logo

Shifting left at enterprise scale: how we manage Cloudflare with Infrastructure as Code

ID: 37317f8d-e9e4-56cb-b199-af4e85004dad

STIX ID: report--37317f8d-e9e4-56cb-b199-af4e85004dad

Feed Name: Cloudflare Blog

Date Published: 2025-12-09

Date Updated: 2026-04-27

Author: Chase Catelli

...
...

Cloudflare’s Customer Zero team outlines how they enforce a shift-left, policy-as-code operating model to securely manage hundreds of internal production accounts at scale, treating configurations as code with Terraform, Atlantis/GitLab CI/CD, and a secure tfstate-butler backend. A centralized security baseline is enforced via OPA/Rego checks that warn or deny changes during merge requests, with exceptions codified through a controlled process, and drift detection automating remediation workflows. They describe challenges onboarding legacy “clickops,” lowering IaC adoption barriers with cf-terraforming, and ensuring provider feature parity via an OpenAPI-generated v5 provider—ultimately improving consistency, governance, and engineering velocity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.