Update Cloudflare WAF blacklist IPs daily

You can configure a workflow definition to start automatically. To specify the time and dates a workflow runs, you define a cron expression.

This tutorial shows how to create a workflow definition that starts automatically. This workflow definition will use HTTP task to fetch the list of bad IP addresses, convert them to the required JSON object format required by Cloudflare, and use Cloudflare API to update all list items.

Prerequisites

To perform the steps in this tutorial, you must already have the following:

Step 1: Create Cloudflare API token

  1. Login to Cloudflare dashboard.

  2. Go to My Profile > API Tokens.

  3. Click Create Token button.

  4. Click Get started button under Custom token section.

  5. Enter Cloudflare list update to the Token name field.

  6. Enter the following permissions for the token:

    Account

    Account Filter Lists

    Edit

    Account

    Account Filter Lists

    Read

  7. For Account Resources, select the account for the Include field.

  8. Click Continue to summary button.

  9. Click Create Token button.

  10. Copy the Cloudflare API token.

Step 2: Create Cloudflare custom list

  1. On Cloudflare dashboard and select the account.
  2. Go to Manage Account > Configurations.
  3. Navigate to Lists and click Create list button.
  4. Enter spammers to the Identifier field.
  5. Select IP for Type field.
  6. Click Create button.

We will create a SimWorkflow workflow definition to update this custom list daily with the blacklist IPs.

Step 3: Create Cloudflare Web Application Firewall (WAF) rule

  1. On Cloudflare dashboard, select the account and domain.

  2. Go to Security > WAF.

  3. Click Create rule button.

  4. Enter Spammers top 10,000 to the Rule name field.

  5. Click Edit expression link and enter the following expression:

    (ip.src in $spammers)
    
  6. Select Block for Then take action… field.

  7. Click Deploy button.

This rule will block the IP source address of the request in the $spammers custom list.

Step 4: Find the Cloudflare Account ID

  1. On Cloudflare dashboard, select the account and domain.
  2. On the Overview page (the landing page for your domain), find the API section.
  3. Copy the Account ID, select Click to copy.

Step 5: Create Bearer token credentials

  1. Log in to the SimWorkflow.

  2. Navigate to Credentials.

  3. Click Create credentials button.

  4. Select Bearer token tab.

  5. Enter Cloudflare to the Name field.

  6. Paste the Cloudflare API token to the Bearer token field.

  7. Click Create credentials button.

We'll use this credentials in the workflow definition when we integrate with Cloudflare to update the custom list.

Step 6: Create SimWorkflow workflow definition

Step 6.1: Plan the workflow definition

There are three key steps in the process:

  1. Fetch the list of bad IP addresses. For this tutorial, we'll use the list from IPsum, as it updates daily.
  2. Prepare the JSON array from the list of bad IPs.
  3. Integrate with Cloudflare API to update the list of bad IPs.

For this, we will define three respective tasks in the workflow definition:

Sequence

Task type

Task name

1.

Retrieve IPs

2.

Prepare IPs

3.

Update Cloudflare

Step 6.2: Design the workflow definition

  1. Log in to the SimWorkflow.

  2. Navigate to Workflow definitions.

  3. Click Create workflow definition button.

  4. Select General tab of the workflow definition.

  5. Enter Update Cloudflare custom list to the Name field.

  6. Click HTTP Task to add a system task and name it Retrieve IPs.

  7. Connect the Start task to the Retrieve IPs task.

  8. Click Retrieve IPs task and select Configuration tab.

  9. Enter the following JSON object to the HTTP request field:

    {
      "url": "https://raw.githubusercontent.com/stamparm/ipsum/master/levels/4.txt",
      "method": "GET"
    }
    

    The system will make an HTTP GET request to the IPsum level 4 bad IPs file.

  10. Click JQ Task to add a system task and name it Prepare IPs.

  11. Connect the Retrieve IPs task to the Prepare IPs task.

  12. Click Prepare IPs task and select Input Parameters tab.

  13. Enter the following JSON object to the Input parameters field:

    {
      "input": "${['Retrieve IPs'].output.body}"
    }
    

    The system will reference the "body" field from the output of the Retrieve IPs task to the "input" field.

  14. Click Prepare IPs task and select JQ Filter tab.

  15. Enter the following JQ filter expression to the Expressions field:

    [.input | split("\n") | .[] | select(. != "") | {ip:.}] | .[:10000]
    

    The system will convert each non-empty line of the bad IPs level 4 text file to a JSON object with the "ip" field contains the bad IP address.

    The output of the Prepare IPs task will be the JSON object with the "result" field contains the first element of the result list and "resultList" field contains all the elements.

  16. Click HTTP Task to add a system task and name it Update Cloudflare.

  17. Connect the Prepare IP List task to the Update Cloudflare task.

  18. Click Update Cloudflare task and select Input Parameters tab.

  19. Enter the following JSON object to the Input parameters field:

    {
      "ipList": "${['Prepare IPs'].output.result}",
      "cloudflareAccountId": "${['swf:variables'].cloudflareAccountId}",
      "cloudflareListId": "${['swf:variables'].cloudflareListId}"
    }
    

    The system will reference the "result" field from the output of the Prepare IPs task to the "ipList" field.

    Set the "cloudflareAccountId" and "cloudflareListId" fields with values from workflow definition variables.

  20. Click Update Cloudflare task and select Configuration tab.

  21. Select Cloudflare (Bearer Token) for the Credentials field.

  22. Enter the following JSON object to the HTTP request field:

    {
      "url": "https://api.cloudflare.com/client/v4/accounts/${cloudflareAccountId}/rules/lists/${cloudflareListId}/items",
      "body": "${ipList}",
      "method": "PUT",
      "headers": {
        "Accept": "application/json",
        "Content-Type": "application/json"
      }
    }
    

    The system will make an HTTP PUT request to Cloudflare API with the values from the input parameters.

  23. Click Save button.

  24. Toggle the Enable checkbox to enable the workflow definition.

Use this workflow definition

Step 7: Define workflow definition variables

  1. Log in to the SimWorkflow.

  2. Navigate to Workflow definitions.

  3. Click Variables menu item from the three dots (more options) menu of the Update Cloudflare custom list workflow definition.

Step 7.1: Cloudflare account ID

  1. Enter cloudflareAccountId in the Variable key field.

  2. Paste the Cloudflare account ID in the Variable value field.

  3. Click Save variable button.

Step 7.2: Cloudflare list ID

  1. Enter cloudflareListId in the Variable key field.

  2. Locate the Cloudflare list ID and enter it in the Variable value field.

  3. Click Save variable button.

Step 8: Run the workflow definition

  1. Navigate to Workflow definitions.
  2. Click Run menu item from the three dots (more options) menu of the Update Cloudflare custom list workflow definition.
  3. The system will execute the workflow and the workflow Completed.

Step 9: Define the schedule with cron expression

  1. Log in to the SimWorkflow.
  2. Navigate to Workflow definitions.
  3. Click Schedule trigger menu item from the three dots (more options) menu of the Update Cloudflare custom list workflow definition.
  4. Turn on Schedule trigger on field.
  5. Select a user for User to start the workflow as field.
  6. Enter @daily to the Schedule cron expression field.
  7. Click Save schedule trigger button.

Summary

You've now successfully completed all the steps necessary to define a workflow definition to integrate with Cloudflare API. You've learned how to schedule the workflow definition to start automatically using cron expression. As a result, you have a process that runs daily to fetch a list of bad IP addresses and update Cloudflare with the updated list.