Shifting left at enterprise scale: how we manage Cloudflare with Infrastructure as Code
ID: 37317f8d-e9e4-56cb-b199-af4e85004dad
STIX ID: report--37317f8d-e9e4-56cb-b199-af4e85004dad
Feed Name: Cloudflare Blog
Cloudflare’s Customer Zero team outlines how they enforce a shift-left, policy-as-code operating model to securely manage hundreds of internal production accounts at scale, treating configurations as code with Terraform, Atlantis/GitLab CI/CD, and a secure tfstate-butler backend. A centralized security baseline is enforced via OPA/Rego checks that warn or deny changes during merge requests, with exceptions codified through a controlled process, and drift detection automating remediation workflows. They describe challenges onboarding legacy “clickops,” lowering IaC adoption barriers with cf-terraforming, and ensuring provider feature parity via an OpenAPI-generated v5 provider—ultimately improving consistency, governance, and engineering velocity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
