Skip to content

Cloudflare Terraform Provider

TrendingActive
cloudflare/terraform-provider-cloudflare

Official Terraform provider for managing Cloudflare zones, DNS, Workers, R2, WAF and Zero Trust resources as code.

View on GitHub
Stars
1.3k
Forks
890
Watchers
1.3k
Open issues
224

Overview

The Cloudflare Terraform Provider lets you manage Cloudflare resources — zones, DNS records, Workers, R2 buckets, WAF rules, Zero Trust policies, and much more — as code with Terraform. It is maintained by Cloudflare and generated from the Cloudflare REST API, so new API features reach the provider quickly.

Managing Cloudflare through Terraform gives you reviewable changes, repeatable environments, and a full history of your configuration in version control.

Key Features

  • Broad API coverage: DNS, zones, Workers, Pages, R2, KV, D1, load balancers, rulesets, Access, Tunnels, and more
  • Infrastructure as code: plan, review, and apply changes like any other Terraform resource
  • Multiple auth schemes: scoped API tokens (recommended), or legacy Global API key plus email
  • Account- and zone-level defaults to cut repetition in large configurations
  • Examples and full docs on the Terraform Registry

Getting Started

Requires Terraform CLI 1.0 or later. Declare the provider in main.tf:

terraform {
  required_providers {
    cloudflare = {
      source = "cloudflare/cloudflare"
    }
  }
}

provider "cloudflare" {
  # Prefer setting CLOUDFLARE_API_TOKEN in the environment instead of hard-coding it.
}

resource "cloudflare_dns_record" "www" {
  zone_id = var.zone_id
  name    = "www"
  type    = "CNAME"
  content = "example.pages.dev"
  proxied = true
  ttl     = 1
}

Then initialize and apply:

terraform init
terraform plan
terraform apply

Pin a provider version in required_providers for reproducible builds, and keep API tokens out of your code by using environment variables or a secrets manager.

Tips

  • Use scoped API tokens with only the permissions your configuration needs.
  • Bring existing resources under management with terraform import, or use Cloudflare’s companion tool cf-terraforming to generate configuration from what is already in your account.
  • Check the upgrade guides when moving between major versions — resource schemas can change.

Use Cases

  • GitOps workflows for DNS and security rules across many zones
  • Reproducible staging and production environments
  • Auditable, peer-reviewed infrastructure changes

License

Apache License 2.0.

Similar open-source projects, ranked by shared categories and tags.

All DevOps projects →