Skip to content
downpipes docs

What Cloudflare configuration is captured: surface reference

This is the reference list of every Cloudflare configuration surface the cf-config source captures. It is for an auditor or a self-hoster who needs the exact inventory rather than the narrative: which surfaces are in scope, whether each is zone-scoped or account-scoped, how each one restores, and which 60 re-apply in-band. For the credential model, the backup behaviour and the full restore workflow, read backing up and restoring your Cloudflare configuration.

The table below lists the same surfaces the backup adapter and the restore sink use.

The registry holds one set of 313 Cloudflare config surfaces. Of those, 60 auto-restore in-band, 228 have no write path and are backup-and-preview only, and 25 carry a writer that is off by default, so a default restore leaves them alone and reaches one only when the request names it. A default restore therefore writes back the 60 and none of the other 253. The restore tiers cut a different axis: idempotent 176, ordered 76 and re-provision 61. A surface auto-restores in-band only when it is one of the idempotent surfaces that also carries an in-band write path, so the 60 in-band surfaces are a subset of the 176 idempotent ones. The idempotent count is not a restore count: it is the number of surfaces that replay cleanly when applied, not the number downpipes applies.

How to read the table

Three columns carry the meaning, so here is what each one tells you.

ColumnWhat it means
ScopeWhether the surface reads at zone level (it needs a zone id, and an account-only downpipe skips it) or at account level (it always applies).
Restore tierHow the surface restores. Idempotent replays cleanly item by item; ordered needs dependency-ordered re-creation and id remapping; re-provision carries write-only values, so a restore can only emit a checklist.
In-bandYes when the engine re-applies the surface straight back into your live account through the console as part of a restore apply, with a live diff preview first. The other surfaces are captured and verified recoverable, but you re-apply them out of band, guided by the restore tier rather than a diff preview.

Restore tier is a property of the surface, not of a run

Every surface carries its tier in the registry, and the tier is surfaced in the restore plan. It tells you, before you confirm anything, whether an apply re-applies that surface for you or hands you a checklist. An idempotent tier never means a secret is recoverable: see the re-provision note at the foot of the table.

The full surface list

These are the 313 surfaces, grouped by the same categories the console uses for its per-surface selection screen. The In-band column marks the 60 surfaces that re-apply on a restore apply that names no scope. Of the other 253, 228 are backup-and-preview only and 25 carry an off-by-default writer that a request has to name before it runs.

DNS & core

SurfaceScopeRestore tierIn-band
DNS records (dns)zoneidempotentYes
DNS settings (dns-settings)zoneidempotentYes
Zone settings (zone-settings)zoneidempotentYes
Managed transform headers (managed-headers)zoneidempotentYes
URL normalization (url-normalization)zoneidempotentYes
Zone details (zone-entity)zonereprovisionNo
Zone hold (zone-hold)zoneidempotentNo
Zone environments (zone-environments)zoneidempotentNo
Secondary DNS ACLs (secondary-dns-acls)accountidempotentYes
Secondary DNS TSIG keys (secondary-dns-tsigs)accountreprovisionNo
Secondary DNS peers (secondary-dns-peers)accountorderedNo
Secondary (incoming) zone transfer config (secondary-dns-incoming)zoneorderedNo
Primary (outgoing) zone transfer config (secondary-dns-outgoing)zoneorderedNo
Account DNS settings (account-dns-settings)accountidempotentYes
DNSSEC configuration (dnssec)zoneorderedNo
Workers custom domains (workers-custom-domains)accountorderedNo
Web3 gateway hostnames (web3-hostnames)zoneidempotentNo
Regional hostnames (regional-hostnames)zoneidempotentNo
Account custom nameservers (account-custom-nameservers)accountidempotentNo
Zone custom nameserver usage (custom-nameserver-usage)zoneidempotentNo
Internal DNS Views (dns-internal-views)accountorderedNo
Google Tag Gateway config (google-tag-gateway)zoneidempotentNo
Registrar domains (registrar-domains)accountreprovisionNo
Registrar registrations (registrar-registrations)accountreprovisionNo
Zone setting: aegis (zone-setting-aegis)zoneidempotentNo
Zone setting: auto origin tls kex (zone-setting-auto-origin-tls-kex)zoneidempotentYes
Zone setting: csam scanner (zone-setting-csam-scanner)zoneidempotentNo
Zone setting: fonts (zone-setting-fonts)zoneidempotentYes
Zone setting: origin h2 max streams (zone-setting-origin-h2-max-streams)zoneidempotentNo
Zone setting: origin max http version (zone-setting-origin-max-http-version)zoneidempotentYes
Zone setting: origin tls compliance (zone-setting-origin-tls-compliance)zoneidempotentYes
Zone setting: speed brain (zone-setting-speed-brain)zoneidempotentYes
Zone setting: ssl automatic mode (zone-setting-ssl-automatic-mode)zoneidempotentYes
Zone setting: zaraz default (zone-setting-zaraz-default)zoneidempotentNo

Security & WAF

SurfaceScopeRestore tierIn-band
WAF & rulesets (zone) (rulesets)zoneidempotentYes
Page rules (page-rules)zoneidempotentYes
Firewall access rules (firewall-access-rules)zoneidempotentYes
Filters (legacy) (filters)zoneidempotentNo
Firewall rules (legacy) (firewall-rules)zoneidempotentNo
Page Shield policies (page-shield-policies)zoneidempotentNo
API Shield user schemas (api-shield-user-schemas)zoneorderedNo
API Shield endpoint operations (api-shield-operations)zoneorderedNo
API Shield schema validation settings (api-shield-schema-validation-settings)zoneidempotentNo
API Shield settings (api-shield-settings)zoneidempotentNo
API Shield token validation config (api-shield-token-validation-config)zonereprovisionNo
API Shield token validation rules (api-shield-token-validation-rules)zoneorderedNo
Email Security allow policies (email-security-allow-policies)accountidempotentNo
Email Security blocked senders (email-security-block-senders)accountidempotentNo
Email Security protected domains (email-security-domains)accountorderedNo
Email Security impersonation registry (email-security-impersonation-registry)accountidempotentNo
Email Security sending domain restrictions (email-security-sending-domain-restrictions)accountidempotentNo
Email Security trusted domains (email-security-trusted-domains)accountidempotentNo
Email Security URL ignore patterns (email-security-url-ignore-patterns)accountidempotentNo
Advanced DNS Protection rules (advanced-dns-protection-rules)accountidempotentNo
Advanced TCP Protection allowlist (advanced-tcp-protection-allowlist)accountidempotentNo
Advanced TCP Protection prefixes (advanced-tcp-protection-prefixes)accountidempotentNo
SYN Protection filters (advanced-tcp-protection-syn-filters)accountidempotentNo
SYN Protection rules (advanced-tcp-protection-syn-rules)accountorderedNo
TCP Flow Protection filters (advanced-tcp-protection-tcp-flow-filters)accountidempotentNo
TCP Flow Protection rules (advanced-tcp-protection-tcp-flow-rules)accountorderedNo
Advanced TCP Protection status (advanced-tcp-protection-status)accountidempotentNo
Vulnerability scanner target environments (vuln-scanner-target-environments)accountidempotentNo
Intel sinkholes (intel-sinkholes)accountorderedNo
Botnet Threat Feed ASN subscriptions (botnet-feed-asn-configs)accountidempotentNo
Fraud Detection settings (fraud-detection-settings)zoneidempotentNo
Rate limits (legacy) (rate-limits)zoneidempotentNo
Zone Lockdown rules (zone-lockdowns)zoneidempotentYes
User Agent Blocking rules (ua-rules)zoneidempotentYes
Page Shield settings (page-shield-settings)zoneidempotentYes
Pay Per Crawl config (pay-per-crawl-config)zoneidempotentNo
Content Scanning settings (content-scanning-settings)zoneidempotentNo
Content Scanning custom expressions (content-scanning-expressions)zoneidempotentNo
Leaked Credential Checks status (leaked-credential-checks)zoneidempotentYes
Leaked Credential custom detections (leaked-credential-detections)zoneidempotentNo
Security.txt (security-txt)zoneidempotentNo
Bot Management (bot-management)zoneidempotentYes
AI Security for Apps (settings + custom topics) (ai-security)zoneidempotentNo
Data security posture webhooks (data-security-posture-webhooks)accountreprovisionNo
Schema validation schemas (schema-validation-schemas)zoneorderedNo
Schema validation hosts (schema-validation-hosts)zoneidempotentNo
Schema validation settings (schema-validation-settings)zoneidempotentNo
Schema validation operations (schema-validation-operations)zoneidempotentNo
Intel indicator feeds (intel-indicator-feeds)accountorderedNo
Intel ip lists (intel-ip-lists)accountidempotentNo
Vulnerability scanner credential sets (vuln-scanner-credential-sets)accountreprovisionNo
API gateway labels (api-gateway-labels)zoneidempotentNo
API gateway schemas (api-gateway-schemas)zoneorderedNo
API gateway user schema hosts (api-gateway-user-schema-hosts)zoneidempotentNo
API gateway discovery settings (api-gateway-discovery-settings)zoneidempotentNo
Legacy WAF packages (waf-legacy-packages)zoneidempotentNo
Smart shield healthchecks (smart-shield-healthchecks)zoneidempotentNo

Traffic & delivery

SurfaceScopeRestore tierIn-band
Workers routes (workers-routes)zoneorderedNo
Load balancers (zone) (load-balancers)zoneorderedNo
Waiting rooms (waiting-rooms)zoneidempotentNo
Spectrum apps (spectrum-apps)zoneidempotentNo
Custom hostnames (SaaS) (custom-hostnames)zoneorderedNo
Custom error pages (custom-pages)zoneidempotentNo
LB monitor groups (lb-monitor-groups)accountorderedNo
Waiting Room zone settings (waiting-room-settings)zoneidempotentNo
Zone RUM (Web Analytics) toggle (zone-rum)zoneidempotentYes
Health checks (healthchecks)zoneidempotentNo
Endpoint health checks (account-endpoint-healthchecks)accountidempotentNo
Tiered Caching (tiered-caching)zoneidempotentNo
Cache Reserve (cache-reserve)zoneidempotentNo
Regional Tiered Cache (regional-tiered-cache)zoneidempotentNo
Smart Tiered Cache (smart-tiered-cache)zoneidempotentYes
Cache Variants (cache-variants)zoneidempotentNo
Origin cloud region mappings (origin-cloud-regions)zoneidempotentNo
Smart Shield settings (smart-shield)zoneidempotentYes
Zaraz configuration (zaraz-config)zoneidempotentYes
Zaraz workflow (zaraz-workflow)zoneidempotentNo
Argo Smart Routing (argo-smart-routing)zoneidempotentNo
Cloud Connector rules (cloud-connector-rules)zoneidempotentNo
Waiting Room bypass rules (waiting-room-rules)zoneorderedNo
Waiting Room scheduled events (waiting-room-events)zoneorderedNo
Account load balancers (account-load-balancers)accountorderedNo
Account waiting rooms (account-waiting-rooms)accountorderedNo
Speed monitored pages (speed-monitored-pages)zoneidempotentNo

TLS & certificates

SurfaceScopeRestore tierIn-band
Certificate packs (certificate-packs)zonereprovisionNo
Custom certificates (custom-certificates)zonereprovisionNo
Authenticated origin pulls (origin-tls-client-auth)zonereprovisionNo
API Shield client certificates (mTLS) (api-shield-client-certificates)zonereprovisionNo
API Shield mTLS hostname associations (api-shield-cert-hostname-associations)zoneorderedNo
Keyless SSL configurations (keyless-certificates)zonereprovisionNo
Custom origin trust store (ACM) (custom-trust-store)zoneidempotentNo
Universal SSL settings (universal-ssl-settings)zoneidempotentYes
Custom CSRs (zone) (custom-csrs)zonereprovisionNo
Custom CSRs (account) (custom-csrs-account)accountreprovisionNo
Custom hostname fallback origin (custom-hostname-fallback-origin)zoneidempotentNo
Origin TLS client auth hostnames (origin-tls-client-auth-hostnames)zoneorderedNo
Origin TLS client auth certificates (origin-tls-client-auth-certificates)zonereprovisionNo
Origin TLS client auth settings (origin-tls-client-auth-settings)zoneidempotentYes
ACM total TLS (acm-total-tls)zoneidempotentNo
DCV delegation (dcv-delegation)zoneidempotentNo
DNSSEC zsk (dnssec-zsk)zonereprovisionNo
Cache origin post-quantum encryption (cache-origin-pq-encryption)zoneidempotentYes

Email & logs

SurfaceScopeRestore tierIn-band
Email routing (email-routing)zoneidempotentYes
Logpush jobs (zone) (logpush)zoneorderedNo
Logpush jobs (account) (account-logpush)accountorderedNo
Email Routing destination addresses (email-routing-addresses)accountreprovisionNo
Email Sending subdomains (email-sending-subdomains)zonereprovisionNo
Email DMARC report configuration (email-dmarc-reports)zoneidempotentYes
Email Routing catch-all rule (email-routing-catch-all)zoneidempotentYes
Log Explorer datasets (zone) (logs-explorer-datasets)zoneidempotentNo
Log Explorer datasets (account) (account-logs-explorer-datasets)accountidempotentNo
Workers Observability saved queries (observability-saved-queries)accountidempotentYes
Log Control CMB (Customer Metadata Boundary) config (logcontrol-cmb-config)accountidempotentNo
Zone log-retention flag (log-retention-flag)zoneidempotentNo
Account email routing rules (account-email-routing-rules)accountorderedNo
Account email sending suppressions (account-email-sending-suppressions)accountidempotentNo
Workers observability destinations (workers-observability-destinations)accountreprovisionNo
Workers observability metricsexport (workers-observability-metricsexport)accountidempotentNo
Zone logpush edge jobs (zone-logpush-edge-jobs)zoneorderedNo

Account settings & rules

SurfaceScopeRestore tierIn-band
Account settings (account-settings)accountidempotentNo
WAF & rulesets (account) (account-rulesets)accountidempotentYes
Rule lists (account-rule-lists)accountidempotentYes
Custom pages (account) (account-custom-pages)accountidempotentNo
Firewall access rules (account) (account-firewall-access-rules)accountidempotentYes
Workers account settings (workers-account-settings)accountidempotentYes
Workers subdomain (workers-subdomain)accountidempotentNo
Realtime SFU (Calls) apps (calls-apps)accountreprovisionNo
Calls TURN keys (wiring) (calls-turn-keys)accountreprovisionNo
MoQ relays (moq-relays)accountreprovisionNo
RealtimeKit apps (realtimekit-apps)accountreprovisionNo
Container image registries (image-registries)accountidempotentNo
Queue event subscriptions (queue-event-subscriptions)accountorderedNo
Cloudforce One custom rules (cloudforce-one-rules)accountidempotentNo
Pages projects (pages-projects)accountreprovisionNo
R2 Data Catalogs (r2-catalog)accountorderedNo
R2 Catalog Syncs (r2-catalog-syncs)accountreprovisionNo
Workflows (workflows)accountorderedNo
Pay Per Crawl crawler Stripe wiring (pay-per-crawl-crawler-stripe)accountreprovisionNo
Pay Per Crawl publisher Stripe wiring (pay-per-crawl-publisher-stripe)accountreprovisionNo
Snippet rules (snippet-rules)zoneorderedNo
Container applications (container-applications)accountreprovisionNo
Queues (definitions + consumers) (queues)accountorderedNo
Workers for Platforms (dispatch namespaces + script settings) (workers-for-platforms)accountreprovisionNo
Web Analytics sites & rules (web-analytics-sites)accountorderedNo
Rules list items (account-rule-list-items)accountidempotentNo
Snippets (snippets)zoneidempotentNo
Flagship apps (flagship-apps)accountorderedNo
Account tag keys (account-tag-keys)accountidempotentNo
Account custom page assets (account-custom-page-assets)accountidempotentYes
Browser extension configuration (browser-extension-config)accountidempotentNo
Web Analytics sites (rum-site-info)accountidempotentNo
Zone custom page assets (zone-custom-page-assets)zoneidempotentYes

Account access

SurfaceScopeRestore tierIn-band
Account members (account-members)accountreprovisionNo
Account roles (account-roles)accountreprovisionNo
Access reusable policies (access-reusable-policies)accountorderedNo
Access mTLS certificates (access-mtls-certificates)accountreprovisionNo
Access key configuration (access-key-configuration)accountidempotentYes
IAM user groups (iam-user-groups)accountorderedNo
IAM resource groups (iam-resource-groups)accountorderedNo
Resource shares (resource-shares)accountorderedNo
Zero Trust organisation (access-organizations)accountidempotentYes
Workers Builds tokens (build-tokens)accountreprovisionNo
Account API tokens (account-api-tokens)accountreprovisionNo
SSO connectors (sso-connectors)accountreprovisionNo
OAuth clients (oauth-clients)accountreprovisionNo
SCIM users (scim-users)accountorderedNo
SCIM groups (scim-groups)accountorderedNo
Access MCP servers (access-mcp-servers)accountorderedNo
Access MCP portals (access-mcp-portals)accountorderedNo

Account network

SurfaceScopeRestore tierIn-band
DNS Firewall (dns-firewall)accountidempotentNo
Load balancer pools (lb-pools)accountorderedNo
Load balancer monitors (lb-monitors)accountorderedNo
Address maps (address-maps)accountorderedNo
IP prefixes (ip-prefixes)accountorderedNo
mTLS certificates (mtls-certificates)accountreprovisionNo
DLS regional-services prefix bindings (dls-prefix-bindings)accountorderedNo
Network Interconnect CNIs (cni-cnis)accountidempotentNo
Workers VPC connectivity services (connectivity-services)accountidempotentNo
Magic Cloud on-ramps (magic-cloud-onramps)accountidempotentNo
Cloud Integration providers (magic-cloud-providers)accountreprovisionNo
Magic Network Monitoring config (mnm-config)accountidempotentNo
Magic Network Monitoring rules (mnm-rules)accountidempotentYes
Magic GRE tunnels (magic-gre-tunnels)accountreprovisionNo
Magic IPsec tunnels (magic-ipsec-tunnels)accountreprovisionNo
Magic static routes (magic-static-routes)accountorderedNo
Cloudflare interconnects (magic-cf-interconnects)accountorderedNo
Magic Transit sites (magic-cf1-sites)accountorderedNo
Magic BGP settings (magic-bgp-settings)accountidempotentYes
Magic BGP filter profiles (magic-bgp-filter-profiles)accountidempotentYes
Addressing leases (addressing-leases)accountorderedNo
Addressing services (addressing-services)accountidempotentNo

Alerting & Turnstile

SurfaceScopeRestore tierIn-band
Notification policies (notification-policies)accountorderedNo
Notification webhooks (notification-webhooks)accountreprovisionNo
Turnstile widgets (turnstile)accountidempotentNo
Notification silences (notification-silences)accountidempotentNo
Certificate Transparency alerting subscription (ct-alerting)zoneidempotentYes
PagerDuty notification destinations (notification-pagerduty-destinations)accountreprovisionNo

Zero Trust

SurfaceScopeRestore tierIn-band
Access apps (access-apps)accountorderedNo
Access groups (access-groups)accountorderedNo
Access identity providers (access-identity-providers)accountreprovisionNo
Access service tokens (access-service-tokens)accountreprovisionNo
Access custom pages (access-custom-pages)accountidempotentNo
Access tags (access-tags)accountidempotentYes
Gateway rules (gateway-rules)accountorderedNo
Gateway lists (gateway-lists)accountidempotentYes
Gateway configuration (gateway-configuration)accountidempotentYes
Tunnels (cloudflared) (tunnels-cloudflared)accountreprovisionNo
Device posture rules (device-posture-rules)accountidempotentNo
Device settings policies (device-settings-policies)accountidempotentNo
Zone Access applications (zone-access-apps)zoneorderedNo
Zone Access groups (zone-access-groups)zoneorderedNo
Zone Access identity providers (zone-access-identity-providers)zonereprovisionNo
Zone Access service tokens (zone-access-service-tokens)zonereprovisionNo
Zone Zero Trust organisation (zone-zero-trust-organization)zoneidempotentYes
Zero Trust device settings (zt-device-settings)accountidempotentYes
Zero Trust connectivity settings (zt-connectivity-settings)accountidempotentYes
Gateway logging settings (gateway-logging)accountidempotentYes
Device posture integrations (device-posture-integrations)accountreprovisionNo
Device managed networks (device-managed-networks)accountidempotentYes
Global WARP override (resilience) (device-resilience-disconnect)accountidempotentYes
Zone device cert provisioning (zone-device-policy-certificates)zoneidempotentNo
Device IP profiles (device-ip-profiles)accountidempotentYes
Gateway locations (gateway-locations)accountidempotentNo
Gateway proxy endpoints (gateway-proxy-endpoints)accountidempotentNo
Gateway PAC files (gateway-pac-files)accountidempotentNo
Gateway SSH certificate authorities (gateway-ssh-ca)accountreprovisionNo
Device deployment groups (deployment-groups)accountidempotentNo
DEX rules (dex-rules)accountidempotentNo
Device DEX tests (dex-tests)accountidempotentNo
Infrastructure access targets (infrastructure-targets)accountorderedNo
DLP profiles (dlp-profiles)accountidempotentNo
DLP custom profiles (dlp-profiles-custom)accountidempotentNo
DLP entries (dlp-entries)accountidempotentNo
DLP data classes (dlp-data-classes)accountidempotentNo
DLP datasets (dlp-datasets)accountorderedNo
DLP data tag categories (dlp-data-tag-categories)accountidempotentNo
DLP sensitivity groups (dlp-sensitivity-groups)accountidempotentNo
DLP document fingerprints (dlp-document-fingerprints)accountreprovisionNo
DLP custom prompt topics (dlp-custom-prompt-topics)accountidempotentNo
DLP email rules (dlp-email-rules)accountidempotentYes
DLP settings (dlp-settings)accountidempotentNo
Zero Trust risk behaviours (zt-risk-scoring-behaviors)accountidempotentNo
Zero Trust risk integrations (zt-risk-scoring-integrations)accountorderedNo
Tunnel routes (teamnet-routes)accountorderedNo
Tunnel virtual networks (teamnet-virtual-networks)accountidempotentYes
WARP connectors (warp-connector)accountreprovisionNo
Cloudflare one applications (cloudflare-one-applications)accountorderedNo
Cloudflare one integrations (cloudflare-one-integrations)accountorderedNo
WARP device policy (device-policy-default)accountidempotentYes
Split tunnel exclude list (device-policy-split-tunnel-exclude)accountorderedNo
Split tunnel include list (device-policy-split-tunnel-include)accountorderedNo
WARP fallback domains (device-policy-fallback-domains)accountorderedNo
Gateway audit ssh settings (gateway-audit-ssh-settings)accountreprovisionNo
Gateway certificates (gateway-certificates)accountreprovisionNo
Gateway custom certificate (gateway-custom-certificate)accountreprovisionNo
Gateway egress cidr pairs (gateway-egress-cidr-pairs)accountidempotentNo
Zerotrust subnets (zerotrust-subnets)accountidempotentNo
Zerotrust hostname routes (zerotrust-hostname-routes)accountorderedNo

Data pipelines

SurfaceScopeRestore tierIn-band
Pipelines ingest streams (pipelines-streams)accountidempotentNo
Pipelines sinks (pipelines-sinks)accountreprovisionNo
Pipelines (pipelines)accountorderedNo
AI gateway gateways (ai-gateway-gateways)accountidempotentYes
AI gateway custom providers (ai-gateway-custom-providers)accountreprovisionNo
AI search instances (ai-search-instances)accountorderedNo
AI search namespaces (ai-search-namespaces)accountidempotentYes
AI search tokens (ai-search-tokens)accountreprovisionNo

Storage & data

SurfaceScopeRestore tierIn-band
Hyperdrive configs (hyperdrive-configs)accountreprovisionNo
Durable Objects namespaces (durable-objects-namespaces)accountreprovisionNo
Vectorize indexes (config) (vectorize)accountreprovisionNo
R2 bucket settings (lifecycle / lock / CORS) (r2-bucket-config)accountidempotentNo
KV namespace configuration (kv-namespaces-config)accountidempotentYes
D1 database configuration (d1-databases-config)accountorderedNo
Secrets Store stores (secrets-store-stores)accountorderedNo
Stream live inputs (stream-live-inputs)accountorderedNo
Stream watermarks (stream-watermarks)accountidempotentNo
Stream signing keys (stream-signing-keys)accountreprovisionNo
Stream webhook (stream-webhook)accountidempotentNo
Images variants (images-variants)accountidempotentNo
Vectorize indexes config (vectorize-indexes-config)accountorderedNo

Re-provision never means a secret is recoverable

Certificate private keys, Access service-token secrets, identity-provider client secrets and tunnel secrets are write-only values the Cloudflare API never returns on read, so the backup never holds them. The re-provision tier captures the configuration around those secrets and their names, then emits a checklist of what to re-provision. Do not read a re-provision surface as a way to recover the secret itself.

The surfaces that auto-restore in-band

In-band re-apply means the engine writes the surface straight back into your live account through the console during a restore apply. That is 60 of the 313 surfaces. Each is an idempotent surface with a diff-driven write path, and a re-run of the restore converges rather than creating duplicates. The table below describes 13 of them, and the In-band column above marks all 60.

SurfaceScopeHow it re-applies in-band
DNS records (dns)zoneReads the live records, matches by a natural key, creates or updates only the differences.
Zone settings (zone-settings)zonePatches each changed setting individually, so one un-settable setting skips itself.
Page rules (page-rules)zoneMatches by the rule’s target pattern and replaces a changed rule by its own id.
Firewall access rules, zone (firewall-access-rules)zoneMatches by the rule’s configuration and updates a changed rule by its id.
Firewall access rules, account (account-firewall-access-rules)accountSame diff-driven apply as the zone surface, at account level.
WAF and rulesets, zone (rulesets)zoneUpdates each existing ruleset’s rule list in place by the ruleset id.
WAF and rulesets, account (account-rulesets)accountSame in-place ruleset-rules update, at account level.
Account rule lists (account-rule-lists)accountMatches a list by its name, which Cloudflare enforces as unique per account, and updates it in place.
KV namespace configuration (kv-namespaces-config)accountRecreates a missing namespace and updates a changed title. The namespace CONTENTS are a separate source, not this surface.
Four single zone settings (zone-setting-fonts, zone-setting-origin-max-http-version, zone-setting-speed-brain, zone-setting-ssl-automatic-mode)zoneEach writes its own setting through the same single-setting writer. A setting your plan does not include is reported as not editable, not silently skipped.

The in-band write is additive by design. It creates or updates only the items that differ, one at a time, and it never replaces a whole collection. It also never deletes a live item the snapshot happens to omit, so a live-only record is reported as left in place rather than removed. 228 surfaces are captured in full and verified recoverable, but restoring them is out of band and does not carry a diff preview, because they hold no write path at all: ordered surfaces re-created in dependency order, and re-provision surfaces rebuilt from their checklist, both from the verified snapshot. The 25 with an off-by-default writer do carry a diff preview once a request names them, and stay untouched until it does.

A further 25 surfaces carry a write path that is not in that 60. Those writers were generated from Cloudflare’s published API schema, which fixes the endpoint and the method but says nothing about which field identifies an item or which fields an update refuses, and both of those decide whether a restore writes to the right object. They are off by default: a restore that does not name a scope will not touch them. An operator who wants one names it explicitly. The named set is bound into the approval hash so an approver sees exactly which off-by-default surface they are authorising. They are counted separately here and never folded into the in-band number, because a default restore does not run them.

What is not captured

The scope is configuration, the settings of an account and its zones, not data and not runtime or analytics. The following are deliberately out of scope for the cf-config source.

Not capturedWhy, and where it lives instead
KV, R2, D1 and Secrets Store dataThese are their own data source types, each captured by its own source rather than by cf-config. See the sources overview.
Worker code, bindings and version inventoryCaptured by the separate Workers source, whose restore is re-deploy from the verified snapshot. See secrets and Workers.
Logs, analytics and RadarRuntime and content, not configuration. The logpush job configuration is captured here; the log and analytics data are not. Stream and Images content is captured by the separate Stream and Images source types, not by cf-config.
BillingOut of scope by design. The engine never reads or writes billing.
Registrar transfer locks and authorisation codesRegistry state rather than account configuration, and the Cloudflare API never replays it. The registrar surfaces themselves are captured, at the re-provision tier: see the registrar-domains and registrar-registrations rows in the table above. Both read with the ordinary read-only discovery token; the Global API Key is not required and the engine never holds one.

Secret values are never in a cf-config record

A cf-config record holds a surface’s configuration as canonical JSON. It does not hold secret values such as certificate private keys or service-token secrets, because the Cloudflare API does not return them on read. The re-provision tier exists so a restore can name what to re-provision without holding the secret.

How surface selection works

A downpipe stores the surface ids it captures in the source selector. Selection matches by exact surface id, not by a prefix, so the per-surface tick-boxes in the console capture exactly what was ticked. Two rules govern the rest.

An empty include list means all surfaces, so a downpipe that selects nothing is selecting everything in scope. And an account-only downpipe, one configured with no zone id, skips every zone-scoped surface and reads only the account-scoped ones; the zone-scoped rows above simply do not apply to it. From engine 0.3.6, the run’s coverage record names each skipped zone-scoped surface under the reason no-zone.

The backup is fail-open per surface. A surface the discovery token cannot read, because of a missing scope, a deprecated endpoint, or an endpoint that refuses the token’s kind, becomes an explicit unavailable marker rather than failing the run. A surface that a run reads and finds not on the plan also becomes a marker, flagged as plan-gated.

In Auto mode the daily discovery finds unused and plan-gated surfaces before the run, so the run does not read them. From engine 0.3.6, the run’s coverage record names each of them with its reason. The archive stays complete, with one record per attempted surface, and a marker is distinguished from a genuinely empty surface. Only if every attempted surface fails does the run fail loudly, because that means a broken token or the wrong account rather than a per-surface gap.

Two surfaces depend on the kind of Cloudflare token, not on its permissions. Page rules (page-rules) and zone device-policy certificates (zone-device-policy-certificates) are refused outright to an account token, whatever permissions it carries. Both read normally under a user token created from My Profile. Cloudflare answers the first with error 1011, “Page Rules endpoint does not support account owned tokens”, and the second with error 1039, “malformed actor email claim”, because an account token carries no user identity. No other surface in this table is decided by the kind; every other row turns on the token’s permissions, which a token of either kind can hold or lack. The credential model has the check that tells you which kind you hold.

How the surface registry works

The surface registry is plain data behind engine/src/sources/cf-config-surfaces.ts, which re-exports the registry files that hold the entries. Each entry names the surface id, its scope, its restore tier and, for the 85 surfaces that carry a writer, the diff-driven write function. The backup adapter and the restore sink both read that one registry, so there is no second list to keep in step.

The console builds its per-surface selection UI from the same registry, grouping the surfaces into the categories above with a human label for each. The read and write functions never cross the wire; only the metadata (id, label, category, scope, tier and the in-band and available flags) is serialised for the selection screen.

Where this fits

Last updated .