Cloudflare (cf)
Give the Sazabi agent the Cloudflare CLI (cf) in its sandbox to manage zones, DNS, and security rules.
About
This CLI connection makes Cloudflare's unified cf CLI available in the Sazabi agent's sandbox. The agent can manage zones, DNS, and security rules in your Cloudflare account. The tool is baked into the sandbox image; connecting it authenticates the already-installed CLI.
Prerequisites
- A Sazabi project.
- A Cloudflare API token (
CLOUDFLARE_API_TOKEN).
Set up in the dashboard
Configure the sandbox in the dashboard under Settings > Sandbox CLIs.
Find Cloudflare (cf) in the catalog
In Settings > Sandbox CLIs, find Cloudflare (cf) under Browse sandbox CLIs and choose to connect it.
Provide credentials
Enter the required value: CLOUDFLARE_API_TOKEN — a Cloudflare API token scoped to the zones and services the agent should access. Save to store it securely; Sazabi injects it into the sandbox when the agent runs.
Set up with the CLI
You can also configure the Cloudflare CLI connection with the Sazabi CLI (installed and authenticated — see CLI reference).
sazabi sandbox-clis set --type cf --env CLOUDFLARE_API_TOKEN=<your-cloudflare-token>To validate the credentials without saving, run the same command with test in place of set (the test command also requires the --env flags).
Verify
Ask the agent, in a thread, to run the cf CLI (for example cf zones list) and confirm it returns real output from your account. If the command is not found, the CLI connection may not be enabled; if it runs unauthenticated, recheck the credentials.
Troubleshooting
Command not found — Confirm the Cloudflare (cf) CLI connection is enabled for the project under Settings > Sandbox CLIs.
Authentication fails — Recheck the credential values; a rotated or revoked token must be re-entered under Settings > Sandbox CLIs or with sazabi sandbox-clis set --type cf.