Cloudflare Zero Trust
Integration & Setup Manual
Cloudflare Zero Trust Integration Guide
Overview
Cup’n’String Guard integrates with Cloudflare Zero Trust Gateway to enforce AI tool outbound network policies at the identity-aware, cloud-hosted layer. Guard uses the Cloudflare v4 API to apply network filtering policies immediately, guarded by ETags to detect concurrent modifications and prevent drift.
Support level
ZTNA Orchestration — immediate apply with ETag-based drift detection. Identity-aware enforcement (user/device identity flows through Cloudflare WARP).
Recommended Guard mode
Observe to audit which AI tool destinations are currently allowed, then Enforce to block unauthorized LLM endpoints at the Cloudflare Gateway layer.
Known limitations
- Cloudflare Gateway policies apply to all WARP-enrolled devices in the account; per-device exclusions require additional Cloudflare device posture rules.
- Per-process enforcement is not available at the Cloudflare Gateway layer.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix