Skip to content

Cloudflare

When you connect a Cloudflare account to Oblique, Oblique will automatically sync the account’s members, along with the user groups and resource groups that describe their access.

As you add members in Cloudflare, change their policies, or remove their access, these changes are automatically synced to Oblique. If connected in a read-write mode, Oblique can also make those changes for you.

You can add multiple Cloudflare accounts to Oblique. These function as separate integrations and are distinguished by their account name.

Oblique integrates with Cloudflare:

  • As a source for accounts
  • As a source for resources
  • As a source and destination for entitlements

From your Cloudflare account, Oblique syncs:

  • Members of the Cloudflare account, as Oblique accounts
  • Resource groups and user groups, as Oblique resources
  • Policies and user group membership, as Oblique entitlements
  • Permission groups, as Oblique roles

Cloudflare accounts are automatically matched to Oblique users based on email.

  • Cloudflare resource groups
  • Cloudflare user groups

In Cloudflare, a policy is used to grant a member or the members of a user group access to a resource group. Oblique reads these policies as entitlements, and reflects both direct access for members and indirect access through user groups as entitlements in Oblique.

The Oblique Cloudflare integration supports information on roles, as defined in Cloudflare, which are its permission groups. An entitlement for a resource group can be for one or more roles. There is no role for being a member of a user group.

The Oblique Cloudflare integration requests the following scopes for your Cloudflare account:

Cloudflare scopeWhat Oblique uses it for
account-settings.readRead the account, its user groups, resource groups, and permission groups
memberships.readRead the account’s members and the policies attached to them
account-settings.writeChange a user group’s policies and its members (for a read-write integration)
memberships.writeChange the policies attached to a member (for a read-write integration)
offline_accessMaintain the connection without an administrator signing in again
You must be an admin to add an integration.

You connect a Cloudflare account to Oblique by signing in to Cloudflare as a Super Administrator and approving the access Oblique asks for.

To add a Cloudflare integration, navigate to the Integrations page:

  1. Select Add integration.
  2. Select Cloudflare.
  3. Under Access mode, select Read-write to let Oblique manage access in Cloudflare, or Read-only to only let Oblique read it.
  4. Select Connect Cloudflare.
  5. Sign in to Cloudflare as a Super Administrator and approve the access Oblique asks for.

Oblique will immediately start syncing the account’s members and groups.

Change Cloudflare integration’s authorizations

Section titled “Change Cloudflare integration’s authorizations”
You must be an admin to change an integration's authorizations.

To reconnect the Oblique Cloudflare integration, including to change the member it is tied to, from the integration’s detail page:

  1. Navigate to the Settings tab.
  2. Under Connection, select Reconnect.
  3. Sign in as a different Cloudflare member and approve the access Oblique asks for.

You can only reconnect the current account. To change the account, instead delete the integration and add another one.

To give a read-only integration write access, from the Settings tab, under Permissions, select Upgrade to read-write and approve the additional access Oblique asks for.

In read-write mode, the Oblique Cloudflare integration lets Oblique manage access in your Cloudflare account. This is done by updating user group membership and policies in Cloudflare.

You don’t need to do anything to sync the Cloudflare integration. Oblique will automatically and continuously sync changes from Cloudflare.

You must be an admin to remove an integration.

To remove a Cloudflare integration, from the integration’s detail page:

  1. Navigate to the Settings tab.
  2. At the bottom of the page, under Delete integration, select Delete integration….
  3. In the confirmation dialog, type the text to confirm, then select Delete integration.

This will immediately stop all syncing and remove all resources from the integration. Access that Oblique granted in Cloudflare stays as it is.