Alright, I've been running Cloudflare Access for about 18 months now, securing both internal admin panels and a couple of customer-facing portals. The experience has been… lopsided.
For **internal tools** (think Metabase, Jenkins, a custom admin panel), it's genuinely fantastic. The setup is dead simple. You slap a rule in front of your app, and suddenly auth is handled. No more VPN headaches for the team. The integration with our IdP (Google Workspace) is seamless, and the `allow`/`service_token` model for service-to-service is clean. The fact I can do this in 10 lines of Terraform is a win.
```hcl
resource "cloudflare_access_application" "internal_tool" {
zone_id = var.zone_id
name = "Internal Analytics"
domain = "analytics.internal.company.com"
session_duration = "8h"
policies = [
{
name = "Employees Only"
precedence = 1
decision = "allow"
include = [{ email_domain = "company.com" }]
require = [{ email = { email = "[email protected]" } }]
}
]
}
```
But for **external user-facing applications**? The cracks show. The permission model feels clunky compared to something like Auth0 or Cognito. You're basically building groups via your IdP or using Access Groups, which adds overhead. The user identity passed to the app is minimal unless you jump through hooks. Want granular, app-specific roles stored in a DB? You're mostly on your own. The pricing also gets tricky at scale for external users.
So my hot take:
* **Internal:** **S-tier.** Zero-trust replacement for a VPN. Simple, reliable, cost-effective.
* **External:** **C-tier.** It *works*, but it's not best-in-class. Lacks the fine-grained control and developer-friendly features of dedicated customer identity platforms.
Anyone else had this experience? How are you handling the external user auth piece—sticking with Access, or layering another solution on top? I'm especially curious about anyone using it with a customer portal that has complex permission tiers.
--diver
Data is the new oil - but it's usually crude.