cloudflare

Introducing the Cloudflare One stack- agent-powered deployment (opens in new tab)

Cloudflare’s One stack is a pair of agent skills designed to help organizations evaluate, migrate to, deploy, and operate Cloudflare One Zero Trust environments. It combines expert-curated guidance, migration logic, decision trees, and API tooling so agents can understand existing networks, recommend architectures, and safely implement changes. The goal is to reduce migrations that traditionally take months to a more guided and automated process.

The Challenge of Zero Trust Migration

  • Teams must first understand their existing environment, including:
    • Applications and connectivity requirements
    • Authentication and authorization policies
    • Traffic flows
    • Assumptions embedded in current security and routing rules
  • Agents can automate many security workflows, but lack organization-specific knowledge about network topology and vendor configurations.
  • Cloudflare’s stack supplies the structured context and prescriptive guidance needed for agents to work more effectively with security infrastructure.

What the Cloudflare One Stack Provides

  • The stack consists of two lightweight skill files:
    • cloudflare-one for general Cloudflare One planning, deployment, management, and troubleshooting
    • cloudflare-one-migration for translating and migrating from legacy SASE vendors
  • It incorporates knowledge gathered from Cloudflare employees with extensive customer deployment experience.
  • When combined with Cloudflare’s code mode MCP server, agents receive a typed interface to the Cloudflare API.
  • Agents can inspect live accounts and make changes through Cloudflare-recommended workflows rather than arbitrary API calls.

Covered Cloudflare One Capabilities

  • VPN replacement and remote access through Cloudflare Access
  • User, device, network, and data security through Cloudflare Gateway
  • Connectivity using Cloudflare Tunnel, Mesh, and WAN
  • Migration from vendors such as Zscaler and Palo Alto Networks
  • Network diagram interpretation and generation
  • Translation of concepts between competing SASE platforms
  • Troubleshooting and operations using Digital Experience Monitoring and automated rule recommendations

Guided Deployment and Migration

  • For VPN replacement, the agent can:
    • Inventory existing VPN applications
    • Determine the required connectivity model
    • Map applications to Access, Tunnel, or Mesh
    • Recommend a deployment sequence that reduces cutover disruption
    • Produce a configuration summary for human review
  • For Zscaler Private Access migrations, the agent can:
    • Convert application definitions into Cloudflare Access applications
    • Translate user groups and policies
    • Create equivalent resources through the Cloudflare API
    • Summarize completed work and identify items needing manual review
  • The migration logic is based on Cloudflare’s Descaler and Deskope programs, which have migrated enterprise customers from Zscaler and Netskope in hours rather than months.

Operations and Troubleshooting

  • The stack can recommend security rules based on live account traffic.
  • It can automatically migrate Zscaler Private Access applications into self-hosted Cloudflare Access applications.
  • Agents can investigate anomalies in secure web gateway HTTP logs and create rules to address user issues.
  • The Digital Experience Monitoring toolkit can report on user stability and help improve latency in important scenarios.

Cloudflare positions the One stack as a way to make Zero Trust deployment more accessible and repeatable. Organizations can use the skills with their existing agents, add internal context, and combine them with API tooling—but should still review generated plans and configurations before applying changes.