Cloudflare
Connect
Polylane investigates and explains issues without ever changing anything in your account.
Connect Cloudflare from the terminal. Pass --help for the flags Cloudflare accepts, plus --no-browser for headless environments.
polylane cloud connect --provider cloudflareAccount-owned read-only API token.
Cloudflare connects with an account-owned, read-only API token. Polylane investigates and explains what it finds without ever changing anything in your account; when the fix is code, it arrives as a pull request for you to review. Your token is encrypted before it is stored, and the agent never sees it.
Setup
- Click Create read-only token above, or Create API token in the console's connection form. Either opens Cloudflare's account API token screen with every permission Polylane needs pre-selected.
- Select the account you want to connect. You must be a Super Administrator on that account to create an account-owned token.
- Review the pre-filled permissions, then click Continue to summary and Create Token.
- Copy the token and paste it back into Polylane.
- Polylane validates the token and starts syncing.
You must be on the Workers Paid plan for full resource discovery.
Permissions
The pre-configured link creates an account-owned token: a durable service principal that keeps working even if the person who created it leaves the account. Every permission is read-only, across the whole account:
- Developer Platform: Workers, KV, R2, D1, Queues, Pipelines, Hyperdrive, Durable Objects, Containers, Secrets Store, Artifacts, and more
- AI & Machine Learning: Workers AI, AI Gateway, AutoRAG, Vectorize, AI Search
- DNS & Zones: DNS, zone settings, registrar, DNS firewall
- Network Services: Load Balancing, Magic Transit/WAN, Spectrum, tunnels
- App Security: WAF, rulesets, DDoS, bot management, page rules, certificates
- Cache, Email, Media, Rules, Analytics & Logs
Nothing in the token can create, modify, or delete anything in your account: no deploys, no config changes, no rollbacks, no billing or API-token management. Remediation arrives as pull requests instead.
Disconnecting
Disconnect the account in Polylane, then revoke the API token from your Cloudflare dashboard under My Profile → API Tokens (or Manage Account → API Tokens for account-owned tokens).
Connect Cloudflare from a CI job or any other environment without a browser.
Connecting Cloudflare needs no browser: the same endpoint the console calls fits in a CI job. One authenticated POST creates the connection and starts the first sync.
Prerequisites
- A Polylane API key with the
cloud_accounts:writeandcloud_accounts:readscopes. See API keys and OAuth. - Your workspace ID, which starts with
ws_. Read it fromGET /v1/workspaceswith the same key. - A Cloudflare account-owned API token. The Create read-only token link above pre-selects every permission Polylane needs.
Create the connection
curl -X POST https://api.polylane.com/v1/cloud_accounts \
-H "x-api-key: $POLYLANE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"provider": "cloudflare",
"workspaceId": "ws_0abc123",
"token": "<cloudflare-api-token>",
"readOnly": true
}'
One call connects every Cloudflare account the token can reach, each as its own connection.
readOnlyrecords that the token was created read-only; leave it out (orfalse) for a token that can write.createMonitoringAlarms(optional, defaulttrue) controls the default Workers observability alerts.
The response lists what was connected, with the first sync already running. Trimmed to the two fields the rest of the flow reads:
{
"success": true,
"result": {
"provider": "cloudflare",
"accounts": [{ "id": "acc_34gky74ibc92h8t2efn8csrh", "status": "syncing" }],
"failures": []
}
}
An account that is already connected lands in failures instead of accounts, so repeating the call never duplicates a connection.
Wait for the first sync
Poll each returned account by its id until status reaches ready (new on registration, syncing while resources stream in):
until [ "$(curl -s "https://api.polylane.com/v1/cloud_accounts/$WORKSPACE_ID/$ACCOUNT_ID" \
-H "x-api-key: $POLYLANE_API_KEY" | jq -r '.result.status')" = "ready" ]; do
sleep 15
done
Give the loop a deadline so a failed connect fails the job instead of hanging it. Once the account is ready, its resources are in the topology and Polylane has started its first check.
Disconnect from the API
Deleting the connection stops every sync and check and deletes the credentials Polylane held. The call needs the cloud_accounts:delete scope:
curl -X DELETE "https://api.polylane.com/v1/cloud_accounts/$WORKSPACE_ID/$ACCOUNT_ID" \
-H "x-api-key: $POLYLANE_API_KEY"
Then revoke the Cloudflare credential on the provider side, as described under Disconnect below.
Disconnect
Disconnecting stops every sync and check and deletes the credentials Polylane held. Everything Polylane set up in Cloudflare is removed as well; nothing is left behind.
polylane cloud disconnect <id>Tools
14Operations agents can perform in threads.
Supported resources
47Resource types that show up in your infrastructure graph.