Cloudflare Zero Trust and Edge Protection
Cloudflare is used for DNS, WAF, Zero Trust access, and tunnel-based exposure of selected MRDTech services.
Repository references:
Roles
| Component | Purpose |
|---|---|
| Cloudflare DNS | Authoritative DNS and public record management |
| Cloudflare WAF | Edge filtering and common attack mitigation |
| Cloudflare Zero Trust / Access | Identity-aware access to selected services |
| Cloudflare Tunnels | Avoid direct inbound exposure where possible |
| CrowdSec Cloudflare bouncer | Push high-confidence ban decisions to the Cloudflare edge |
Operating principles
- No unnecessary direct inbound exposure.
- Protect administrative apps with identity-aware access or LAN/VPN-only exposure.
- Use Cloudflare WAF and CrowdSec bouncer decisions as edge controls.
- Keep DNS and tunnel credentials out of repositories and WikiDocs.