Minimal bash scripts to work with custom certificates for Cloudflare's authenticated origin pulls feature
-
Updated
Jul 18, 2025 - Shell
Minimal bash scripts to work with custom certificates for Cloudflare's authenticated origin pulls feature
A self-contained hardening script for Debian/Ubuntu/windows servers that only allows HTTP(S) traffic from Cloudflare's official IP ranges. It fetches Cloudflare's latest CIDR lists, writes nftables sets, and keeps the configuration transactional so you can safely apply, update, or roll back with a single command.
Add a description, image, and links to the authenticated-origin-pulls topic page so that developers can more easily learn about it.
To associate your repository with the authenticated-origin-pulls topic, visit your repo's landing page and select "manage topics."