CloudflareOrigin

Cloudflare origin protection checklist

A working checklist we use across engagements to reason about origin exposure, from CT-log audit to firewall trust anchoring.

A working origin-protection checklist has to survive rotation. The following list is what we validate on every Cloudflare-fronted engagement.

Certificate transparency audit for prior origin IPs. Locked-down origin firewall (allow only current edge IPs). Signed CDN header verified end-to-end. Historical DNS records reviewed for exposure. No staging environments listening on public interfaces. No CI runners on production-adjacent IPs.

None of these are novel. The consistent finding is that they need to be automated. A manual checklist done at launch does not survive the first infrastructure change.

Cookies

We use a minimal set of cookies to keep this site functional. Analytics cookies only with your consent. Cookie Policy.