cloudflare-one-migrations

Plan Cloudflare One migrations from Zscaler, Palo Alto, VPN, SWG, and SASE environments.

Updated Jan 30, 2026
One-click install
npx skills add https://github.com/Rayzerrek/dotfiles --skill cloudflare-one-migrations
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: cloudflare-one-migrations
Source: https://github.com/Rayzerrek/dotfiles/tree/main/.pi/agent/skills/cloudflare-one-migrations
Command: npx skills add https://github.com/Rayzerrek/dotfiles --skill cloudflare-one-migrations

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill turns complex security and networking migrations into a structured Cloudflare One assessment, helping teams avoid missed rules, broken dependencies, and unsafe cutovers.

Core Features & Use Cases

  • Source-to-target mapping: Converts Zscaler, Palo Alto, legacy VPN, SWG, and SASE controls into Cloudflare One resources and policies.
  • Gap and risk analysis: Flags partial mappings, unsupported features, identity gaps, TLS and DLP mismatches, and rollout prerequisites.
  • Migration planning: Produces inventories, staged rollout plans, validation checks, and rollback guidance for real-world enterprise cutovers.

Quick Start

Ask the AI to analyze your source security stack exports and generate a Cloudflare One migration assessment with mappings, risks, rollout steps, and validation gates.

Frequently Asked Questions about cloudflare-one-migrations

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I plan a Cloudflare One migration from Zscaler or Palo Alto?

Cloudflare One migration planning analyzes source security stack exports to map Zscaler or Palo Alto controls into Cloudflare One resources, generating staged rollout plans and validation checks to prevent unsafe cutovers.

What is SASE policy mapping and how does it handle unsupported features?

SASE policy mapping converts existing security controls into target platform policies, explicitly flagging partial mappings and unsupported features during the inventory review to ensure validation before enablement.

How do I identify parity gaps when migrating VPN and SWG controls?

Parity-gap analysis for VPN and SWG migrations identifies mismatches in identity, routing, DNS, DLP, and logging controls by tracing dependencies in structured exports before attempting a cutover.

Does Cloudflare One migration require structured exports and API schemas?

Yes, Cloudflare One migration requires structured source rule exports, Cloudflare documentation, and API schemas to accurately map controls and validate that all identity and networking dependencies are accounted for.

What is the best way to roll out a Cloudflare One pilot safely?

The safest way to roll out a Cloudflare One pilot is using a staged rollout plan with validation gates and rollback guidance, ensuring dependency tracing and policy mapping are verified before full enablement.

What are the limitations of migrating legacy SASE environments to Cloudflare One?

Migrating legacy SASE environments to Cloudflare One faces limitations with partial or unsupported mappings, requiring explicit gap analysis for TLS and DLP mismatches to avoid broken dependencies during cutovers.