Skip to content
CloudFlare DNS and domain settings management tool
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Type Name Latest commit message Commit time
Failed to load latest commit information.

CloudFlare domain management tool

This script allows manage DNS records that are held in CloudFlare in declarative way.

Purpose of the tool:

Play with DNS records:

  • create: simply add new line like:
- { name: '', content: '', type: 'A', ttl: '1', proxy: 'true'  }

  • update: set proxy to 'false'
- { name: '', content: '', type: 'A', ttl: '1', proxy: 'false'  }

  • detele: simply delete the line

Infrastrucure as code

DNS records are written in declarative way. Easy to parse and to manipulate with data that is stored in the data structure everybody loves – json(actually dictionary but can be easily transformed into json).

Team collaboration

No body needs password to your CF account. Everything happens via token access. You can grant rights to your domain repo config to your SysOps/DevOps/SRE/Admins team

History of changes

You always knows what changes have been made and what for. So you can easily find records you do not need any more and delete them safely.


Delete wrong DNS record? DO not remember the IP address has been removed? Everything can be easely found in your git history.

Quick DDoS protection:

Easy to set all records 'proxy:true' with security level you need.


  • You can set your CI system to execute sript on push commit.
  • You can set up and run only 'diffs' between config settings.
  • No need to set different CF settings in web-based account.

Current Version:

  • v1.0.0

Requirements:, version >= 0.8.4


pip install -r requirements.txt

Config example:

  token: cf_token_comes_here

      - { name: '', content: '', type: 'A', ttl: '1', proxy: 'true'  }
      - { name: '', content: '', type: 'A', ttl: '1', proxy: 'true'  }
      - { name: '', content: '', type: 'A', ttl: '1', proxy: 'false'  }
      - { name: '', content: '', type: 'CNAME', ttl: '1', proxy: 'true'  }
      - { name: '', content: '', type: 'MX', priority: '5', ttl: '1' }
      - { name: '', content: 'v=DMARC1; p=none; sp=none;', type: 'TXT', ttl: '1' }
      - { name: '', content: 'google-site-verification=1jhgsdJGXASJGDS', type: 'TXT', ttl: '1' }
      - { name: '', content: 'v=spf1 ~all', type: 'TXT', ttl: '1' }
      - { name: '', content: 'v=DKIM1; k=rsa; p=s0mEKeyComeShErE', type: 'TXT', ttl: '1' }
      websockets: 'on'
      browser_cache_ttl: 31536000
      email_obfuscation: 'off'
      hotlink_protection: 'off'
      ip_geolocation: 'on'
      security_level: 'essentially_off'
      ssl: 'full'
      development_mode: 'off'
      always_online: 'on'
      challenge_ttl: 7200


./ -c configs/example.yml

note: optionally you can add list of domains:

./ -c configs/example.yml -d,


  1. Please, READ, example.yml in config dir!
  2. CF api calls are limited to 1200calls/300seconds for free account. Keep this in mind you have lots of domains.


  1. Check the result after changes have been made (one more api call and compare result)
  2. Calculate approximate api calls based on number of domains and number of records to warn about limits
  3. Generate report
You can’t perform that action at this time.