cloudflare-one-migrations
Agent skill from cloudflare/skills.
What it does
- ZIA/SWG policies usually map to Gateway traffic policies and Gateway lists.
- ZPA private app access usually maps to Access application types, Cloudflare Tunnel, private network routing/DNS, and Access policies.
- Source coverage: which products are in scope, which exports are available, and whether screenshots/prose summaries are hiding missing object files.
- Rule volume and hit data: counts by rule type, disabled/stale rules, no-hit rules, high-hit rules, and business-critical exceptions.
- Object dependencies: address objects, service objects, groups, custom categories, network services, app IDs, zones, tags, connectors, and server groups.
- Identity readiness: IdP, SCIM/group sync, group-name normalization, individual-user rules, local groups, service accounts, and contractor identities.
- TLS/DLP readiness: source decryption rules, certificate-pinned bypasses, DLP engines/profiles, custom regex, exact-match data, and payload logging expectations.
Requirements & configuration
- DLP engines and custom regex usually require manual Cloudflare DLP profile recreation. Placeholder policies must not be enabled as if DLP is complete.
- Broad any destination/service rules and very broad CIDRs require manual review. Do not auto-create broad catchalls.
- HIP/device checks require Cloudflare device posture integrations before enforcement.
- Individual users, local groups, departments, and dynamic application IDs often need identity normalization. SCIM/group sync is the gating prerequisite for group selectors.
Derived from the skill's own SKILL.md documentation · extracted 2026-07-23
Source
Repository: https://github.com/cloudflare/skills
cloudflare-one-migrations FAQ
What does the cloudflare-one-migrations skill do?
Plans migrations from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE stacks to Cloudflare One. Use for migration assessments, policy mapping, rollout plans, and parity/gap analysis. ZIA/SWG policies usually map to Gateway traffic policies and Gateway lists. ZPA private app access usually maps to Access application types, Cloudflare Tunnel, private network routing/DNS, and Access policies.
What does cloudflare-one-migrations require?
DLP engines and custom regex usually require manual Cloudflare DLP profile recreation. Placeholder policies must not be enabled as if DLP is complete. Broad any destination/service rules and very broad CIDRs require manual review. Do not auto-create broad catchalls. HIP/device checks require Cloudflare device posture integrations before enforcement. Individual users, local groups, departments, and dynamic application IDs often need identity normalization. SCIM/group sync is the gating prerequisite for group selectors.
How do I install cloudflare-one-migrations?
Run: npx -y skills add https://github.com/cloudflare/skills --skill cloudflare-one-migrations --agent claude-code — the source lives at github.com/cloudflare/skills.
Maintain cloudflare-one-migrations?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[](https://getagentictools.com/skills/cloudflare-skills-cloudflare-one-migrations?ref=badge) npx agentictools info skills/cloudflare-skills-cloudflare-one-migrations The second line is the CLI lookup for this page — handy in READMEs and docs.