All integrations

Domains & DNS Available

Cloudflare

Cloudflare is not a place you go; it is something a domain has. So the management lives on the domain record itself, and Instellingen only keeps the accounts and the zones you fetched.

What you need

  • The cloudflare module switched on under Instellingen → Modules (Settings → Modules), and licence cover via Instellingen → Licentie (Settings → Licence). Without cover, past the grace period only the read surface keeps working: the zone list, the DNS view, the export and the stored status.
  • The permissions cloudflare.settings.manage, cloudflare.dns.read and cloudflare.zone.manage, granted in Instellingen → Rollen (Settings → Roles). All three are admin-only by default.
  • A scoped API token from Cloudflare's own dashboard (My Profile → API Tokens → Create Token). Never the legacy Global API Key: the field demands a scoped token and refuses the unscoped key on purpose.
  • One account row per Cloudflare account, not per installation. An agency has its own; clients bring theirs.
  • No webhook and no callback URL. Traffic is outbound only, from the API container to api.cloudflare.com.

How to connect it

  1. 1 Switch the module on under Instellingen → Modules (Settings → Modules) and hand out the three permissions in Instellingen → Rollen (Settings → Roles): cloudflare.settings.manage, cloudflare.dns.read and cloudflare.zone.manage.
  2. 2 Mint the token in Cloudflare (My Profile → API Tokens → Create Token, custom token). Minimum Zone → Zone → Read. For the DNS table, the export and the records a redirect needs: Zone → DNS → Edit. For the redirect itself: Zone → Dynamic Redirect → Edit. Optional are Zone → Page Rules → Read (spots a legacy forwarding page rule as a conflict), Account → Zone → Edit (create a zone that does not exist yet), Account → Cloudflare Pages → Read/Edit and Account → Domain Registration → Read (the Registrar list, and therefore the invoicing decision).
  3. 3 Add the account under Instellingen → Cloudflare → Account toevoegen (Add account). Fill in Naam (Name, e.g. the client), paste the token into API-token, optionally link a Leveranciersregel (supplier row) and tick In gebruik (In use). The token is never played back; the row only reports that a token is stored.
  4. 4 Press Token controleren (Check token). Under Wat dit token mag (What this token may do) you then get an answer per item: token valid, read account, read zones, read Pages projects, read Registrar domains. Anything you did not grant reads niet toegekend here, instead of surfacing as a 403 on a button three screens away. If the token sees several Cloudflare accounts, fill in Cloudflare-account-ID yourself.
  5. 5 Press Zones ophalen (Fetch zones). One action pulls the zones, the Pages projects and the Cloudflare Registrar list. Whatever did not match on apex name you link by hand in the Zones table with Aan domein koppelen (Link to domain); the Alleen niet-gekoppelde (Unlinked only) filter shows exactly those rows.
  6. 6 Connect a domain: Domeinen → the domain → Cloudflare panel → Koppelen aan Cloudflare (Connect to Cloudflare), and pick the Account. Taking over a client's existing setup, tick Alleen een bestaande zone koppelen (Adopt an existing zone only). schakl. adopts an existing zone before it ever creates one either way. Controleren bij Cloudflare (Check at Cloudflare) is then the button that actually goes and looks.
  7. 7 If schakl. created a new zone, repoint the domain's nameservers at your registrar to the pair the panel shows under Cloudflare verwacht (Cloudflare expects). Until you do, the zone stays pending at Cloudflare and no traffic reaches the edge, so a redirect does not fire yet. For a domain at OXXA, the Nameservers van Cloudflare gebruiken button on the registrar panel fills it in for you.
  8. 8 Set the redirect under Domeinbrede omleiding (Domain-wide redirect): Omleiden naar (Redirect to), Soort omleiding (Redirect type), Pad meenemen (Keep the path), Querystring meenemen (Keep the query string) and Ook www en andere subdomeinen omleiden (Redirect www and other subdomains too). Leave Records toevoegen die de omleiding nodig heeft (Add the records the redirect needs) ticked and press Omleiding opslaan (Save redirect).

The redirect finally has a mechanism

A domain marked as a redirect in schakl. was a status label with nothing behind it for a long time — the actual redirect lived in an external flow. Now it is a Cloudflare Redirect Rule with a single owner. schakl. stores what it set and, on Controleren bij Cloudflare, reads back what is really there; if the two differ you get Gewijzigd bij Cloudflare (changed at Cloudflare) and you decide whether to overwrite. If another redirect rule or a legacy forwarding page rule already redirects on the zone, it shows up under Andere omleidingen op deze zone (other redirects on this zone). schakl. never reorders or deletes somebody else's rule.

  • 301, 302, 307 or 308, with a warning on the permanent ones because browsers remember them
  • A redirect that points back into its own match set is refused, not saved
  • Removing one walks the domain's own status back only if it still says what schakl. put there

Without a proxied record, nothing happens

This is the single most confusing way a redirect fails. A Redirect Rule only fires for traffic that actually reaches Cloudflare's edge, and a zone whose apex has no proxied record never receives any. The rule saves, Cloudflare's dashboard shows it active, and nothing happens. That is why Records toevoegen die de omleiding nodig heeft is on by default: it writes Cloudflare's own documented placeholder, a proxied AAAA 100::, covering the apex and www and deliberately nothing else. An existing record is never replaced. Grey the cloud out later and it is reported under Aandachtspunten (points of attention) rather than quietly ceasing to work.

DNS, export and Pages

The DNS table is read live from Cloudflare and never stored by schakl.: a cached copy would be wrong within minutes of any change. You add and edit records in the same panel, with Type, Naam, Waarde, TTL, Via Cloudflare (proxied), Prioriteit and Notitie. Exports come as a zone file (Cloudflare's own BIND export) or CSV. For a site on Cloudflare Pages you pick a Project and optionally a Hostnaam under Cloudflare Pages; schakl. registers the hostname on the project and writes the CNAME when the domain has a zone here. When it does not, the panel says in so many words that you must point DNS at the project's pages.dev address yourself.

The register decides who pays

A zone is not a registration. Cloudflare will happily answer DNS for a domain the client registered elsewhere and renews themselves, which is exactly the domain an agency must never invoice. Only the Cloudflare Registrar list can tell those two apart. So the Facturatie (invoicing) field on a domain is three-state: Wel factureren (do invoice), Niet factureren (do not invoice), or Volg het register (follow the register). Under Volg het register the hint says whether the domain sits in a connected register, and the Gefactureerd column in the domain list prints volgens register beside the answer. Only a register that has actually answered may narrow what gets invoiced: until then, every undecided domain bills exactly as it did before.

Permissions

Grant these to the role that manages this integration (Settings → Roles). Admin-only by default, and never to the client role.

  • cloudflare.settings.manage Add a Cloudflare account, rotate, verify or delete its token, and run the sync. This permission is also what opens Instellingen → Cloudflare.
  • cloudflare.dns.read The zone list, the DNS table and its export, the stored status report and the account picker.
  • cloudflare.zone.manage Create or adopt a zone, edit DNS, set or remove the domain-wide redirect, and link Pages. All three permissions are admin-only by default and are never granted to the seeded client role.

What it deliberately does not do

  • There is no background sync. Zones ophalen is a button: zones, Pages projects and the Registrar list never refresh themselves on a schedule.
  • The Registrar half has never been exercised against a live Cloudflare Registrar account. Every field is parsed defensively, and docs/CLOUDFLARE.md carries a checklist to run the day such an account exists.
  • schakl. never guesses which Cloudflare account. If the same apex exists in several of them, connecting is refused — a zone created in the wrong account cannot be moved, only deleted and recreated, with a nameserver change and a propagation window in between.
  • Conflicts are reported, never resolved. Another redirect rule or page rule stays where it is, and account-level Bulk Redirects are not inspected at all.
  • The zone table in Instellingen is a flat inventory capped at 200 zones with no pager. An account holding more will not show them all on that screen.
  • Deleting an account row removes only the local rows (zones, redirects, Pages projects and links). Nothing changes at Cloudflare.

Where to find it Instellingen → Cloudflare (Settings → Cloudflare) for the accounts and the fetched zones, plus the Cloudflare panel on Domeinen → the domain (Domains) for the per-domain work.

Read the guide

More in this category

Other integrations