Official agent skill

Cloudflare One Migrations

by cloudflare in cloudflare/skills

Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.

OfficialApache-2.0Auto-check passedDatabases

Install Cloudflare One Migrations

skills CLI
$ npx skills add cloudflare/skills --skill cloudflare-one-migrations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudflare/skills cloudflare-one-migrations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudflare/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloudflare-one-migrations .claude/skills/cloudflare-one-migrations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare-one-migrations
GitHub stars
3k
Used in
6 other repos
Token cost
~3.1k tokens
SKILL.md length
1,382 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
Apache-2.0

At a glance

Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.

  • Works in 7 steps: Identify the source stack: Zscaler ZIA,… → Request exports and logs before mapping.… → Build an inventory: identities, groups,… → …
  • Databases work in your project
  • SKILL.md covers Workflow, Exports To Ask For, Mapping Heuristics and Migration Assessment Prompts, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cloudflare One Migrations is an agent skill from cloudflare/skills, published by the product's own GitHub organization. Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Databases. It works with Cloudflare and Prisma. The repository describes itself as: Skills for teaching agents how to build on Cloudflare. The licence is Apache-2.0.

When your agent uses it

  • Databases work in your project

Example prompts

  • “/cloudflare-one-migrations”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Identify the source stack: Zscaler ZIA, Zscaler ZPA, Palo Alto NGFW/Prisma/GlobalProtect, legacy VPN/SWG/SD-WAN, or other.
  2. Request exports and logs before mapping. Prefer structured exports over screenshots or prose summaries.
  3. Build an inventory: identities, groups, apps, destinations, connectors/tunnels, DNS/URL/firewall/DLP/TLS policies, objects/lists…
  4. Produce a mapping plan: source object, Cloudflare One target resource, confidence, prerequisites, unsupported/partial mappings, and manual…
  5. Create dependencies first: identity/SCIM, connectors/on-ramps, routes/DNS, lists/objects, TLS bypasses, Access apps/policies, Gateway…
  6. Stage safely: use a migration prefix, create disabled/audit-mode rules by default, pilot with small groups/sites, compare logs, then…
  7. Account for every source rule. Each rule must map to a Cloudflare object or an explicit Not Migrated row with reason and security impact.

What it can do on your machine

Read from SKILL.md and the folder at commit 41e0d19. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudflare One Migrations loads about 3.1k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,382 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudflare/skills at commit 41e0d19, republished under its Apache-2.0 licence (© cloudflare). 1,382 words, ~3,113 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare-one-migrations/SKILL.md (or your agent's skills folder).
name
cloudflare-one-migrations
description
Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.

Cloudflare One Migrations

Retrieve current Cloudflare docs, Cloudflare API schemas, and source-vendor export docs before generating exact configuration.

Workflow

  1. Identify the source stack: Zscaler ZIA, Zscaler ZPA, Palo Alto NGFW/Prisma/GlobalProtect, legacy VPN/SWG/SD-WAN, or other.
  2. Request exports and logs before mapping. Prefer structured exports over screenshots or prose summaries.
  3. Build an inventory: identities, groups, apps, destinations, connectors/tunnels, DNS/URL/firewall/DLP/TLS policies, objects/lists, locations/sites, exceptions, hit counts, and compliance logging.
  4. Produce a mapping plan: source object, Cloudflare One target resource, confidence, prerequisites, unsupported/partial mappings, and manual decisions.
  5. Create dependencies first: identity/SCIM, connectors/on-ramps, routes/DNS, lists/objects, TLS bypasses, Access apps/policies, Gateway policies, DLP/CASB, logging.
  6. Stage safely: use a migration prefix, create disabled/audit-mode rules by default, pilot with small groups/sites, compare logs, then expand rollout.
  7. Account for every source rule. Each rule must map to a Cloudflare object or an explicit Not Migrated row with reason and security impact.

Exports To Ask For

  • ZIA: URL filtering, firewall filtering, SSL inspection, DLP, custom URL categories, IP groups, network services/service groups, users/groups/departments, locations, GRE tunnels, and static IPs.
  • ZPA: app segments, segment groups, server groups, app connectors/connector groups, access policies, IdP/group mapping, private DNS domains, ports, and protocols.
  • Palo Alto/Prisma: security/NAT/decryption rules, address/service objects and groups, URL categories, HIP profiles, GlobalProtect config, Prisma Access remote network/service connection config, zones, tags, logs, and hit counts.

Mapping Heuristics

Migration Assessment Prompts

  • Source coverage: which products are in scope, which exports are available, and whether screenshots/prose summaries are hiding missing object files.
  • Rule volume and hit data: counts by rule type, disabled/stale rules, no-hit rules, high-hit rules, and business-critical exceptions.
  • Object dependencies: address objects, service objects, groups, custom categories, network services, app IDs, zones, tags, connectors, and server groups.
  • Identity readiness: IdP, SCIM/group sync, group-name normalization, individual-user rules, local groups, service accounts, and contractor identities.
  • TLS/DLP readiness: source decryption rules, certificate-pinned bypasses, DLP engines/profiles, custom regex, exact-match data, and payload logging expectations.
  • Connectivity readiness: source tunnels/connectors, private DNS, Split Tunnels or bypass behavior, source IP preservation, egress IP allowlists, and site-to-site requirements.
  • Rollout readiness: pilot groups/sites, parallel-run period, rollback owner, source-stack decommission criteria, and monitoring/log comparison plan.

Source-Specific Traps

Zscaler ZIA / SWG
  • Custom URL categories often split into separate IP, domain, and URL lists. Count the generated lists, not just source categories.
  • ZIA locations with IPs are useful as source IP lists; they are not automatically Gateway DNS locations for DNS policy scoping.
  • GRE tunnel source IPs can inform policy conditions, but the transport migration is a separate WARP Connector or Cloudflare WAN workstream.
  • CAUTION/warn behavior has no exact Gateway equivalent. Treat it as an explicit customer decision, not a silent allow/block choice.
  • DLP engines and custom regex usually require manual Cloudflare DLP profile recreation. Placeholder policies must not be enabled as if DLP is complete.
  • Network application groups and unsupported protocols are partial mappings. Review them before enablement.
  • If SCIM is unavailable, identity-scoped source rules become overly broad unless you add an enforceable alternative such as user/email lists. Check Gateway identity selectors before creating those rules.
Zscaler ZPA / Private Access
  • ZPA app segments, server groups, and connector groups do not map 1:1. Cloudflare separates Access apps, tunnel routes, DNS, and policies.
  • Creating tunnels through the API does not complete connector deployment. Plan cloudflared installation, authentication, and origin reachability separately.
  • Create one Cloudflare Tunnel per ZPA connector group regardless of connector runtime status (AUTHENTICATED, DISCONNECTED, or disabled). Status is operational, not architectural. Tag disconnected or legacy groups in the tunnel description and let the customer decide what to decommission after validation.
  • Each ZPA connector instance within a group maps to one cloudflared replica running against that tunnel's token. Match replica count to connector instance count per group to preserve the same topology. A single tunnel token supports multiple simultaneous cloudflared processes. Recommend installing replicas within the same data center but on different hosts or subnets.
  • For each connector group, identify all server groups linked to it and all app segments assigned to those server groups. IP addresses and CIDRs in those app segments become CIDR routes on the corresponding tunnel; domain names become hostname routes on the same tunnel. Prefer one CIDR route per subnet over per-host /32 routes where a broad subnet covers all app segment IPs.
  • ZPA bypass means split-tunnel bypass in Cloudflare, not an Access bypass decision. Bypass rules map to WARP Split Tunnel exclude entries. This is a manual configuration step with no API automation - the customer must add bypassed domains and IPs to the device profile split tunnel exclude list through the dashboard.
  • Agentless/browser apps may become separate public-hostname Access apps per domain. WARP private apps remain private-destination apps.
  • The default Cloudflare Access application destination limit is 5 hostnames per app. For ZPA migrations with large app segments, contact the Cloudflare account team to request an increase (up to 50) before implementation. Confirm the limit is active on the account before creating apps - without it, large segments must be split into multiple apps with identical policies, significantly increasing object count.
  • IP-anchored apps require an explicit egress decision before migration: preserve source IP through customer egress, use Cloudflare dedicated egress where available, or accept that the target service must be updated to allow new source IPs. This is a customer decision that blocks implementation if unresolved.
  • Resolver policies can be account-wide. Be careful with overlapping private DNS namespaces across sites or virtual networks; retrieve resolver policy docs before making DNS changes.
  • Each ZPA access policy rule maps to a Cloudflare reusable Access policy. Create all reusable policies before attaching them to Access apps. In default-deny Gateway Network environments, additionally create a Network allow rule with selector "Self-hosted Access App with Private Address is Present" (wirefilter: any(access.private_app[*] in {"*"})) at higher precedence than any broad L4 block rules - without it, Gateway blocks private app traffic before Access policy evaluation occurs.
  • In combined ZIA and ZPA migrations, Gateway Network rules can accidentally block Access private-app traffic. The Gateway Network allow rule above is the fix - place it at higher precedence (lower number) than ZIA-migrated block rules. Add and validate this rule before enabling broad L4 blocks.
Show full SKILL.md (277 more words)Show less
Palo Alto / Prisma / NGFW
  • One Palo Alto rule can produce multiple Cloudflare resources. Preserve rule intent, not rule count.
  • App-ID, URL category, zone, HIP, schedule, and decryption behavior rarely translate exactly. Mark partial mappings rather than forcing false equivalence.
  • Export address/service objects and groups with rules. Missing object exports cause silent-looking drops unless explicitly detected.
  • Broad any destination/service rules and very broad CIDRs require manual review. Do not auto-create broad catchalls.
  • HIP/device checks require Cloudflare device posture integrations before enforcement.

Gotchas

  • Source exports often split references across files. Resolve IDs against object, service, and group files before declaring a rule unmappable.
  • Individual users, local groups, departments, and dynamic application IDs often need identity normalization. SCIM/group sync is the gating prerequisite for group selectors.
  • Zscaler caution/warn behavior, Palo Alto App-ID behavior, and TLS/decryption exceptions may not have exact equivalents. Flag them as decision points instead of forcing a 1:1 mapping.
  • Preserve source rule order and hit counts where available. Disable or delete stale/no-hit rules only with user approval.
  • Never create broad allow-all catchalls to preserve connectivity unless explicitly requested and time-limited.

Validation Gates

  • After each migration stage, compare Cloudflare object counts against parsed source counts. Stop on mismatches.
  • Review every unsupported, partial, unmapped, needs_identity, needs_posture, and manual_review item before enabling policies.
  • Validate group matching with real pilot users after SCIM sync and re-authentication.
  • Test TLS inspection and Do Not Inspect behavior before enabling HTTP/DLP blocks broadly.
  • Keep rollback paths explicit: disable migrated rules by prefix, restore source routing, or revert the pilot group/site.
  • Before declaring done, produce a source-rule accounting table: migrated object, partial mapping, not migrated reason, security impact, and owner for each manual action.

Assessment Template

markdown
## Migration Assessment

Source stack:
Artifacts reviewed:
Assumptions / missing exports:
Recommended Cloudflare One target:
Mapping summary:
Risks / partial mappings:
Not migrated:
Pilot plan:
Validation:
Rollback:

© cloudflare, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cloudflare-one-migrations of cloudflare/skills.

Open the folder on GitHubat commit 41e0d19

Used in 6 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 6 other GitHub owners. This page covers the copy in cloudflare/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cloudflare One Migrations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare One Migrations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare One Migrations this skillcloudflare/skills3k6 repos~3.1kAutomated safety check: PassApache-2.0
Cloudflare Hyperdrivesecondsky/claude-skills227—~1.8kAutomated safety check: PassMIT
Content Create Hero Imageprisma/web1.1k—~6.9kAutomated safety check: PassNone
Better Drizzlealmeidazs/better-drizzle347—~1.7kAutomated safety check: PassApache-2.0
Prisma Database Setupcurvenote/curvenote1693 repos~1.4kAutomated safety check: PassMIT
Create Auth Skilldeadlock-mod-manager/deadlock-mod-manager5744 repos~3.4kAutomated safety check: PassGPL-3.0

Similar skills

  • Cloudflare Hyperdrive

    secondsky/claude-skills

    Cloudflare Hyperdrive for Workers-to-database connections with pooling and caching.

    227 GitHub stars~1.8k tokensUpdated 10 days ago
    DatabasesAuto-check passed
  • Official

    A skill your agent uses when the operator wants a hero or meta image for a Prisma blog post; asks to create or generate a blog hero, cover, social card, Open Graph, or YouTube image; mentions cover…

    1.1k GitHub stars~6.9k tokensUpdated today
    DatabasesAuto-check passed
  • Better Drizzle

    almeidazs/better-drizzle

    Write, review, and debug code that uses better-drizzle, the typed repository layer over Drizzle ORM 1.x (better(db), client.users.findMany, paginate, cursor, upsertMany, relation include/connect…

    347 GitHub stars~1.7k tokensUpdated 3 days ago
    DatabasesAuto-check passed
  • Prisma Database Setup

    curvenote/curvenote

    Guides for configuring Prisma with different database providers (PostgreSQL, MySQL, SQLite, MongoDB, etc.).

    169 GitHub starsUsed in 3 repos~1.4k tokens
    DatabasesAuto-check passed
  • Create Auth Skill

    deadlock-mod-manager/deadlock-mod-manager

    Scaffold and implement authentication in TypeScript/JavaScript apps using Better Auth.

    574 GitHub starsUsed in 4 repos~3.4k tokens
    DatabasesAuto-check passed
  • Datamodellm

    nimbalyst/nimbalyst

    Create visual data models for database schemas using Nimbalyst's DataModelLM editor.

    1.9k GitHub stars~713 tokensUpdated today
    DatabasesAuto-check passed

More from cloudflare/skills

All 16 skills in this repo
  • Turnstile Spin

    cloudflare/skills

    Official

    Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.

    3k GitHub starsUsed in 4 repos~7.2k tokens
    Auto-check: notes
  • Nextjs On Cloudflare

    cloudflare/skills

    Official

    Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.

    3k GitHub starsUsed in 2 repos~678 tokens
    Auto-check passed
  • Agents SDK

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Agents SDK applications using the agents package.

    3k GitHub starsUsed in 2 repos~3k tokens
    Auto-check passed
  • Durable Objects

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.

    3k GitHub starsUsed in 2 repos~1.5k tokens
    Auto-check passed
  • Sandbox Next

    cloudflare/skills

    Official

    Build or maintain Cloudflare Sandbox apps on @cloudflare/sandbox@next (SDK 1.0 preview).

    3k GitHub starsUsed in 2 repos~1.7k tokens
    Auto-check passed
  • Workers Best Practices

    cloudflare/skills

    Official

    Cloudflare Workers best practices for production applications.

    3k GitHub starsUsed in 2 repos~1.4k tokens
    Auto-check passed

Categories

Questions about Cloudflare One Migrations

What does Cloudflare One Migrations do?

Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout. Cloudflare One Migrations is an agent skill from cloudflare/skills, published by the product's own GitHub organization. Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.

When should I use Cloudflare One Migrations?

Cloudflare One Migrations fits situations like: databases work in your project.

How do I install Cloudflare One Migrations in Claude Code?

Run `npx skills add cloudflare/skills --skill cloudflare-one-migrations -a claude-code`. Or copy the skill folder (skills/cloudflare-one-migrations in cloudflare/skills) into .claude/skills/cloudflare-one-migrations in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare One Migrations in Codex?

Run `npx skills add cloudflare/skills --skill cloudflare-one-migrations -a codex`. Or copy the skill folder (skills/cloudflare-one-migrations in cloudflare/skills) into .agents/skills/cloudflare-one-migrations in your project. Codex loads it when a task matches its description.

Can I use Cloudflare One Migrations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudflare/skills --skill cloudflare-one-migrations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-one-migrations, .gemini/skills/cloudflare-one-migrations, .github/skills/cloudflare-one-migrations and .opencode/skills/cloudflare-one-migrations in your project.

What does Cloudflare One Migrations need to run?

SKILL.md names no scripts, command-line tools or credentials: Cloudflare One Migrations is instructions for the agent only.

Does Cloudflare One Migrations access the network?

SKILL.md names 1 domain. As links in the text: developers.cloudflare.com. This is read from the text; nothing was executed.

Is Cloudflare One Migrations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloudflare One Migrations use?

Cloudflare One Migrations is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare One Migrations use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloudflare One Migrations?

Skills that share tags, products or a category with Cloudflare One Migrations: Cloudflare Hyperdrive (secondsky/claude-skills, 227 stars), Content Create Hero Image (prisma/web, 1.1k stars), Better Drizzle (almeidazs/better-drizzle, 347 stars) and Prisma Database Setup (curvenote/curvenote, 169 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare One Migrations?

cloudflare (a GitHub organization, an official publisher) maintains it in cloudflare/skills, which has 3,004 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 1, 2026.

Source: cloudflare/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.