Cloudflare
The Cloudflare connector discovers DNS zones available to its API token and supports Gateway’s managed Domains and DNS-01 certificate workflows. It is not a hosting provider and does not replace Gateway Relay or a managed ingress node.
Create the Cloudflare token
Section titled “Create the Cloudflare token”- In the Cloudflare dashboard, open My Profile > API Tokens > Create Token. Choose the Edit zone DNS template or create a custom token.
- Set these two permissions and review the template rather than assuming it includes both:
| Permission category | Resource | Access | Purpose |
|---|---|---|---|
Zone |
Zone |
Read |
Discover the zones available to the connector |
Zone |
DNS |
Edit |
Create/update/delete managed DNS and certificate-challenge records |
- Under Zone Resources, select Include > Specific zone and each zone Gateway should manage. Do not select all zones unless that is intentional.
- If setting Client IP Address Filtering, allow the Gateway backend’s outbound IP, not your browser’s IP. Set an expiry that you can rotate before certificate renewal depends on it.
- Review the summary, create the token, and copy the secret. It is an API token, not a Global API Key, Origin CA key, or account ID.
These workflows do not require Workers, Pages, Tunnel, or account-administration privileges. A zone token must belong to an identity that itself has access to the selected zones.
Reference: Cloudflare API-token creation.
Connect DNS access
Section titled “Connect DNS access”- Create a dedicated Cloudflare API token with access to the intended zones and the zone-read/DNS-edit permissions needed by your workflow. Restrict the zone resources at Cloudflare rather than supplying an account-wide credential.
- Open Settings > Integrations > Cloudflare, add a named connector, and supply the token through the credential field.
- Test access and inspect the discovered zones. The connector discovers all zones visible to that token; token restrictions determine that boundary.
- Review automatic synchronization and the default TTL and proxy settings.
- Continue with Domains, Routes, and TLS to choose an eligible ingress node and create the actual managed Domain and Route.
A connection test and zone discovery do not prove DNS write permission or public propagation. Verify the intended record and certificate workflow separately. Existing conflicting DNS records require an explicit overwrite decision; do not assume a connector gives Gateway ownership of unrelated records.
Certificates and transport
Section titled “Certificates and transport”DNS-01 validation needs the correct zone and permission to manage challenge records. Verify credential availability for renewal, not just the initial certificate issuance. See SSL certificates.
The web hostname’s Cloudflare proxy setting is separate from daemon enrollment. Do not assume a proxied HTTPS hostname can carry Gateway’s direct gRPC connection; use the generated address and requirements in Add your first node.
Permissions and recovery
Section titled “Permissions and recovery”Connector visibility and administration use integrations:cloudflare:view and integrations:cloudflare:manage. Managed Domain operations use domains:*; certificate actions have their own permissions. Provider-token rights are an additional boundary, not a replacement for Gateway scopes.
For errors, check the selected account and zone, token expiration and privileges, authoritative DNS response, TTL, proxy mode, and certificate challenge status. Rotate the token only after verifying the replacement. Before disabling or removing the connector, identify dependent Domains and certificate renewals.
For other delivery integrations, see Email and webhooks.
