Cutover
Migrate from Cloudflare
Move DNS, CDN, WAF, Workers, Pages, Turnstile, Tunnel, Email Routing, and Waiting Room to Zipper without a dual-running tax.
Cloudflare analogue: Cloudflare
Map the products
One Zipper workspace replaces several Cloudflare SKUs.
- ▸CDN / Cache → The Crown
- ▸WAF → The Keep
- ▸Turnstile → Portcullis
- ▸Edge antivirus → Palace Guard (no Cloudflare analogue)
- ▸DDoS → The Moat
- ▸DNS → The Herald
- ▸SSL/TLS → The Vault
- ▸Rate limiting / API Shield → The Scepter
- ▸Analytics / Logpush → The Watchtower
- ▸Load Balancing → The Drawbridge
- ▸Images / Polish → The Gallery
- ▸R2 → The Archives
- ▸Access → The Throne Room
- ▸Workers → Edge Functions
- ▸Pages → Site Hosting
- ▸Queues → Job Queues
- ▸Stream → Video Delivery
- ▸Tunnel → Origin Connect
- ▸Email Routing → Zipper Mail
- ▸Waiting Room → Visitor Queue
A-record cutover
Export Cloudflare DNS. Create the Zipper zone. Recreate records in The Herald so /dns-query can answer them.
Lower TTL, then point the web hostname’s A/AAAA at 191.215.40.237. Keep Cloudflare nameservers — Zipper is not authoritative on port 53.
Turnstile → Portcullis
Replace the Turnstile script with portcullis/v1/api.js. Siteverify URL changes; the JSON shape (success, challenge_ts, hostname) is familiar on purpose.
Workers → Edge Functions
Port fetch handlers to Edge Functions (timed Node vm on Zipper). Cron Workers become functions with a cron string and a scheduled() handler. Bindings to KV/R2 become Archives + Job Queues; use env.ZIPPER_* flags to see what is live on the zone.
Tunnel → Origin Connect
Replace cloudflared with a Zipper connector. The secret is zip_conn_…. Heartbeat keeps the tunnel in rotation. Pair with The Throne Room for identity-aware apps.
Next: Migrate from Vercel · All docs · Create a free account