cloudflare-one

Manage Cloudflare One configuration and troubleshooting across Access, Gateway, WARP, and Tunnel.

Updated Jul 5, 2026
One-click install
npx skills add https://github.com/Arupbiswas09/claude_skills --skill cloudflare-one-arupbiswas09
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloudflare-one
Source: https://github.com/Arupbiswas09/claude_skills/tree/main/skills/cloudflare-one
Command: npx skills add https://github.com/Arupbiswas09/claude_skills --skill cloudflare-one-arupbiswas09

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) and assets (resource) components.

What problem does it solve?

This Skill provides comprehensive guidance for Cloudflare One, simplifying the management of Zero Trust and SASE across various components like Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity.

Core Features & Use Cases

  • Zero Trust Architecture: Offers guidelines for designing, configuring, troubleshooting, and reviewing Cloudflare One deployments.
  • Documentation Retrieval: Provides instructions to retrieve current information from Cloudflare One docs, MCP server, or API schema.
  • Workflow Management: Outlines a workflow for classifying asks, gathering context, retrieving necessary documentation, inspecting existing resources, and proposing change sets.
  • Assessment Prompts: Provides prompts for architecture, current state, access and SaaS federation, tunnel and private networking, gateway, TLS, and DLP, CASB, device posture, risk, and operations, infrastructure access, logs, analytics, and DEX, Cloudflare WAN, and site connectivity.
  • Guardrails: Offers best practices and considerations for access controls, public and private app configurations, tunneling, identity and access, device client deployment, private networking, gateway, TLS, and DLP, CASB, risk, and operations, infrastructure access, logs, analytics, and DEX, Cloudflare WAN, and site connectivity.
  • Identity and Access: Explains the difference between Access Groups and IdP/SCIM groups, group naming and SAML/OIDC attributes, SCIM changes, and group membership.
  • Device Client Deployment: Describes the on-ramp for user devices, enrollment rules, device profiles, connection mode, split tunnel configuration, user permissions, auto-reconnect, and captive portal behavior.
  • Private Networking: Discusses split tunnel mode, virtual networks, tunnel health, route lookup, origin reachability, routing, management model, and HA.
  • Gateway, TLS, and DLP: Explains traffic controls, identity, TLS inspection, DLP, and API CASB.
  • CASB, Risk, and Operations: Discusses CASB findings, remediation guidance, scan timing, finding instances, and risk-score signal latency.
  • Infrastructure Access: Describes Zero Trust Infrastructure Access, Browser Rendering, Audit SSH, short-lived certificates, and kubectl and database access.
  • Logs, Analytics, and DEX: Provides information on Gateway activity logs, Access audit logs, Shadow IT discovery, DEX, Logpush, and troubleshooting.
  • Cloudflare WAN / Site Connectivity: Discusses site topology, on-ramp type, route ownership, tunnel redundancy, static vs BGP-managed routes, network firewall needs, and appliance/profile ownership.

Quick Start

Use the cloudflare-one skill to retrieve current documentation for Cloudflare One from the Cloudflare One docs, the Cloudflare docs MCP server, or the Cloudflare API schema.

Frequently Asked Questions about cloudflare-one

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I configure Cloudflare One Zero Trust and SASE components like Access and Gateway?

Configuring Cloudflare One Zero Trust and SASE components involves defining Access groups, deploying the WARP device client, setting Gateway traffic controls, and establishing tunnel routing. It guides this workflow end-to-end, proposing change sets with prerequisites, validation, and rollback procedures.

What is the difference between Cloudflare Access Groups and IdP SCIM groups?

Cloudflare Access Groups are policy constructs within the Zero Trust dashboard, while IdP SCIM groups synchronize membership directly from your Identity Provider. The skill explains group naming, SAML/OIDC attributes, SCIM change handling, and group membership differences for identity and access management.

How do I troubleshoot Cloudflare WARP device client deployment and private networking routing?

Troubleshooting Cloudflare WARP and private networking requires checking enrollment rules, split tunnel configurations, virtual networks, and tunnel health. The skill helps inspect existing resources, verify route lookup, origin reachability, and HA configurations to resolve routing issues.

Does this approach support configuring Cloudflare DLP, CASB, and TLS inspection?

Yes, configuring Cloudflare DLP, CASB, and TLS inspection is fully supported. The skill provides assessment prompts and guardrails for implementing traffic controls, TLS inspection, data loss prevention, API CASB findings remediation, scan timing, and risk-score signal latency.

Can I manage Cloudflare WAN site connectivity and BGP-managed routes using this workflow?

Managing Cloudflare WAN site connectivity covers site topology, on-ramp types, route ownership, and tunnel redundancy. The skill helps assess static versus BGP-managed routes, network firewall needs, and appliance profile ownership to propose optimized architecture changes.

What is the best way to retrieve current Cloudflare One documentation for architecture assessment?

Retrieving current Cloudflare One documentation is best handled by pulling data directly from the Cloudflare One docs, the Cloudflare docs MCP server, or the Cloudflare API schema. The skill automates gathering context and inspecting resources prior to proposing change sets.