Cloudflare
We run Cloudflare as the layer in front of your infrastructure: DNS, Tunnel and Zero Trust Access, so services stay reachable without open ports or public IP addresses.
FIG 10
DNS management and Cloudflare Tunnel publish services without a public IP address. This works behind CGNAT too.
Access policies in front of internal tools: identity based instead of blanket VPN access for everyone.
Edge logic runs close to the user, for functions that do not need to live on a classic server.
Security headers, WAF-adjacent rules and Turnstile bot protection are part of the standard setup, not an add-on.
Cloudflare DNS · Cloudflare Tunnel · Cloudflare Access (Zero Trust) · Workers · Turnstile · WAF