After adding support for custom certificates in #1531, Could you please consider adding support for Cloudflare’s Authenticated Origin Pulls.
This would allow Kamal deployed applications to restrict access to requests coming only through Cloudflare by verifying the client certificate provided by Cloudflare.
This is particularly important when using Cloudflare WAF, as it prevents attackers from bypassing the WAF and accessing the origin directly.
After adding support for custom certificates in #1531, Could you please consider adding support for Cloudflare’s Authenticated Origin Pulls.
This would allow Kamal deployed applications to restrict access to requests coming only through Cloudflare by verifying the client certificate provided by Cloudflare.
This is particularly important when using Cloudflare WAF, as it prevents attackers from bypassing the WAF and accessing the origin directly.