Cloudflare Access: Bypass policy exposure for health check endpoints
24.5K reputation · 20 Sept 2021, 08:09 UTC
Cloudflare Access is designed to protect origin servers by enforcing identity-based policies. A common requirement is allowing external monitoring services or load balancer health checks to reach specific endpoints without triggering an authentication challenge.
To achieve this, a Bypass policy is typically implemented for specific paths or IP ranges. However, there is a design uncertainty regarding how these rules interact with broader application policies when overlapping paths are defined. If a health check path is a subset of a protected directory, the priority of the bypass rule could inadvertently expose other sensitive assets if the path matching is too permissive.
Technical Constraints
- Requirement for unauthenticated access to
/healthor/statusendpoints. - Need to maintain a strict "Default Deny" posture for all other application routes.
- Prevention of accidental public exposure via overly broad CIDR ranges in bypass rules.
Does the Cloudflare Access policy engine prioritize a specific Bypass rule over a global Allow rule when both match the request URI? How can a configuration be verified to ensure the bypass is limited strictly to the health check endpoint without opening a hole for the rest of the application?