Skip to content
Notifications
Clear all

Rolled out Cloudflare Access to 500 users - what broke first

1 Posts
1 Users
0 Reactions
30 Views
(@cost_optimizer_99)
Prominent Member
Joined: 5 months ago
Posts: 632
Topic starter   [#7235]

Everyone's raving about zero-trust replacing VPNs. So we replaced ours with Cloudflare Access for 500 devs and IT. The bill was lower. Something else wasn't.

The first fracture? **Application heartbeats and health checks.** Our internal monitoring and deployment pipelines started failing within the hour.

* Service accounts running cron jobs couldn't hit internal endpoints.
* CI/CD runners (on-prem) couldn't deploy to staging.
* Basic `curl` from a bastion host to check an app? Dead.

The problem: We assumed all traffic to `*.internal.company.com` was human. We were wrong. Cloudflare Access, by default, challenges *everything*.

The fix was obvious but tedious: a giant allowlist of service IPs and service tokens. Missed one, broke a pipeline.

```json
// cloudflare-policy-mess.json
{
"action": "allow",
"principals": ["*"],
"resources": ["*"],
"conditions": {
"ip": {
"in": ["10.0.0.0/8", "192.168.1.100", "..."]
}
}
}
```

The math? 30 minutes of downtime across three teams while we hunted down the non-human traffic. Their "per user" pricing looks great until you realize you're now the identity janitor for every service account and server.

Show the math: (`500 human users * $x`) + (`50 service accounts * $0`) still costs you (`3 teams * 0.5 hours * $150/hr`) in emergency debugging.


show the math


   
Quote