Dev.to
7/15/2026

Terraform Cloudflare DNS Checklist Before Every Apply
Short summary
A practical 14-step checklist for safely running Terraform applies against Cloudflare DNS zones across multiple environments. Covers provider version pinning, API token scoping, state isolation, plan diff review, and drift detection. Born from a real incident where a flipped proxied flag silently broke staging SSH access.
- •14-step pre-apply checklist covering provider hygiene, plan review, and state integrity
- •Real-world incident: misconfigured proxied flag broke staging SSH for 40 minutes
- •Addresses rate limits, token scoping, state isolation, and drift detection at scale
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



