Skip to main content

Documentation Index

Fetch the complete documentation index at: https://infisical.com/docs/llms.txt

Use this file to discover all available pages before exploring further.

Deploy custom SSL certificates to your Cloudflare zones. Certificates synced to Cloudflare are used for HTTPS traffic to your domains.
Certificate Syncs are configured per Application. First select which certificates to sync, then configure the Cloudflare destination.

Prerequisites

Cloudflare has a default quota of one custom certificate per zone on most plans. Enterprise plans may have higher quotas. Check your plan’s limit before syncing multiple certificates.

Create a Cloudflare Sync

  1. In your Application, go to the Certificate Syncs tab and click Create Sync.
  2. Select the Cloudflare Custom Certificate option.
  3. Configure the Destination:
    • Cloudflare Connection: The Cloudflare Connection to authenticate with.
    • Zone: The Cloudflare zone (domain) for the certificates.
  4. Configure the Sync Options:
    • Enable Removal of Expired/Revoked Certificates: Remove certificates from the destination if they are no longer active.
    • Certificate Name Schema: Customize certificate names using {{certificateId}} placeholder.
    • Auto-Sync Enabled: Automatically sync certificates when changes occur.
  5. Configure the Details:
    • Name: The name of your sync (slug-friendly).
    • Description: Optional description.
  6. Select which certificates should be synced.
  7. Review and click Create Sync.

Certificate Management

The Cloudflare Custom Certificate Sync provides:
  • Automatic Deployment: Deploy certificates in Infisical to Cloudflare as Custom certificates.
  • Certificate Updates: Update certificates in Cloudflare when renewals occur.
  • Expiration Handling: Optionally remove expired certificates from Cloudflare (if enabled).
  • Chain Management: Properly bundle certificate chains for optimal browser compatibility.
Cloudflare Custom Certificate Syncs support both automatic and manual synchronization modes. When auto-sync is enabled, certificates are automatically deployed as they are issued or renewed.

Manual Certificate Sync

You can manually trigger certificate synchronization to Cloudflare using the sync certificates functionality. This is useful for:
  • Initial setup when you have existing certificates to deploy
  • One-time sync of specific certificates
  • Testing certificate sync configurations
  • Force sync after making changes
To manually sync certificates, use the Sync Certificates API endpoint or the manual sync option in the Infisical UI.

FAQ

Cloudflare does not support importing certificates back into Infisical due to security limitations where private keys cannot be extracted from Cloudflare.

What’s Next?

AWS Certificate Manager

Import certificates into ACM for AWS services.

Auto-Renewal

Enable automatic certificate renewal and syncing.

Alerting

Get notified about certificate lifecycle events.

Other Sync Destinations

View all supported sync destinations.