Self-hosted Cloudflare operations

See the fleet. Define intent. Review every change.

Cloudflare Fleet turns configuration from many zones into one comparable matrix, then keeps every supported mutation behind a fresh read, an exact plan, human confirmation, and scoped verification.

TOKEN STAYS SERVER-SIDE READ-ONLY BY DEFAULT NO THIRD-PARTY CONTROL PLANE

One operational workspace

Start with posture, move into evidence

Fleet opens with a decision-oriented review surface, then lets operators move from differences to expected state and finally to supported change paths.

Cloudflare Fleet dashboard showing a synthetic example fleet, fleet intent status, review cards, and automated workflows.
Generated from the deterministic local fixture. Every hostname uses the reserved .example namespace; no live account data is present.

Designed for careful operators

Visibility without surrendering control

01 / COMPARE

Normalize the fleet

Cloudflare resource shapes become stable facets with explicit identity and equality rules, so genuine differences stand apart from server metadata.

02 / GOVERN

Define expected state

Presence and value intent compose across all zones and fixed scopes. Exact acknowledgements stay tied to one observed value, while supported drift exposes a direct alignment review.

03 / CHANGE

Plan before execution

Cell, row, policy, and workflow changes reread their dependencies, produce endpoint-specific plans, save a pending journal entry, execute in order, and verify the smallest authoritative surface.

04 / ASSIST

Give agents bounded tools

The installed CLI and local stdio MCP server expose redacted first-run diagnosis, audit, complete intent persistence, intent alignment, bounded direct changes, activity, and guarded undo through exact plan digests, fresh replanning, and confirmation-gated writes instead of a raw API passthrough.

From intent to action

Review a complete convergence plan

Exact and forbidden intent can produce first-class alignment actions on a policy, matrix row, or individual drifting cell. Supported adapters include zone settings, Email Routing subaddressing and wizard preferences, DNS, DNSSEC, API-managed routes, redirects, and rules. Fleet refreshes the latest intent and the relevant facet across the account, then blocks the whole selected scope if any drift cell is conflicting, ambiguous, or unsupported.

Cloudflare Fleet intent alignment confirmation for a synthetic zone setting, showing the target zone, live current and desired values, API endpoint, method, and review acknowledgement.
The synthetic fleet's row action enters the same confirmation, verification, activity, and guarded undo flow used by direct edits.
Cloudflare Fleet matrix showing a disabled intent alignment action with the exact read-only Email Routing status reason visible at row and cell scope.
A disabled control never hides its explanation in a tooltip. The exact blocker remains visible beside the affected action.

Deploy it your way

One interface, two protected transports

The browser application is shared. Run it behind Cloudflare Access and a Worker for durable anywhere access, or launch it through an ephemeral loopback broker on macOS. Credentials stay in the backend either way.

Architecture diagram comparing the Access-protected Worker path with the local loopback broker path.

The complete operating model

Hosted continuity, local independence

CLOUDFLARE WORKER

Access-protected and durable

  • Cloudflare Access gates every asset and API request
  • The Worker validates the JWT audience and issuer again
  • D1 stores intent, activity, and inventory snapshots
  • A constrained proxy keeps the API token out of the browser

LOCAL LOOPBACK

Ephemeral and full-featured

  • A random session capability protects a loopback-only broker
  • Ignored local files hold fleet state and policy
  • The regular browser profile needs no weakened security flags
  • Local capabilities remain available without hosted infrastructure

Desktop depth, mobile reach

The same controls adapt to the viewport

Intent management remains a focused workspace, while narrow screens expose the complete filter model without shrinking the configuration matrix into an unreadable card list.

Fleet intent workspace with policies, groups, coverage, acknowledgements, and an evaluation summary.
Saving intent remains descriptive; the separate Review alignment action starts a fresh, confirmable Cloudflare plan.
Cloudflare Fleet responsive matrix controls and the first synthetic zone columns on a phone-sized viewport.
Responsive controls retain the full matrix model.

Start safely

Install, diagnose, and audit before enabling writes.

The local dashboard and generated hosted configuration both default to read-only.

Open getting started