Introducing the Cloudflare One stack: agent-powered deployment
TL;DR · AI 摘要
Cloudflare One stack 是一种基于代理的工具集,可自动化 Zero Trust 环境的配置和部署,提升安全操作效率。
核心要点
- Cloudflare One stack 提供了预定义的技能,帮助代理自动配置 Zero Trust 环境。
- 该工具集整合了 Cloudflare 与数千客户合作的经验,提升迁移和部署效率。
- Cloudflare One stack 与 MCP 服务器结合,提供结构化的 API 接口,减少手动操作。
结构提纲
按章节快速跳转。
- §引言
采用 Zero Trust 架构面临挑战,Cloudflare One stack 提供自动化解决方案。
现有代理缺乏对组织网络拓扑和供应商配置的训练,导致安全操作效率低下。
Cloudflare One stack 是一组可与任何代理结合使用的技能,用于部署和管理 Zero Trust 环境。
该工具集包含迁移逻辑、规划工具和 Cloudflare API 的结构化接口。
思维导图
用一张图看清主题之间的关系。
查看大纲文本(无障碍 / 无 JS 友好)
- Cloudflare One stack
- 功能
- 自动化 Zero Trust 配置
- 集成迁移逻辑
- 结构化 API 接口
- 优势
- 提升部署效率
- 减少手动操作
- 基于经验的工具集
金句 / Highlights
值得收藏与分享的关键句。
Cloudflare One stack 是一种基于代理的工具集,可自动化 Zero Trust 环境的配置和部署。
该工具集整合了 Cloudflare 与数千客户合作的经验,提升迁移和部署效率。
Cloudflare One stack 与 MCP 服务器结合,提供结构化的 API 接口,减少手动操作。
Introducing the Cloudflare One stack: agent-powered deployment
2026-06-17
- AJ Gerstenhaber
- Abe Carryl
4 min read
This post is also available in
,
Polski
and
Português
.
Adopting or migrating to a Zero Trust network architecture can be a daunting task. Before a single policy changes, teams have to recall how their network is actually built: which applications exist, their authentication and authorization constructs, how traffic flows between them, and any assumptions the current architecture makes. This hands-on process requires practitioners to decode the intent behind every security and routing policy in place.
Today, weâre releasing the Cloudflare One stack, a set of skills you give to your agent to configure, deploy, and manage your Zero Trust environment for you. This toolkit is designed to help automate the process of learning an entirely new security suite and mapping your existing one into Cloudflare.
Cloudflare has worked with thousands of customers through exactly this process. That repetition built expertise on where migrations stall, what questions come up every time, and what it takes to move forward. The Cloudflare One stack packages that expertise and makes it more accessible than ever.Â
The agent gap in network security
Teams are already using agents to write code, triage alerts, and automate workflows. Organizations are increasingly asking for Cloudflare-provided tooling to help agents execute on security workflows. On their own, agents are not trained on the nuances of an organization's specific network topology or vendor configurations.
By providing prescriptive and authoritative guidance, organizations can layer this context into their existing toolkit to make better use of the security products they are already deploying.
Cloudflare has long been the easiest-to-deploy SASE vendor in the market. The stack extends that philosophy to agents: it gives them the context, tools, and structured reasoning they need to operate on your security infrastructure.
What is the Cloudflare One stack?
The Cloudflare One stack is a collection of skills that can be used with any agent. As with any skill , you can use them standalone, layer in your own context, or build tooling on top. It was purpose-built to help security practitioners across the entire lifecycle of evaluating, deploying, and managing Cloudflare One .
The stack was built by synthesizing hand-curated knowledge from employees with tens of thousands of hours of experience working with customers on Cloudflare One products. It contains tools for planning, managing, and implementing your user and agent security infrastructure on Cloudflare. It also contains handpicked logic for migrating from legacy vendors like Zscaler and Palo Alto Networks.
When used in conjunction with the Cloudflare code mode MCP server , the stack gives agents a typed interface to the Cloudflare API. Agents can query your live account, inspect configurations, and make changes through a curated set of Cloudflare-recommended workflows rather than ad-hoc API calls.
Whatâs in the stack?
The Cloudflare One stack ships as two lightweight skill files: cloudflare-one and cloudflare-one-migration. Together they cover migrating to, building an implementation for, managing, and troubleshooting your Cloudflare One deployment:
- Remote access and VPN replacement with Cloudflare Access
- User, network, device, and data security with Cloudflare Gateway
- Connectivity with Cloudflare Tunnel, Cloudflare Mesh, and Cloudflare WAN
- Migration guidance with explicit detail for moving from other SASE vendors
- Network diagram interpretation and generation , so you can visualize proposed changes to your network in a way that is easy for you and your team to understand
- Vendor concept translation , which maps concepts between SASE vendors to reduce the barrier to evaluating and switching providers
- Troubleshooting and operations , with the Digital Experience Monitoring (DEX) toolkit and automated rule recommendations
How it works
The stack is available in the Cloudflare Skills repository. Each skill file contains structured knowledge, decision trees, and tool definitions that agents load automatically when the context matches. Give this to your agent and let it help you set up, configure, and manage your Zero Trust environment:
The cloudflare-one skill covers general product guidance. For example, if you ask an agent for the best way to replace your VPN infrastructure with Cloudflare Tunnel or Cloudflare Mesh, the skill knows how to:
- Inventory your existing VPN applications and identify which connectivity model each requires
- Map each application to the appropriate Cloudflare primitive â self-hosted Access application, Tunnel-connected service, or Mesh-connected network segment
- Generate a recommended deployment sequence that minimizes disruption during cutover
- Produce a configuration summary your team can review before making any changes
The cloudflare-one-migration skill covers vendor-to-vendor translation. For example, if you ask an agent to migrate your Zscaler Private Access applications to Cloudflare Access, the skill knows how to:
- Map Zscaler application definitions to Cloudflare Access application definitions
- Transform Zscaler user groups and policies into Cloudflare Access policies
- Use the Cloudflare API to create the equivalent resources in your account
- Generate a summary of what was migrated and what requires manual review
The migration logic in the stack is the same logic used in Cloudflare's Descaler and Deskope programs. Those programs have already moved enterprise customers from Zscaler and Netskope to Cloudflare One in hours rather than months. The stack makes that capability available to any customer or partner, at any time, without waiting for a scheduled engagement.
More ways to use the stack
The Cloudflare One stack can also:
- Recommend security rules based on traffic seen in your live account
- Automatically migrate your existing Zscaler Private Access applications into self-hosted Cloudflare Access applications
- Investigate anomalies in your secure web gateway HTTP logs and build rules to resolve issues users are seeing
- Report on user stability with the DEX toolkit and take actions to improve user latency in key scenarios
Whether you are loading the skill from an agent or building custom tooling on top, the Cloudflare One stack handles all of these use cases and more.
For partners, too
While this simplifies ongoing management for customers who have already adopted the Cloudflare One product suite, it is also a tool for the Cloudflare partner network. Partners can use it to help their customers deploy faster, manage more effectively, troubleshoot with increased accuracy, and drive issues to resolution.
What's next
You can start using the Cloudflare One stack today. To get the most out of the stack, pair it with the Cloudflare code mode MCP server . The MCP server gives your agent live access to the Cloudflare API through a single, compressed interface that keeps authentication credentials out of the model context.Â
The Cloudflare One stack will continue to expand as Cloudflare One products evolve. New skills for additional migration sources and more advanced troubleshooting workflows are already in development.
As we learn more about how customers and partners utilize these skills files, we plan to build more robust tooling around these skills. If you are a customer or partner and want to share feedback on what the stack should handle next, reach out through your account team or open an issue in the repository.
[if astro]>server-island-start<![endif]
Cloudflare One
Zero Trust
Agents