Skip to content

AWS

AWS holds the databases and the out-of-band credential and recovery stores. It runs on a separate identity plane from Cloudflare, which is deliberate: a Cloudflare-side incident must not lock away the material needed to rebuild it.

Secrets Manager is the system of record for database credentials and for the identity-provider recovery codes that rebuild Cloudflare Zero Trust if the upstream IdP fails. KMS-encrypted, IAM-gated, CloudTrail-audited.

RDS and Aurora MySQL hold the console, aggregate, and billing databases, reached from Workers through Hyperdrive over the Tunnel. EC2 with Auto Scaling runs the cloudflared tunnel daemons. Each gets its own page here as its standard is written.