A Prometheus exporter for Cloudflare Analytics metrics, providing real-time HTTP and DNS analytics data from your Cloudflare zones.
Important
Due to Cloudflare data sampling on Analytics GraphQL API, numbers reported by exporter are not exact, but rather close approximation. You could still rely on this data with high degree of confidence, but your dashboards and alerts should rely more on ratios and percentages, rather than on exact numbers (e.g. cache hit/miss ratio, [45]xx errors ratio).Read more here: https://developers.cloudflare.com/analytics/graphql-api/sampling/
Configuration is handled via environment variables or .env file:
| Variable | Required | Default | Description |
|---|---|---|---|
CF_API_TOKEN | Yes | - | Cloudflare API token |
CF_LISTEN_PORT | No | 8080 | Port to expose Prometheus metrics on (range: 1024-65535) |
CF_LOG_LEVEL | No | INFO | Logging level (DEBUG, INFO, WARNING, ERROR, CRITICAL) |
CF_MAX_WORKERS | No | 5 | Maximum number of concurrent worker threads (range: 3-10) |
CF_API_URL | No | URL | Cloudflare GraphQL API endpoint |
CF_CMB_REGION | No | global | Region for CMB compliance ('global', 'eu', or 'us') |
CF_SCRAPE_DELAY | No | 60 | Scrape interval in seconds (60-300, must be multiple of 60) |
CF_ZONES | No | - | Comma-separated list of zone IDs to monitor |
CF_EXCLUDE_ZONES | No | - | Comma-separated list of zone IDs to exclude |
CF_EXCLUDE_DATASETS | No | - | Comma-separated list of datasets to exclude |
Note
Zone IDs can be found in the [Cloudflare dashboard Overview page](https://developers.cloudflare.com/fundamentals/setup/find-account-and-zone-ids/) under the API section. They are 32-character hexadecimal strings.
This exporter supports Cloudflare's data residency requirements through CMB regions. For a complete list of available datasets and their regional availability, see Cloudflare CMB GraphQL Datasets documentation.
Choose the appropriate CF_CMB_REGION based on your compliance requirements.
The Cloudflare API token needs the following permissions:
Account:
Zone:
Generic Labels for All Metrics:
zone - Cloudflare zone nameaccount - Cloudflare account nameaccount_id - Cloudflare account ID| Metric Name | Custom Labels Set | Description |
|---|---|---|
cloudflare_requests_total | country, status | Total number of HTTP requests made to the Cloudflare service. |
cloudflare_bytes_total | country, status | Total amount of data (in bytes) transferred through the Cloudflare service. |
cloudflare_cached_requests_total | country, status | Total number of HTTP requests that were served from the cache. |
cloudflare_cached_bytes_total | country, status | Total amount of data (in bytes) transferred from the cache. |
cloudflare_firewall_events_total | action, rule_id, source | Total number of events triggered by the firewall rules. |
cloudflare_enterprise_zone_quota_max | None | Maximum quota allowed for the enterprise zone. |
cloudflare_enterprise_zone_quota_current | None | Current usage of the enterprise zone quota. |
cloudflare_enterprise_zone_quota_available | None | Remaining quota available for use in the enterprise zone. |
# Start the exporter
uv run python -m cloudflare_exporter.main
The exporter will start serving metrics on http://localhost:8080/metrics (or configured port).
# Build the image
docker buildx build --platform linux/amd64,linux/arm64 -t cloudflare-exporter:latest .
# Run the container
docker run -p 8080:8080 --env-file .env cloudflare-exporter
The Cloudflare Prometheus Exporter Helm chart is available for download from our GitHub Pages repository:
You can install the chart using the following command:
helm repo add cloudflare-exporter https://n0zz.github.io/cloudflare-prometheus-exporter
helm install my-release cloudflare-exporter/cloudflare-prometheus-exporter
# Install dependencies
uv sync
# List available commands
just
# Run unit tests
just unit-test
# Run integration tests (requires valid Cloudflare token, see below)
just integration-test
# Run type checking
just typecheck
# Format code
just format
# Run linting
just lint
# Run security checks (dependencies and code analysis)
just security-check
# Run Trivy vulnerability scan on repo
just trivy-scan
# Run Trivy vulnerability scan on Docker image
just trivy-image
# Build the Helm chart
just build-helm-chart
# Build Docker image
just build-docker-image
Integration tests run against the real Cloudflare API and require a valid CF_API_TOKEN.
Locally: Create a .env file with your token and run just integration-test.
CI: Integration tests run automatically in GitHub Actions if the CF_API_TOKEN secret is configured in the repository settings. If the secret is not set, the job is skipped gracefully. To enable them in your fork, add a CF_API_TOKEN repository secret under Settings > Secrets and variables > Actions.
This project includes several security scanning tools:
Trivy - Scans for:
Bandit - Static application security testing (SAST) for Python code
Zizmor - GitHub Actions workflow security auditing (action pinning, injection risks, permissions)
Security scans run:
just security-checkResults are available in the GitHub Security tab.
When deployed via Helm, the chart includes a ServiceMonitor resource — no additional configuration is needed if you use Prometheus Operator.
For standalone Prometheus without the operator, add a scrape config to your prometheus.yml:
scrape_configs:
- job_name: 'cloudflare'
static_configs:
- targets: ['localhost:8080']
scrape_interval: 60s
Grafana dashboard: Grafana Cloud

git checkout -b feature/amazing-feature)uv syncjust test and just lintgit commit -m 'feat: add amazing feature')git push origin feature/amazing-feature)This project is licensed under the MIT License - see the LICENSE file for details.
For support, please open an issue on the GitHub repository or contact the maintainers.
Content type
Image
Digest
sha256:6da98637b…
Size
52.6 MB
Last updated
3 months ago
docker pull nulltix/cloudflare-prometheus-exporter