Cloudflare Zero Trust Lists Integration
Manage Cloudflare Zero Trust Gateway IP lists directly from Weavestream with automatic drift detection.
Cloudflare Zero Trust Lists lets you manage Cloudflare Zero Trust Gateway IP lists directly from Weavestream.
Instead of manually editing IP lists across individual Cloudflare tenant dashboards, you add, update, and remove IP and CIDR entries inside Weavestream. Changes are pushed to Cloudflare immediately, establishing Weavestream as the primary source of truth.
Key Capabilities
- Bidirectional Sync & Push: Manage Cloudflare Zero Trust Gateway IP lists natively within Weavestream.
- Automated Drift Detection: A background drift sweep constantly compares Cloudflare state against Weavestream records, detecting and auto-correcting out-of-band edits.
- IPv4 and IPv6 Support: Full validation and support for single IP addresses and CIDR prefix blocks (e.g.
192.168.1.0/24and2601:280:5280:7bc0::/64). - Multi-List Registration: Register multiple Cloudflare Gateway IP lists under a single API integration instance.
Managed Attributes Reference
Setup Instructions
Prerequisites
- A Cloudflare account with Zero Trust enabled.
- Cloudflare Account ID.
- A Cloudflare API Token with the Account → Zero Trust → Edit permission.
Step 1: Create the Cloudflare API Token
- Log into your Cloudflare Dashboard.
- Navigate to My Profile → API Tokens → Create Token.
- Select Create Custom Token.
- Set permissions to: Account → Zero Trust → Edit.
- Set Account Resources to your target account.
- Click Continue to Summary and Create Token. Copy the generated token.
Step 2: Configure Integration in Weavestream
- In Weavestream, navigate to Admin → Integrations → New Integration.
- Select Cloudflare Zero Trust Lists as the provider.
- Enter your Cloudflare Account ID and the API Token.
- Click Test Connection to verify access to your Cloudflare Zero Trust environment.
- Click Save.
Step 3: Link an Existing Gateway List
- Open the created Cloudflare integration detail page.
- Click Link Cloudflare List.
- Select the Gateway list you wish to manage from the list of discovered Cloudflare Zero Trust Gateway lists.
- Click Register List. Weavestream will import existing entries and begin active management.
Note
For detailed step-by-step instructions—including setting up Cloudflare Gateway policies and firewall rules—see the complete Cloudflare Zero Trust IP Lists guide.