduled.

View module
Static validatedLive test pending

cloudflare-load-balancer

A pool with no monitor is healthy forever and keeps sending traffic to a dead origin; the fallback pool is required and the easiest value is the same pool that just failed; the notification email that says a pool went down is optional. Every pool uses the module's HTTPS monitor, a fallback that is also a default is refused, an address is told, and the balancer is proxied so origins stay hidden.

View module
Static validatedLive test pending

cloudflare-pages-project

Every branch pushed gets a public preview URL by default, the half-finished pricing page included; an environment variable is readable in the dashboard unless stored as a secret; and the production branch is whatever the repository's default was. Previews limited to the branches you list (every branch by name), each variable marked secret or plain, bindings per environment, and custom domains.

View module
Static validatedLive test pending

cloudflare-turnstile

The widget secret is the whole check: whoever holds it mints passing verifications for your forms; domains is an allow list of hostnames, so a widget made for production does not render on staging until staging is listed; and the mode decides whether visitors see a checkbox, a spinner or nothing. Hostnames required, the mode validated, and the secret exposed only as a sensitive output.

View module
Static validatedLive test pending

cloudflare-waf

A paid plan makes the Cloudflare Managed Ruleset and the OWASP Core Ruleset available; a zone runs them only when a rule in the managed phase executes them, so a subscribed zone with no such rule is protected by the free ruleset alone. Both executed here with the OWASP threshold set, custom rules that block rather than log, and a per-client rate limit in its own phase.

View module
Static validatedLive test pending

cloudflare-origin-ca-certificate

A certificate for the hop between Cloudflare and your origin. It is trusted by Cloudflare and by nothing else, so it is right only when the origin accepts Cloudflare alone. A CSR is required precisely so the key stays where it was generated, and the validity is one year rather than the fifteen the API offers, since that is how long a leaked key stays usable.

View module
Static validatedLive test pending

cloudflare-health-check

A health check on an origin with allow_insecure false, since an origin whose certificate expired last week passes a check that was told not to look. expected_body is what tests the application rather than the web server, because an error page, a maintenance page and a page saying the database is unreachable are all 200s. Two consecutive failures, not one.

View module
Static validatedLive test pending

cloudflare-r2-bucket

R2 has no versioning: an overwrite or delete is the end of the object, and the only control that refuses deletion is a bucket lock rule, which a bucket without one needs to accept by name. Abandoned multipart uploads bill until a lifecycle rule aborts them. Private with no domain attached, lock rules taken, incomplete uploads freed after a week, and the EU or FedRAMP jurisdiction set at creation.

View module
Static validatedLive test pending

cloudflare-bot-management

Bot Fight Mode is zone-wide with no path exclusion and no allow list: it challenges CI runners, monitoring, mobile apps and every API client that worked yesterday. Off unless accepted by name, Super Bot Fight Mode with an action per class on paid plans (challenge the definitely automated, admit the rest), AI crawlers blocked, and an output that says whether API clients will be challenged.

View module
Static validatedLive test pending

cloudflare-cdn

Cloudflare caches by file extension out of the box, so the hashed assets are cached and the HTML is not, and every page view still reaches the origin while the dashboard reports a healthy hit ratio. A rule that caches is what changes that; a ruleset holding none is refused, and a caching rule matching every request is refused separately.

View module
Static validatedLive test pending

cloudflare-dns

Zone DNS records, security settings, and managed WAF rulesets for a Cloudflare zone - provider v5 ready.

View module
Static validatedLive test pending

cloudflare-notification-policy

An origin marked unreachable, a certificate that failed to renew, a DDoS mitigation on your zone: each is an event the account can notify about and none does until a policy exists, and a policy whose mechanisms block is empty is accepted and notifies nobody. Origin health, certificate and DDoS policies by default, more by alert type, and at least one email or webhook required for all of them.

View module
Static validatedLive test pending

cloudflare-workers-platform

Worker with KV/R2/D1 bindings, routes, custom domain, and secrets - full edge app scaffold.

View module
Static validatedLive test pending

cloudflare-zero-trust-access

Access application with policies, identity provider wiring, and a cloudflared tunnel to private origins.

View module
Static validatedLive test pending

cloudflare-zone-hardening

ssl = flexible encrypts the visitor's half and speaks plain HTTP to the origin while showing a padlock; DNSSEC is off until turned on at Cloudflare and again at the registrar; and TLS 1.0, HTTP without redirect and no HSTS are the defaults. Strict SSL with weaker modes accepted by name, TLS 1.2 minimum, HTTPS forced, HSTS (preload by name), DNSSEC on with the DS record exposed.

View module

Compare across clouds

All solutions →

See how the services Cloudflare covers here compare on other providers.

Other providers