cloudflare-one-migrations

Agent skill from cloudflare/skills.

cloudflare ↓ 11k
Claude Code
View source ↗

What it does

  • ZIA/SWG policies usually map to Gateway traffic policies and Gateway lists.
  • ZPA private app access usually maps to Access application types, Cloudflare Tunnel, private network routing/DNS, and Access policies.
  • Source coverage: which products are in scope, which exports are available, and whether screenshots/prose summaries are hiding missing object files.
  • Rule volume and hit data: counts by rule type, disabled/stale rules, no-hit rules, high-hit rules, and business-critical exceptions.
  • Object dependencies: address objects, service objects, groups, custom categories, network services, app IDs, zones, tags, connectors, and server groups.
  • Identity readiness: IdP, SCIM/group sync, group-name normalization, individual-user rules, local groups, service accounts, and contractor identities.
  • TLS/DLP readiness: source decryption rules, certificate-pinned bypasses, DLP engines/profiles, custom regex, exact-match data, and payload logging expectations.

Requirements & configuration

  • DLP engines and custom regex usually require manual Cloudflare DLP profile recreation. Placeholder policies must not be enabled as if DLP is complete.
  • Broad any destination/service rules and very broad CIDRs require manual review. Do not auto-create broad catchalls.
  • HIP/device checks require Cloudflare device posture integrations before enforcement.
  • Individual users, local groups, departments, and dynamic application IDs often need identity normalization. SCIM/group sync is the gating prerequisite for group selectors.

Derived from the skill's own SKILL.md documentation · extracted 2026-07-23

cloudflare-one-migrations FAQ

What does the cloudflare-one-migrations skill do?

Plans migrations from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE stacks to Cloudflare One. Use for migration assessments, policy mapping, rollout plans, and parity/gap analysis. ZIA/SWG policies usually map to Gateway traffic policies and Gateway lists. ZPA private app access usually maps to Access application types, Cloudflare Tunnel, private network routing/DNS, and Access policies.

What does cloudflare-one-migrations require?

DLP engines and custom regex usually require manual Cloudflare DLP profile recreation. Placeholder policies must not be enabled as if DLP is complete. Broad any destination/service rules and very broad CIDRs require manual review. Do not auto-create broad catchalls. HIP/device checks require Cloudflare device posture integrations before enforcement. Individual users, local groups, departments, and dynamic application IDs often need identity normalization. SCIM/group sync is the gating prerequisite for group selectors.

How do I install cloudflare-one-migrations?

Run: npx -y skills add https://github.com/cloudflare/skills --skill cloudflare-one-migrations --agent claude-code — the source lives at github.com/cloudflare/skills.

Maintain cloudflare-one-migrations?

Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.

cloudflare-one-migrations on getagentictools
[![cloudflare-one-migrations on getagentictools](https://getagentictools.com/badge/skills/cloudflare-skills-cloudflare-one-migrations.svg)](https://getagentictools.com/skills/cloudflare-skills-cloudflare-one-migrations?ref=badge)
npx agentictools info skills/cloudflare-skills-cloudflare-one-migrations

The second line is the CLI lookup for this page — handy in READMEs and docs.