DashboardSign inStart your trial

CloudflareCloudflare
01Integration field card

Cloudflare Automation, DNS & Firewall Approvals

Run Cloudflare on autopilot. Keep the veto.

20 actions

A misconfigured DNS record or WAF rule fires before you see it, and the fallout lands in your inbox. Rills proposes every Cloudflare change; you approve before it goes out.

Try the approval demo

Interactive. No signup. 14 days free · approvals always free.

Powered by Composio
02. The trust layer

Most automation fires first, asks later. Rills shows you the change before it ships.

Every consequential other action from Cloudflare arrives on your phone first. Approve in seconds. Decline without explaining yourself. Workflows wait, paused at zero cost, until you decide.

Queue 3

CLOUDFLARE · WAF LIST UPDATE
82

Add 14 IPs to WAF blocklist "bad-actors-2024"?

14 IPs flagged across 3 zones in past 6h

Same pattern as last month's scraper block

No overlap with known customer IP ranges

SWIPE → APPROVE
Illustrative. Your real proposals match your data and your approval history.
  1. Free to wait. Free to think.

    Approvals and logic don't cost a credit. Pause a workflow for three hours or three weeks. The price is the same: zero. You only pay when something real happens: an AI call, an outbound action.

  2. Approve from your phone in five seconds.

    Swipe right when you're sure. Decline when you're not. Between meetings, mid-coffee, on the train. No dashboard to babysit, no inbox triage, and no surprise send you find out about after it's already out the door.

  3. Routine cases graduate themselves.

    Every approval feeds a confidence score for that exact workflow shape. The obvious cases (the ones you've green-lit fifty times) start running on their own. The judgment calls still come to you.

03. Overview

About Cloudflare automation

A wrong DNS record update or an accidental WAF list deletion can break your site for everyone, and you won't know until someone texts you. Cloudflare automation is useful right up until it isn't, and the consequences aren't soft.

When Cloudflare runs unsupervised

Every operation that touches your network config is a live wire. One bad change ships quietly and the blast radius shows up in downtime, blocked users, or exposed traffic.

  • Deleting a DNS record removes routing for a subdomain your checkout or email delivery depends on, and traffic just stops.
  • Creating or deleting a WAF list can block legitimate users at scale before anyone notices the pattern.
  • Updating a tunnel configuration breaks internal access for your whole team, not just one person.
  • Updating a zone with wrong settings changes how all traffic into that domain is handled, across every service sitting behind it.
  • Deleting a zone removes the entire configuration surface, with no soft undo.

What Rills does inside Cloudflare

Rills sits between your automation logic and the Cloudflare operations that actually change things. Whether the task is updating a DNS record, modifying a WAF list, or reconfiguring a tunnel, nothing goes through until you've seen the proposal and approved Cloudflare changes explicitly.

The DNS record still gets updated; you just read what it will say before it goes live.

Why Cloudflare has no triggers and how Rills fills the gap

Cloudflare doesn't emit events that kick off workflows on their own, so Rills uses scheduled checks and upstream signals to surface the right proposals at the right time.

  • Scheduled DNS audits: Rills polls List DNS Records on a schedule and flags records that look stale, duplicated, or inconsistent with your current infrastructure.
  • WAF list reviews: Rills queues a List WAF Lists check after upstream signals (a new IP block list, a security incident report) and proposes Create WAF List or Update WAF List actions for your approval.
  • Tunnel health checks: Rills runs List Tunnels on a cadence and surfaces Update Tunnel Configuration proposals when config drift is detected against a known baseline.
  • Zone change proposals: changes to zone settings proposed by other tools or team members queue as Update Zone actions, held until you approve them rather than applied immediately.
04. Actions

What Rills can do in Cloudflare

4 of 20 actions across reads, writes, and updates.

  1. 01

    Create DNS record

    Add a new DNS record to your domain, such as pointing subdomains to servers or setting up email routing without manual configuration.

  2. 02

    List DNS records

    Retrieve and search DNS records within your Cloudflare zone to find record IDs and details for management purposes. Useful for identifying existing records before making updates or deletions.

  3. 03

    List Zones

    Retrieve a list of all domains (zones) you're managing through Cloudflare in your account, with support for searching, filtering, and pagination to easily find specific domains.

  4. 04

    Update DNS record

    Modify existing DNS records in your Cloudflare zone by updating specific fields like IP addresses, CNAME targets, or TTL values without affecting other record settings.

05. FAQ

Common questions about Cloudflare automation

How do I automate Cloudflare DNS record changes without breaking things?

Rills proposes the DNS change, whether it's creating, updating, or deleting a record, and waits for your approval before anything touches your zone. You review the exact record it plans to write, then approve or reject it. Nothing ships to Cloudflare until you say so.

Can I get mobile approvals before Cloudflare WAF list updates go live?

Yes. When Rills queues a WAF list create, update, or delete, you get an approval request on your phone. You see what it plans to change before it fires. No dashboard login required. You swipe to approve or block it from wherever you are.

How do I automate Cloudflare firewall rules for my site safely?

Rills can list your current firewall rules and propose changes based on logic you define. Before any rule goes live, you approve it from your phone. If something looks wrong, you reject it. Your Cloudflare configuration does not change without your explicit sign-off.

Can Rills automate Cloudflare tunnel configuration updates?

Rills can read your tunnel list and propose configuration updates when conditions you set are met. The proposed change sits in your approval queue until you review it. Nothing updates in Cloudflare until you approve, so a bad config does not silently break your tunnel.

How is Rills different from Zapier for Cloudflare automation?

Zapier runs actions automatically the moment a trigger fires. Rills holds every proposed Cloudflare action in a queue and waits for your approval before it executes. For infrastructure changes like DNS records, WAF lists, and firewall rules, that pause before execution is the point. You keep the veto.

Why use Rills instead of a script for Cloudflare zone and DNS management?

A script fires immediately and silently. Rills proposes the action, shows you exactly what it plans to do to your zone or DNS record, and waits for your call. If the logic produces something unexpected, you catch it before it ships, not after your site goes down.

Does Rills support Cloudflare webhooks or event triggers?

Rills currently connects to Cloudflare through direct operations: creating zones, managing DNS records, updating WAF lists, listing tunnels, and more. Inbound Cloudflare event triggers are not yet supported, but you can kick off Cloudflare actions from triggers in other connected tools.

How much does Rills cost for Cloudflare automation?

Approvals and workflow logic are free. You only pay when Rills executes a real action, like an AI call or an external API operation against Cloudflare. Reviewing a proposed DNS change or WAF list update in your approval queue costs nothing.

06. NEXT MOVE

Approve every Cloudflare change before it ships.

14 days free. No credit card. About 90 seconds to your first proposal.