Skip to content

Cloudflare One — N1 Network Architecture

Cloudflare One — N1 Network Architecture

Section titled “Cloudflare One — N1 Network Architecture”

Snapshot 2026-06-06 · account 70dc91c5… · free tier · IaC-managed

Every Cloudflare One component N1 currently runs (org n1research), every component we plan to add, every tunnel and every Access app, and every gateway/posture/identity decision in one place. All nodes are clickable — the side panel explains what each component does, its current state, the planned change, free-tier availability, and the Terraform file that manages it (or a note that it isn’t IaC-managed yet).

Every human operator at N1 represents a potential security risk. Every control on this diagram applies org-wide. There is no tiering, no separate Access groups by role, no softer bar for BYOD. Per-OS posture rules are a technical decomposition of one org-wide policy, not a per-population split.

The setup is now managed as code in the cloudflare-one Terraform and applied.

Live & enforcing:

  • The org-wide DNS security-category block
  • The incident-C2 canary
  • The locked device profile
  • The split-tunnel flip to EXCLUDE

Deliberately in monitoring mode: All 10 device-posture rules and Gateway antivirus are deployed but intentionally bound to nothing this round — they run visibility-only to build a compliance baseline (how many devices already pass disk-encryption, OS-floor, firewall, AV). Enforcement (binding them in Access require{}) is a separate, later decision — not planned yet. (TLS-decrypt also stays off by decision.)

Still to do:

  • Finish session tiering
  • Rotate service tokens to 90 days
  • Add the org group and break-glass policy
  • Enforcing today: Green background
  • Planned (IaC drafted or vetted): Yellow background
  • Open gap (live config): Red background
  • Excluded by decision: Gray dashed border
  • Live data path: Solid line
  • Planned policy / monitor-only: Dashed line
  • Currently bypasses (gap): Red line

All devices run the WARP client, where DNS, posture, and tunneling decisions are made on the endpoint.

Device types:

  • Linux endpoint — WARP-enrolled, posture rules (kernel floor, LUKS attestation)
  • macOS endpoint — WARP-enrolled, FileVault & firewall posture
  • Windows endpoint — WARP-enrolled, BitLocker & firewall posture

WARP client components:

  • Service mode: “warp” (full tunnel mode)
  • Split tunnel: EXCLUDE mode (5 private/link-local ranges excluded)
  • Device profile: locked (allowed_to_leave=false, switch_locked=true)
  • Posture engine: monitoring-only baseline collection

Identity:

  • Google IdP (n1.healthcare) — sole identity provider
  • Audit Logs v2 — all-plan, 18-month retention

Free tier infrastructure for identity decisions, gateway filtering, and posture evaluation.

  • 13 Access apps — all with 24h sessions, none require posture yet
  • Access policies — plan to tier sessions (1h–8h) and add posture requirements
  • Access groups — none defined; plan to add ONE org-wide group (N1-Google-Users)
  • Break-glass policy — planned for phase 0, scoped to admin identity only
  • Service tokens (3) — expire 2027-06; plan 90-day rotation
  • Canary — DNS block rule for incident C2 host, single-user scope

Gateway (DNS · Network · HTTP filtering)

Section titled “Gateway (DNS · Network · HTTP filtering)”

DNS filter:

  • 2 override rules (staging DB / RDS routing)
  • Planned: security-category block (11 categories: malware, C2, phishing, etc.) — LIVE

DNS security-category block:

  • 11 IDs live: 68, 80, 83, 117, 131, 134, 151, 153, 175, 176, 178
  • Blocks malware, C2, phishing, cryptomining, DGA, and more

Network policy (L4):

  • 0 rules defined; gap since split-tunnel is now EXCLUDE

HTTP policy (L7):

  • 0 rules defined; will become effective once EXCLUDE flips

Activity logging:

  • Currently OFF; plan to enable in phase 0 (free feature)

TLS decryption:

  • Explicitly OFF by decision (no HIPAA BAA yet)

Antivirus / file scanning:

  • Enabled but inert (requires TLS decrypt)

DLP profiles:

  • 2 predefined profiles exist but unused

Gateway Lists:

  • None defined; planned for phase 2 (do-not-inspect allowlist)

All rules deployed but visibility-only (bound to no Access apps):

  • Require Gateway — closes consumer-WARP loophole, all OS
  • disk_encryption — Linux (LUKS), macOS (FileVault), Windows (BitLocker)
  • os_version — kernel/build floor floors only, never distro pins
  • firewall — macOS & Windows only

Outbound-only connectors; each origin behind an Access app + (planned) device posture.

Healthy tunnels:

  • EKS Production
  • EKS Staging
  • EKS AI Cluster
  • Signoz (observability)
  • N1 Local Dev
  • N1 NexAI

Down:

  • N1 Langfuse — connector dead or retired (open question)
  • Public web — DNS filtered via Gateway; HTTP/L4 filtering planned
  • LLM providers — via LiteLLM, DNS filtered

Out of scope / excluded:

  • HIPAA BAA (Enterprise + separate paperwork)
  • Logpush (Enterprise-only)
  • Email Security / Area 1 (Enterprise add-on)
  • Paid MDM/EDR (by decision)
  • AI Gateway DLP (by decision)

Live audit snapshot (2026-06-06, read-only)

Section titled “Live audit snapshot (2026-06-06, read-only)”
Surface State
Identity providers 1 — Google (n1.healthcare)
Access apps 13 — all session=24h, none require posture
Access groups 0
Service tokens 3 — Signoz×2, Automated Testing (expire 2027-06)
Gateway rules 2 — both DNS override; no Block
Gateway lists 0
Gateway TLS decryption OFF
Gateway activity log OFF
Antivirus unconfigured
Device profiles 1 default, service_mode=warp, allowed_to_leave=true
Split tunnel EXCLUDE · 5 private/link-local ranges excluded
Device posture rules 1 — warp only (no disk/OS/firewall)
DLP profiles 2 — unreferenced
Tunnels 7 — 6 healthy, 1 DOWN (N1 Langfuse)
Capability Free? Notes
Up to 50 seats YES Well within N1’s operator count
Access apps + policies YES Allow/Block/Bypass/Service-Auth
Gateway DNS policies + security categories YES All 16 categories (C2, Malware, Phishing)
Gateway Network + HTTP policies YES Limited rule counts; otherwise full
TLS decryption YES We choose to leave OFF (no BAA)
WARP-native posture (disk/OS/firewall/file/cert/UUID) YES All checks free; gated only by OS support
cloudflared tunnels YES Unlimited; what we already use ×7
Audit Logs v2 YES All-plan · 18-month retention
DEX synthetic tests / remote captures YES 10 tests · 100 captures/day (free cap)
CASB — connection count YES 2 free integrations · detailed findings Enterprise
DLP profiles (predefined) YES 2 already exist · enforcement needs TLS-decrypt
Logpush (Gateway / Access events) NO Enterprise-only
Email Security (Area 1) NO Enterprise add-on
Browser Isolation (full) LIMITED Free has narrow isolation; full is Pay-as-you-go
User Risk Score NO Enterprise-only
SCIM for Google Workspace N/A Unsupported at any tier — manual revoke ad-hoc
HIPAA BAA N/A Enterprise + separate paperwork — not this round

What changes:

  • DNS security-category block (org-wide) · canary (single-user)
  • Activity log ON · sessions 1h–8h
  • Break-glass Allow · Access group N1-Google-Users
  • Service-token rotation (90d+alerts, scope-per-app)
  • allowed_to_leave=false

Where: Mostly drafted in cloudflare-one/terraform/; remainder is next-up

What changes:

  • Posture rules deployed and running monitoring-only (disk_encryption, os_version, firewall, AV) to build a compliance baseline
  • DNS new/newly-seen domains in monitor mode
  • Google Workspace → CASB
  • DEX synthetic test on api.n1.healthcare

Where: Applied in TF (visibility-only)

What changes:

  • Build do-not-inspect allowlist
  • Flip split tunnel INCLUDE → EXCLUDE in monitor mode
  • Client notifications before any L4 block
  • Enable HTTP category/domain block + L4 egress (block :25, SSH-to-internal-only)

Where: Sequenced; INCLUDE→EXCLUDE flip is the load-bearing step

Every control is proven by making it fire and observing it, not by trusting docs.

Default test:

  1. Block the target (DNS category, posture rule, L4 port) scoped to a single identity
  2. Resolve / connect from that identity’s device BEFORE apply: real response
  3. Apply → resolve / connect again: Gateway block response (DNS: 0.0.0.0/::, HTTP: block page)
  4. The difference is the proof. Then expand scope.

For posture: The rules run monitoring-only across the fleet, counting how many devices pass each check by OS — that is the deliberate stage we are in now. Binding require{} to actually enforce is a separate, later decision, not planned this round. When enforcement does come, anyone whose machine can’t meet the bar loses access — the bar won’t bend per person.

Built from cloudflare-one/results/cf-zt-audit.json + Cloudflare One developer docs (verified 2026-06-06) + the locked plan in cloudflare-one/docs/CLOUDFLARE-ONE-PLAN.md. IaC under ~/n1-repos/n1-security/cloudflare-one/terraform/.