PanelicaDocs
panelica.com
Docs / Domains / Cloudflare Integration

Cloudflare Integration

Panelica 1.0.375 Verified 2026-07-23 Domains

Panelica's Cloudflare integration brings your Cloudflare account into the panel: zones, DNS records, cache, security modes, firewall rules and analytics, all without leaving Panelica. It supports multiple Cloudflare accounts at once and keeps your Panelica DNS and Cloudflare DNS in sync.

Panel locationDomains → Cloudflarehttps://YOUR-SERVER-IP:8443/domains/cloudflare
 Cloudflare Integration
Zones DNS Management Quick Actions Firewall Page Rules Analytics Settings
Total Zones
6
Panelica Domains
4
Active
5
Under Attack
1
P example.com A: 203.0.113.10activeDNS · Quick Actions · expand
P shop.net IP MismatchactiveDNS · Quick Actions · expand
external-site.org (external)pendingDNS · Quick Actions · expand

Connecting your account

Setup happens on the Settings tab. Add an account with your Cloudflare e-mail address and Global API Key (the panel walks you through finding it: My Profile → API Tokens → View under Global API Key). A Test button verifies the credentials before saving. You can add several accounts, mark one as default, and remove accounts later. Saved keys are never displayed again; the entry field itself is masked with a show/hide toggle.

The Settings tab also holds defaults for new DNS records: whether they start proxied or DNS-only, and their default TTL.

Until an account is connected, the working tabs (DNS, Quick Actions, Firewall, Page Rules, Analytics) stay disabled and the page shows a "Not Connected" banner pointing you to Settings; Zones and Settings remain reachable. The same tabs also stay disabled while the account has no zones yet.

Zones

The Zones tab is the overview: stat cards (total zones, Panelica domains, external zones, active, under attack), a search box, and filters by type (Panelica-hosted vs external) and by Cloudflare account.

Zones that are also hosted on this Panelica server carry a P badge: green when the zone's root A record points at this server, red when it does not, backed by an explicit IP Mismatch badge. Expanding a zone reveals its details: zone ID, plan, security level, SSL mode, a nameserver box with one-click copy (plus a notice on pending zones telling you to update these nameservers at your registrar), development-mode countdown and zone type, along with shortcuts into the DNS and Quick Actions tabs and a Delete Zone button.

Other tools on this tab:

  • Add Zone: create a zone in your Cloudflare account from the panel, with a Jump Start option (enabled by default) that imports the domain's existing DNS records automatically.
  • Bulk operations: select several zones (or all Panelica zones at once) and either Sync to Panelica, pointing their root A records at this server, or set a custom A record IP across all of them.
  • Delete Zone requires typing the zone name exactly before it proceeds.

DNS Management

Full Cloudflare DNS editing for the selected zone with eight record types (A, AAAA, CNAME, MX, TXT, NS, SRV, CAA), search and type filters, and a proper form for the tricky types: SRV gets service/protocol/priority/weight/port/target fields, CAA gets tag/flags/value, MX gets its priority. TTL is chosen from Auto up to one day.

Two things set this tab apart:

  • The proxy cloud is clickable. Toggle any A, AAAA or CNAME record between Proxied and DNS-only right in the table. Records Cloudflare marks as not proxiable or locked are indicated and protected.
  • Drift detection. When a record's value on Cloudflare no longer matches what Panelica expects (for example the root A record after a server move), the page shows a "DNS Drift Detected" banner, highlights the drifted rows and displays the expected value next to the actual one.

Bulk deletion is supported, with a progress counter as records are removed one by one; Cloudflare-locked records are excluded automatically.

Quick Actions

One-click operations for the selected zone, each behind a confirmation:

Action What it does
Sync Panelica IP Points the zone's root A record at this server. The card is honest about state: already synced, pointing at another IP owned by this server (fine for multi-IP hosting), or genuinely mismatched. After a sync it also re-syncs the mail DNS records.
Purge Cache Clears the entire Cloudflare cache for the zone; changes can take a few minutes to propagate
Development Mode Bypasses the cache for 3 hours; the card shows the remaining time while active
Under Attack Mode Turns on Cloudflare's 5-second JavaScript challenge for every visitor; the panel warns to use it only during an attack
Sync Mail DNS Aligns the mail records (MX, mail and webmail A records, SPF, DKIM, DMARC) with this server, reporting per record whether it was created, updated or already correct
SSL Mode Switches between Flexible, Full and Strict
HTTPS Redirect Toggles Cloudflare's "Always Use HTTPS"

A Recent Activity table underneath keeps the last 20 operations with their outcomes.

Firewall

Custom WAF rules for the zone with all seven Cloudflare actions: Block, Managed Challenge, Interactive Challenge, JS Challenge, Allow, Log and Skip. Rules are written in a two-mode expression builder: Simple mode composes the expression from dropdowns (IP address, country, URI path, user agent, AS number, hostname, HTTP method with equals/contains style operators) and shows the generated expression live; Advanced mode is a free-form Cloudflare expression editor. Existing rules always open in Advanced mode for precise editing. Enabling or disabling a rule is done from its edit dialog.

Page Rules

The classic Cloudflare page rules: a URL pattern plus up to one of each action, including Always Use HTTPS, Forwarding URL (301/302 with $1 capture support), cache level, browser cache TTL, SSL mode, security level and Rocket Loader. Rules can be toggled on and off directly in the list.

Page Rules are legacy. Cloudflare is migrating Page Rules to its newer Rules products. Existing rules keep working and remain manageable here, but Cloudflare may restrict creating new ones.

Analytics

Read-only traffic insight per zone over 24 hours, 7 days or 30 days: total requests, bandwidth (with how much the cache saved), a color-coded cache hit ratio, unique visitors, a threats-blocked banner when relevant, request and bandwidth charts, a response status breakdown and a top-countries table.

Permissions

The whole integration is a licensed feature (cloudflare). Beyond that, the Zones, DNS, Firewall, Page Rules and Analytics tabs each have their own view permission, while the Quick Actions tab follows the cache-purge action permission and the Settings tab follows the settings permission. The sensitive pieces have their own keys on top: connecting and removing accounts, managing zones, bulk syncing, and creating, editing or deleting firewall and page rules are each controlled separately. A user sees only the tabs and buttons their permissions allow.

Panelica Documentation · Written and verified against the live panel. · Last verified 2026-07-23 on Panelica 1.0.375