Cloudflare DNS
Connect Cloudflare DNS to import A, AAAA, and CNAME records from your zones into Guard as assets.
Overview
The Cloudflare DNS integration imports the DNS records in your Cloudflare zones into the Praetorian Guard Platform (PGP) as assets.
How the Integration Works
The Cloudflare integration automatically discovers all domains and zones in your Cloudflare account and maps DNS records to assets in PGP's inventory. This happens without any manual configuration once the integration is active.
Once configured, the integration performs the following automated operations:
- Automatic Zone Discovery: The integration automatically discovers and enumerates all accessible zones (domains) in your Cloudflare account using the Cloudflare API
- DNS Record Retrieval: For each discovered zone, the integration automatically retrieves all DNS records using the Cloudflare API
- Asset Mapping: The integration processes and maps DNS records to assets in PGP:
- A and AAAA records: Automatically creates asset entries for each IP address, mapping them to their corresponding domains
- CNAME records: Automatically creates asset relationships linking canonical names to their aliases
Discovered zones, DNS records, and their relationships are added to PGP's asset inventory. No manual export or import is required.
Integration Process
Setting Up the Cloudflare API Token
- Begin by accessing your Cloudflare dashboard at https://dash.cloudflare.com/
- Once logged in, navigate to My Profile by clicking on your profile icon in the top right corner
- In the left sidebar, select API Tokens
- Click the Create Token button
- You can either:
- Use the Edit zone DNS template and modify it, or
- Click Create Custom Token to build a token with specific permissions
Configure API Token Permissions
For security best practices, you'll want to configure the API token with minimal necessary permissions. The integration only requires read-only DNS-related permissions to function properly.
Required Permissions
When creating a custom token, configure the following permissions:
Zone Permissions:
- Zone → Read — Required to list all zones in your account
Zone DNS Permissions:
- Zone DNS → Read — Required to read DNS records from zones
Account Resources
- In the Account Resources section, select Include → All accounts (or specify the specific account if you have multiple)
- In the Zone Resources section, select Include → All zones (or specify specific zones if you want to limit access)
Additional Configuration
- IP Address Filtering: Leave empty unless your organization requires specific IP restrictions
- TTL: Set an appropriate expiration time for the token based on your security policies
After configuring these settings, click Continue to summary and then Create Token. Make sure to copy the API token immediately, as you won't be able to access it again after leaving the page. Store it securely, as you'll need it for the next step.
Configuring PGP
With your Cloudflare API token ready, return to your PGP dashboard
Navigate to the Integrations page and click the Add Integration button in the top right corner
Look for the Cloudflare integration option in the list. You can find it by:
- Using the search bar to search for "Cloudflare", or
- Navigating to the Managed DNS Providers category
- Note that the Cloudflare WAF integration is a separate integration
Click Connect on the Cloudflare integration
A configuration window will appear with a single input field for the API token
Paste your previously copied Cloudflare API token into this field
Click Save or Connect to complete the integration
PGP will automatically validate the API token and verify that it has the required permissions. If validation succeeds, the integration will be active and ready to use.
If you have questions, contact support@praetorian.com.
Still need help? Ask the team