Cloudflare
When you connect a Cloudflare account to Oblique, Oblique will automatically sync the account’s members, along with the user groups and resource groups that describe their access.
As you add members in Cloudflare, change their policies, or remove their access, these changes are automatically synced to Oblique. If connected in a read-write mode, Oblique can also make those changes for you.
You can add multiple Cloudflare accounts to Oblique. These function as separate integrations and are distinguished by their account name.
Supported options
Section titled “Supported options”Oblique integrates with Cloudflare:
- As a source for accounts
- As a source for resources
- As a source and destination for entitlements
From your Cloudflare account, Oblique syncs:
- Members of the Cloudflare account, as Oblique accounts
- Resource groups and user groups, as Oblique resources
- Policies and user group membership, as Oblique entitlements
- Permission groups, as Oblique roles
Cloudflare accounts are automatically matched to Oblique users based on email.
Supported resources
Section titled “Supported resources”- Cloudflare resource groups
- Cloudflare user groups
In Cloudflare, a policy is used to grant a member or the members of a user group access to a resource group. Oblique reads these policies as entitlements, and reflects both direct access for members and indirect access through user groups as entitlements in Oblique.
Supported roles
Section titled “Supported roles”The Oblique Cloudflare integration supports information on roles, as defined in Cloudflare, which are its permission groups. An entitlement for a resource group can be for one or more roles. There is no role for being a member of a user group.
Required permissions
Section titled “Required permissions”The Oblique Cloudflare integration requests the following scopes for your Cloudflare account:
| Cloudflare scope | What Oblique uses it for |
|---|---|
account-settings.read | Read the account, its user groups, resource groups, and permission groups |
memberships.read | Read the account’s members and the policies attached to them |
account-settings.write | Change a user group’s policies and its members (for a read-write integration) |
memberships.write | Change the policies attached to a member (for a read-write integration) |
offline_access | Maintain the connection without an administrator signing in again |
Add Cloudflare integration
Section titled “Add Cloudflare integration”You connect a Cloudflare account to Oblique by signing in to Cloudflare as a Super Administrator and approving the access Oblique asks for.
To add a Cloudflare integration, navigate to the Integrations page:
- Select Add integration.
- Select Cloudflare.
- Under Access mode, select Read-write to let Oblique manage access in Cloudflare, or Read-only to only let Oblique read it.
- Select Connect Cloudflare.
- Sign in to Cloudflare as a Super Administrator and approve the access Oblique asks for.
Oblique will immediately start syncing the account’s members and groups.
Change Cloudflare integration’s authorizations
Section titled “Change Cloudflare integration’s authorizations”To reconnect the Oblique Cloudflare integration, including to change the member it is tied to, from the integration’s detail page:
- Navigate to the Settings tab.
- Under Connection, select Reconnect.
- Sign in as a different Cloudflare member and approve the access Oblique asks for.
You can only reconnect the current account. To change the account, instead delete the integration and add another one.
To give a read-only integration write access, from the Settings tab, under Permissions, select Upgrade to read-write and approve the additional access Oblique asks for.
Manage entitlements
Section titled “Manage entitlements”In read-write mode, the Oblique Cloudflare integration lets Oblique manage access in your Cloudflare account. This is done by updating user group membership and policies in Cloudflare.
Sync Cloudflare integration
Section titled “Sync Cloudflare integration”You don’t need to do anything to sync the Cloudflare integration. Oblique will automatically and continuously sync changes from Cloudflare.
Remove Cloudflare integration
Section titled “Remove Cloudflare integration”To remove a Cloudflare integration, from the integration’s detail page:
- Navigate to the Settings tab.
- At the bottom of the page, under Delete integration, select Delete integration….
- In the confirmation dialog, type the text to confirm, then select Delete integration.
This will immediately stop all syncing and remove all resources from the integration. Access that Oblique granted in Cloudflare stays as it is.