Harden Linux and Windows origins so HTTP(S) traffic only comes from Cloudflare IP ranges, with nftables, Windows Firewall, and safe apply/update/revert flows.
-
Updated
Jan 28, 2026 - Shell
Harden Linux and Windows origins so HTTP(S) traffic only comes from Cloudflare IP ranges, with nftables, Windows Firewall, and safe apply/update/revert flows.
Additively synchronize a UFW allowlist with Cloudflare's published IP ranges, with input validation and dry-run support.
Add a description, image, and links to the origin-security topic page so that developers can more easily learn about it.
To associate your repository with the origin-security topic, visit your repo's landing page and select "manage topics."