
Cloudflare R2 Create
CertifiedCreate Cloudflare IP access rule
Cloudflare R2 Create
Create Cloudflare IP access rule
Creates an IP access rule scoped to either a zone or an account (provide exactly one). Supports block/challenge/whitelist modes and fails if Cloudflare does not return a rule ID.
type: io.kestra.plugin.cloudflare.waf.accessrules.CreateExamples
Block an IP
id: create_ip_access_rule
namespace: company.team
tasks:
- id: block_ip
type: io.kestra.plugin.cloudflare.waf.accessrules.Create
apiToken: "{{ secret('CLOUDFLARE_API_TOKEN') }}"
zoneId: "zone123"
mode: block
target: ip
value: "1.2.3.4"
Properties
apiToken *Requiredstring
Cloudflare API token
Your Cloudflare API token. Create one in the Cloudflare dashboard with DNS read/write permissions.
mode *Requiredstring
blockchallengewhitelistjs_challengemanaged_challengeMode
Action to apply; case-insensitive values from Cloudflare API
target *Requiredstring
ipip_rangeasncountryTarget Type
Entity matched by the rule (IP/CIDR, ASN, or country)
value *Requiredstring
Target Value
Target value such as IP, CIDR block, ASN, or ISO country code
accountId string
Account ID
Account ID to scope the rule; mutually exclusive with zoneId
baseUrl string
https://api.cloudflare.com/client/v4Cloudflare API base URL
Base URL for Cloudflare API. Usually you don’t need to change this.
notes string
Notes
Optional note displayed in Cloudflare dashboard
options Non-dynamic
HTTP client options
Optional advanced HTTP settings like timeouts or proxy.
io.kestra.core.http.client.configurations.HttpConfiguration
falseIf true, allow a failed response code (response code >= 400)
List of response code allowed for this request
The authentication to use.
io.kestra.core.http.client.configurations.BasicAuthConfiguration
The password for HTTP basic authentication.
The username for HTTP basic authentication.
io.kestra.core.http.client.configurations.BearerAuthConfiguration
The token for bearer token authentication.
io.kestra.core.http.client.configurations.DigestAuthConfiguration
The password for HTTP Digest authentication.
The username for HTTP Digest authentication.
The password for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
The username for HTTP basic authentication. Deprecated, use auth property with a BasicAuthConfiguration instance instead.
durationThe time allowed to establish a connection to the server before failing.
durationThe time an idle connection can remain in the client's connection pool before being closed.
UTF-8The default charset for the request.
java.nio.charset.Charset
trueWhether to enable TCP Keep-Alive extended socket options (TCP_KEEPIDLE, TCP_KEEPINTERVAL, TCP_KEEPCOUNT).
Set to false when running on Windows workers, as these extended socket options are not supported by the Windows JDK and will cause connection failures.
trueWhether redirects should be followed automatically.
ALLTRACEDEBUGINFOWARNERROROFFNOT_SPECIFIEDThe log level for the HTTP client.
REQUEST_HEADERSREQUEST_BODYRESPONSE_HEADERSRESPONSE_BODYThe enabled log.
The maximum content length of the response.
The proxy configuration.
io.kestra.core.http.client.configurations.ProxyConfiguration
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTDIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
The address of the proxy server.
The password for proxy authentication.
The port of the proxy server.
DIRECTHTTPSOCKSThe type of proxy to use.
The username for proxy authentication.
durationThe time allowed for a read connection to remain idle before closing it.
durationThe maximum time allowed for reading data from the server before failing.
The SSL request options
io.kestra.core.http.client.configurations.SslOptions
Whether to disable checking of the remote SSL certificate.
Only applies if no trust store is configured. Note: This makes the SSL connection insecure and should only be used for testing. If you are using a self-signed certificate, set up a trust store instead.
The timeout configuration.
io.kestra.core.http.client.configurations.TimeoutConfiguration
The time allowed to establish a connection to the server before failing.
PT5MThe time allowed for a read connection to remain idle before closing it.
pluginDefaultsRef Non-dynamicstring
Reference (ref) of the pluginDefaults to apply to this task.
zoneId string
Zone ID
Zone ID to scope the rule; mutually exclusive with accountId
Outputs
mode string
Mode
Action applied
ruleId string
Rule ID
Identifier returned by Cloudflare
target string
Target
Target type
value string
Value
Target value