---
title: "Cloudflare CDN and WAF in front of an origin"
description: "Put Cloudflare's CDN and WAF in front of an origin server"
url: "https://www.pulumi.com/dev/examples/cloudflare-ts-cdn-waf/"
image: "https://www.pulumi.com/assets/og/dev/examples/cloudflare-ts-cdn-waf.png"
---

# Cloudflare CDN and WAF in front of an origin

Put Cloudflare's CDN and WAF in front of an origin server

- Source on GitHub: https://github.com/pulumi/examples/tree/master/cloudflare-ts-cdn-waf
- Deploy with Pulumi: https://app.pulumi.com/new?template=https%3A%2F%2Fgithub.com%2Fpulumi%2Fexamples%2Ftree%2Fmaster%2Fcloudflare-ts-cdn-waf

## Get started with this example

This example lives in the [pulumi/examples](https://github.com/pulumi/examples/tree/master/cloudflare-ts-cdn-waf) repo. Pull down just this directory to follow along:

```bash
git clone --filter=blob:none --sparse https://github.com/pulumi/examples pulumi-examples
git -C pulumi-examples sparse-checkout set cloudflare-ts-cdn-waf
cd pulumi-examples/cloudflare-ts-cdn-waf
```

Puts Cloudflare in front of an existing origin server: a proxied DNS record routes traffic
through Cloudflare, a [cache ruleset](https://developers.cloudflare.com/cache/how-to/cache-rules/)
caches responses at the edge, and a [rate-limiting ruleset](https://developers.cloudflare.com/waf/rate-limiting-rules/)
protects the origin from abuse.

## Prerequisites

1. [Install Pulumi](https://www.pulumi.com/docs/install/)
1. [Install Node.js](https://www.pulumi.com/docs/iac/languages-sdks/javascript/)
1. A domain already added to Cloudflare as a [zone](https://developers.cloudflare.com/dns/zone-setups/).
1. Create a [Cloudflare API token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/)
   with DNS and Zone WAF edit permissions, and export it:

   ```bash
   export CLOUDFLARE_API_TOKEN=<your-token>
   ```

## Deploying the example

1.  Create a new stack:

    ```bash
    pulumi stack init dev
    ```

1.  Configure the zone and origin:

    ```bash
    pulumi config set zoneId <your-zone-id>
    pulumi config set origin origin.example.com
    ```

1.  Install dependencies and deploy:

    ```bash
    npm install
    pulumi up
    ```

1.  The proxied hostname is exported as `url`:

    ```bash
    pulumi stack output url
    ```

## Cleaning up

```bash
pulumi destroy
pulumi stack rm dev
```
