Deploy a managed ruleset
You can deploy a managed ruleset at the zone level or at the account level.
To deploy a managed ruleset to a phase, use the Rulesets API.
Use the following workflow to deploy a managed ruleset to a phase at the zone level.
- Get your zone ID.
- Invoke the List account rulesets operation to obtain the available rulesets. Managed rulesets exist at the account level, but you can deploy them to a zone. Find the ruleset ID of the managed ruleset you wish to deploy.
- Identify the phase where you want to deploy the managed ruleset. Ensure that the managed ruleset belongs to the same phase where you want to deploy it. To learn more about the available phases supported by each Cloudflare product, refer to the specific documentation for that product, or the Phases list.
- Add a rule to the zone-level phase entry point ruleset that executes the managed ruleset.
The following example deploys a managed ruleset to the http_request_firewall_managed
phase of a given zone ({zone_id}
) by creating a rule that executes the managed ruleset.
Use the following workflow to deploy a managed ruleset to a phase at the account level.
- Get your account ID.
- Invoke the List account rulesets operation to obtain the available rulesets. Find the ruleset ID of the managed ruleset you wish to deploy.
- Identify the phase where you want to deploy the managed ruleset. Ensure that the managed ruleset belongs to the same phase where you want to deploy it. To learn more about the available phases supported by each Cloudflare product, refer to the specific documentation for that product, or the Phases list.
- Add a rule to the account-level phase entry point ruleset that executes the managed ruleset. Use parentheses to enclose any custom conditions in the rule expression and end your expression with
and cf.zone.plan eq "ENT"
so that it only applies to zones on an Enterprise plan.
The following example deploys a managed ruleset to the http_request_firewall_managed
phase of your account ({account_id}
) by creating a rule that executes the managed ruleset. The rules in the managed ruleset are executed when the zone name matches one of example.com
or anotherexample.com
.
In these examples, the managed ruleset executes the behavior configured by Cloudflare. To customize the behavior of managed rulesets, refer to Override a managed ruleset.