Cloudflare control room for your whole domain portfolio

By General Input

See every domain's security and certificate settings on one screen, spot the ones that drift from your house standard, and fix them in bulk.

Integrations

  • Cloudflare
  • Slack Bot

Type

App

Categories

  • Engineering
  • Operations

Build me a Cloudflare domain portfolio control room: one screen that lists every zone my Cloudflare connection can see, so I stop clicking through domains one at a time in the Cloudflare dashboard. This is used by an agency or an internal IT team managing dozens of domains, so everything should be built around reviewing and fixing many zones at once rather than one zone at a time.

The main view is a portfolio grid, one row per zone. Populate it with List Zones, and use Get Zone Details for the per zone plan, status and nameservers. Then enrich each row with the security and performance settings from List All Zone Settings (SSL/TLS mode, Always Use HTTPS, minimum TLS version, Brotli, security level), Bot Management state from List Bot Management Settings, DNSSEC state from Get DNSSEC, and certificate health from List Certificate Packs plus Get SSL Verification so that expiring or stuck certificates show up as their own column. The grid must be sortable and filterable by drift severity, by plan, and by certificate expiry date, because the whole point is to triage the portfolio quickly.

Let me save a house standard baseline inside the app and edit it there. It is a set of expected setting values, for example SSL mode Full strict, Always Use HTTPS on, minimum TLS version 1.2, and DNSSEC enabled. Persist the baseline in the app so it survives reloads and is shared by the team, and let me change which settings are part of it. Every zone row shows a drift badge that lists exactly which settings deviate from the baseline, with a severity so I can sort the worst offenders to the top.

Each zone has a drill-in page showing all of its settings from List All Zone Settings with the baseline value next to the live value, the zone's DNS records from List DNS Records, its certificate packs with detail from Get Certificate Pack and outstanding validation records from Get SSL Verification, and recent activity from List Audit Logs so I can see who changed what and when.

Actions in the app. First, select one or many drifting zones and apply the baseline, using Update Multiple Zone Settings where several settings change on the same zone and Update Zone Setting for a single change. This must sit behind a preview that spells out, per zone, every setting that would change and its before and after value, and nothing runs until I confirm. Second, restart a stalled certificate with Restart Certificate Pack Validation. Third, purge a zone's cache with Purge Cache. Fourth, post a change summary to a Slack channel using the Slack Bot Send a Message operation, naming the zones touched and the settings changed.

Important behaviours to bake in. Settings that are not available on a zone's plan must be shown as not supported for that zone rather than being counted as drift or failing the apply, and a batch apply must skip them and carry on with the rest instead of aborting. Every apply is logged inside the app with who ran it, when, which zones were included, and the per zone result including partial failures, and that log is visible in the app. Cloudflare access is scoped to whatever zones the connection was granted, so an empty or unexpectedly short zone list should be explained in the UI as likely scoping rather than presented as an error or a bug.

Keep this app on the zone settings surface. Do not build ruleset editing into it, because updating a ruleset replaces its rules wholesale and that is not a safe bulk action for a portfolio tool. Handle pagination when listing zones and DNS records, and be considerate of rate limits when fanning out per zone reads across dozens of domains.

Related prompts

Explore more prompts
A brand asset library your marketing team actually searchesTurn Mailjet email clicks into ranked HubSpot follow-upsClean out the Looker dashboards and Looks nobody opensLiveKit live operations console for room moderationWake up dormant Keap leads with a researched reasonLiveChat coverage board for planning next week's shiftsPhone routing control panel for LiveKit voice agentsLinkedIn Ads budget pacing dashboard for every client accountGive your team Looker numbers without buying more seatsPause marketing emails to escalated customers, then restore them