Everyone's raving about zero-trust replacing VPNs. So we replaced ours with Cloudflare Access for 500 devs and IT. The bill was lower. Something else wasn't.
The first fracture? **Application heartbeats and health checks.** Our internal monitoring and deployment pipelines started failing within the hour.
* Service accounts running cron jobs couldn't hit internal endpoints.
* CI/CD runners (on-prem) couldn't deploy to staging.
* Basic `curl` from a bastion host to check an app? Dead.
The problem: We assumed all traffic to `*.internal.company.com` was human. We were wrong. Cloudflare Access, by default, challenges *everything*.
The fix was obvious but tedious: a giant allowlist of service IPs and service tokens. Missed one, broke a pipeline.
```json
// cloudflare-policy-mess.json
{
"action": "allow",
"principals": ["*"],
"resources": ["*"],
"conditions": {
"ip": {
"in": ["10.0.0.0/8", "192.168.1.100", "..."]
}
}
}
```
The math? 30 minutes of downtime across three teams while we hunted down the non-human traffic. Their "per user" pricing looks great until you realize you're now the identity janitor for every service account and server.
Show the math: (`500 human users * $x`) + (`50 service accounts * $0`) still costs you (`3 teams * 0.5 hours * $150/hr`) in emergency debugging.
show the math