Cloudflare One Migration Planner
Turns Zscaler, Palo Alto, legacy VPN, SWG, or SASE migrations into verifiable Cloudflare One plans.
The skill requires current documentation and source exports, prefers structured exports, and emphasizes disabled or audit-mode rules, small pilots, user approval, per-rule accounting, and explicit rollback. These controls support risk containment, transparent data flow, and controlled external effects. It does not specify credential handling, protection of sensitive exports or logs, privilege isolation, dependency integrity, or a consistent confirmation gate, so points were deducted.
The workflow, inventories, mapping traps, and validation gates are internally consistent and require stopping on count mismatches or unresolved mappings. There are no executable scripts, committed tests, abnormal-input examples, or diagnostic failure messages; the static-review ceiling also limits the score, so points were deducted.
The target scenarios are clear: migrations from Zscaler, Palo Alto, legacy VPN/SWG/SD-WAN, and SASE stacks, including assessment, mapping, rollout, and gap analysis. Several non-equivalent or manual-decision cases are identified. Exact trigger boundaries, input/output contracts, Chinese-language support, and mainland-China network fit are not defined; the core workflow depends on retrieving Cloudflare documentation whose reachability is unspecified, so points were deducted.
The document uses useful sections for workflow, required exports, heuristics, traps, validation gates, and an assessment template, and repository context provides installation and Apache-2.0 licensing information. It lacks skill versioning, a changelog, named maintenance responsibility, an update path, FAQs, explicit dependency notes, and more complete examples, so points were deducted.
The skill offers a concrete framework for inventory, policy mapping, risk identification, piloting, validation, and rollback, which plausibly completes the core migration-assessment task. It deliberately defers exact configuration until current sources are retrieved and provides no committed representative assessment outputs or execution evidence, so points were deducted.
The skill links to multiple Cloudflare documentation sources and defines audit steps such as object-count comparison, rule accounting, log comparison, and review of unresolved mappings. The repository also contains Semgrep CI, but it does not cover the skill's key paths. There are no committed tests, third-party execution records, or independently reproducible results, so points were deducted.
- Do not treat the linked documentation or mapping heuristics as verified current API behavior; recheck versions, account limits, and product capabilities before implementation.
- Migration exports, identity data, logs, DLP, and TLS information may be sensitive; the skill does not define secure transfer, storage, redaction, or least-privilege procedures.
- Reachability of Cloudflare documentation and related services from mainland-China networks is unspecified and may affect the core workflow.
- There are no executable tests or representative outputs, so generated mappings and configuration require human review and controlled pilot validation.
What does this skill do, and when should you use it?
This skill assesses migrations from Zscaler ZIA/ZPA, Palo Alto, legacy VPN, SWG, or SASE stacks to Cloudflare One. It requires current Cloudflare documentation, API schemas, and source-vendor export documentation before planning exact configuration. It inventories identities, applications, connectivity, policies, objects, logs, and dependencies, then produces mappings, gaps, risks, and rollout plans. Its process emphasizes small pilots, audit mode, log comparison, rule-by-rule accounting, and explicit rollback paths.
Identifies the source security or networking stack; requests structured exports and logs; inventories identities, groups, applications, destinations, connectors, tunnels, DNS, URL, firewall, DLP, TLS, objects, sites, exceptions, and hit counts; maps source objects to Cloudflare One resources with confidence, prerequisites, unsupported or partial mappings, and manual decisions; plans dependencies for identity synchronization, connectors, routes, DNS, lists, TLS bypasses, Access, Gateway, DLP, CASB, and logging; defines migration-prefixed, disabled or audit-mode policies, small pilots, and staged expansion; and produces source-rule accounting with migrated objects, partial mappings, non-migration reasons, and security impact.
- A network team migrating Zscaler ZIA/SWG needs to map URL filtering, firewall, SSL inspection, and DLP policies to Gateway.
- An architect migrating Zscaler ZPA private applications needs to separate Access applications, Cloudflare Tunnel, routing, DNS, and policy mappings.
- A security team replacing Palo Alto, Prisma, or NGFW needs to assess mappings involving zones, objects, users, applications, decryption, and hit counts.
- An infrastructure team replacing a legacy remote VPN with Access, WARP, and Tunnel needs a pilot, parallel-run, and rollback plan.
- A security owner needs to identify identity-sync, TLS/DLP, egress-IP, private-DNS, or site-to-site connectivity gaps before migration.
What are this skill's strengths and limitations?
- Covers the named migration paths for Zscaler, Palo Alto, legacy VPN, SWG, and SASE environments.
- Requires rule-by-rule accounting with reasons and security impact for unsupported or non-migrated items.
- Includes checks for identity, connectors, routing, DNS, TLS, DLP, logging, pilots, and rollback.
- Provides detailed ZPA guidance for connector groups, Tunnel replicas, Split Tunnel behavior, and Gateway allow rules.
- Reliable exact mapping depends on current documentation, API schemas, source exports, and logs.
- Several areas require partial mappings or customer decisions, including Zscaler CAUTION behavior, Palo Alto App-ID, TLS/DLP exceptions, and IP-anchored applications.
- Creating a Tunnel through an API does not complete cloudflared connector deployment; installation, authentication, and origin reachability remain separate work.
- The source provides no test suite, automation scripts, or dedicated installation command.
How do you install this skill?
This skill is part of the cloudflare/skills collection. Install the collection with the supported command: npx skills add https://github.com/cloudflare/skills. Alternatively, copy the skills/cloudflare-one-migrations folder into the relevant Agent Skills directory. The README lists ~/.claude/skills/ for Claude Code, ~/.cursor/skills/ for Cursor, ~/.config/opencode/skills/ for OpenCode, ~/.codex/skills/ for OpenAI Codex, and ~/.pi/agent/skills/ for Pi. The source does not document a separate installation command for this skill.
How do you use this skill?
In an Agent Skills-compatible client, provide a concrete migration request, such as: Assess a Zscaler ZPA migration to Cloudflare One. First list the required exports, then produce a rule-by-rule mapping, gap analysis, pilot plan, and rollback plan. Supply source-system exports and logs, and specify product scope, identity readiness, connectivity requirements, and rollout constraints. The skill requires retrieving current Cloudflare documentation, API schemas, and source-vendor export documentation. The source does not define a dedicated slash command.
How does this skill compare with similar options?
This skill is designed for migrations from Zscaler ZIA/ZPA, Palo Alto/Prisma/NGFW, legacy VPN, SWG, or SASE stacks to Cloudflare One. It is a migration assessment, mapping, and rollout-planning skill rather than a configuration-management skill for those source products.