Overview
Cloudflare is a one-click connector that gives Rootly AI read access to your Cloudflare account across fourteen surfaces — from core Cloudflare (DNS, Workers, Zero Trust) through Cloudflare’s observability and security products. Sign in once through Cloudflare’s authorization screen and every enabled surface is available to Rootly AI during investigations. The Rootly setup asks for a Connection name, then sends you to Cloudflare for authorization. There are no Cloudflare credential fields to fill in; Rootly AI queries the surfaces the authorizing Cloudflare user has permission to see. Rootly passes through the available tools from Cloudflare’s MCP servers, but requests read-scoped OAuth grants for the Cloudflare surfaces it connects. The connected user’s Cloudflare roles and those OAuth scopes determine which calls succeed; Rootly does not apply a separate tool-name allowlist to this connector.You do not need to enable every surface. Cloudflare gates each product behind its own permissions — Rootly AI will only be able to read from surfaces the connecting user (and your Cloudflare plan) actually has access to.
Before You Start
- A Cloudflare account with permission to authorize third-party OAuth apps.
- Roles on the surfaces you want available. The connecting Cloudflare user’s account roles determine what Rootly AI can see — for example, without CASB permissions the Cloudflare CASB surface won’t return data even though the connector is technically enabled.
Setup
Open AI SRE → Atlas → Connectors (AI & Agents → Connectors if your sidebar doesn’t have an AI SRE item) and click Connect on the Cloudflare card. Enter a Connection name, then sign in to Cloudflare and authorize Rootly AI. When the flow completes, the card flips to Connected and Rootly AI can query every surface your Cloudflare account exposes.Surfaces Rootly AI Can Read
Cloudflare exposes fourteen distinct surfaces through this connector. Each one gives Rootly AI a different kind of context during an investigation.Infrastructure
Observability & Security
During an Incident
“An audit log shows a config change during the incident window.” Rootly AI queries Cloudflare’s audit log for changes during the incident window — DNS record edits, Zero Trust policy modifications, Workers deploys — and surfaces them in the investigation output. When the incident correlates with a Cloudflare config change, responders see the exact change, who made it, and when, without leaving Rootly.Best Practices
- Authorize with an account that already has broad Cloudflare permissions. Rootly AI can only see what the connecting user can see. A restricted user makes the connector superficially “Connected” but starves the underlying queries.
- Use it alongside code, deployment, and observability connectors. Cloudflare tells you what’s happening at the edge; pair it with GitHub for recent source changes, your deployment provider for rollout timing, and Datadog or Sentry for the origin.
- Prefer Radar for organization-wide traffic questions. For customer-specific traffic, Cloudflare Observability and DNS Analytics give better fidelity.
- Rotate the connection if a Cloudflare admin’s permissions change. Disconnect and reconnect with the new user’s account so Rootly AI sees the updated scope.
Troubleshooting
Some Cloudflare surfaces return no data even though the card shows Connected
Some Cloudflare surfaces return no data even though the card shows Connected
Cloudflare gates each surface behind its own product permission (CASB, Zero Trust, Radar Business, etc.). If the connecting user’s Cloudflare account doesn’t have access to a surface — either by role or by plan tier — Rootly AI can’t read from it either. Grant the user access on the Cloudflare side, then disconnect and reconnect so the OAuth grant refreshes.
Rootly AI cites the wrong Cloudflare zone
Rootly AI cites the wrong Cloudflare zone
Confirm the connecting user has access to the zone in question. Multi-zone Cloudflare accounts route by permission, so a user restricted to one zone will only surface data from that zone.
Disconnected on the Cloudflare side
Disconnected on the Cloudflare side
If a Cloudflare admin revokes the OAuth grant from Cloudflare’s side, Rootly AI’s card still shows Connected but every query fails. Reconnect from Rootly to re-authorize.
Frequently Asked Questions
Do I have to connect each Cloudflare surface individually?
Do I have to connect each Cloudflare surface individually?
No. A single Cloudflare OAuth authorization covers all fourteen surfaces. Which surfaces actually return data depends on the connecting user’s Cloudflare permissions and your plan.
Does Rootly AI store Cloudflare data?
Does Rootly AI store Cloudflare data?
Rootly does not maintain a persistent copy of Cloudflare data — queries run at investigation time and the response is used in reasoning only. Query results do appear in the LLM traces Rootly logs for quality monitoring, as with every tool call Rootly AI makes. See Data Privacy for Rootly AI for the retention boundary.
Can I limit which Cloudflare surfaces Rootly AI can read from?
Can I limit which Cloudflare surfaces Rootly AI can read from?
Yes — indirectly, through the connecting user’s Cloudflare roles. Rootly AI cannot read a surface that the authorizing user doesn’t have access to in Cloudflare.
Does the Cloudflare connector cover Cloudflare Pages?
Does the Cloudflare connector cover Cloudflare Pages?
Not directly today. The current fourteen surfaces cover DNS, Workers, Zero Trust, and Cloudflare’s observability + security products. Ask support if Pages coverage is on your roadmap.
Related Pages
Connectors Overview
All connectors and how they fit together.
AWS
The other infrastructure connector.
Data Privacy for Rootly AI
What Rootly AI sees, retention, and model training controls.