Deployment model

Deployment model A architecture diagram generated by Archify. Cloudflare Origin network Internet · Remote browser · Architecture component Internet Remote browser Cloudflare Access · Authentication · Cloudflare Cloudflare Access Authentication Cloudflare Proxy · Injects assertion · Cloudflare Cloudflare Proxy Injects assertion Origin allowlist · Cloudflare ingress only · Origin network Origin allowlist Cloudflare ingress only Reverse proxy · Not managed here · Origin network Reverse proxy Not managed here DeepSeek Harness · --trusted-host · Origin network DeepSeek Harness --trusted-host Server · JWT + policy · Origin network Server JWT + policy Client · Capability only · Origin network Client Capability only HTTPS Authenticated session Cf-Access-Jwt-Assertion Allowed ingress Host / Origin webServer wrap Web module Legend Frontend Backend Cloud Security External

Added layer

  • • Identity stays in Cloudflare Access
  • • A valid JWT does not authorize arbitrary Host/Origin
  • • Do not put Origin on the public internet just to install this plugin

In-process

  • • Server verifies JWT and makes the allow/deny decision
  • • Client only does capability enablement
  • • The reverse proxy is owned by the deployer