エージェント駆動型デプロイメントを特徴とする「Cloudflare One」スタックの発表
本文の状態
日本語全文を表示中
詳細モードで約9分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Cloudflare Blog
クラウドフレアは、ゼロトラストネットワークアーキテクチャへの移行や採用が抱える課題に対し、セキュリティポリシーやルーティングの意図を解読する手作業を軽減するため、「エージェント駆動型デプロイメント」機能を備えた「Cloudflare One」スタックを発表した。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
ゼロトラストネットワークアーキテクチャへの採用または移行は、非常に困難なタスクになり得ます。ポリシーを一つ変更する前にも、チームは自社のネットワークが実際にどのように構築されているかを思い出す必要があります:どのようなアプリケーションが存在し、その認証・認可の仕組みはどうなっており、トラフィックはそれらの間でどのように流れ、現在のアーキテクチャがどのような前提に基づいているかです。この実践的なプロセスでは、実務者は現在設置されているすべてのセキュリティおよびルーティングポリシーの背後にある意図を解読する必要があります。
本日、私たちは Cloudflare One stack をリリースします。これは、エージェントに与えるスキルセットであり、ゼロトラスト環境の設定、デプロイ、管理をエージェントが行うためのものです。このツールキットは、全く新しいセキュリティスイートの学習プロセスや、既存のものを Cloudflare へマッピングするプロセスを自動化することを支援するために設計されています。
Cloudflare は、まさにこのプロセスを通じて数千社のお客様と協力してきました。その繰り返しが、移行が停滞する地点、毎回発生する質問、そして前進するために必要なものについての専門知識を築きました。Cloudflare One stack はその専門知識をパッケージ化し、これまで以上にアクセスしやすくしました。
ネットワークセキュリティにおけるエージェントのギャップ
チームはすでに、コード作成、アラートのトリアージ、ワークフローの自動化のためにエージェントを使用しています。組織では、セキュリティワークフローを実行する際に Cloudflare が提供するツールリングをエージェントに求める声が高まっています。しかし、それら単独のエージェントには、組織固有のネットワークトポロジやベンダー構成の微妙なニュアンスについての訓練が施されていません。
指示的かつ権威あるガイダンスを提供することで、組織は既存のツールキットにこの文脈を層化し、すでに展開しているセキュリティ製品をより効果的に活用できるようになります。
Cloudflare は長年、市場で最も導入が容易な SASE ベンダーとして知られてきました。このスタックはその哲学をエージェントにも拡張するものであり、セキュリティインフラ上で動作するために必要な文脈、ツール、構造化された推論能力を提供します。
Cloudflare One スタックとは何ですか?
Cloudflare One スタックは、あらゆるエージェントと併用可能なスキル集です。他のスキルと同様に、単独で使用したり、独自の文脈を層化して追加したり、その上にツールを開発したりできます。これはセキュリティ実務者が Cloudflare One の評価、展開、管理のライフサイクル全体を通じて支援するために意図的に設計されたものです。
このスタックは、Cloudflare One 製品で顧客と協力してきた従業員が持つ数万時間にわたる経験から手作業で収集・編集された知識を統合して構築されました。Cloudflare 上のユーザーおよびエージェントセキュリティインフラの計画、管理、実装のためのツールが含まれています。また、Zscaler や Palo Alto Networks などのレガシーベンダーからの移行に特化した厳選されたロジックも含まれています。
Cloudflare のコードモード MCP サーバーと併用することで、このスタックはエージェントに Cloudflare API への型安全なインターフェースを提供します。エージェントは、生きたアカウントを照会し、構成を検証し、アドホックな API 呼び出しではなく、精選された Cloudflare 推奨のワークフローを通じて変更を加えることができます。
スタックには何が含まれているか?
Cloudflare One スタックは、2 つの軽量スキルファイルとして提供されます:cloudflare-one と cloudflare-one-migration。これら 2 つを組み合わせることで、Cloudflare One の展開への移行、実装の構築、管理、トラブルシューティングを網羅します。
Cloudflare Access を用いたリモートアクセスと VPN の代替
Cloudflare Gateway によるユーザー、ネットワーク、デバイス、データのセキュリティ
Cloudflare Tunnel、Cloudflare Mesh、Cloudflare WAN を活用した接続性
他の SASE ベンダーからの移行に関する明確な詳細を含む移行ガイダンス
提案されたネットワーク変更をあなたやあなたのチームが理解しやすい方法で可視化するためのネットワーク図の解釈と生成
SASE ベンダー間の概念のマッピングを行うベンダー概念翻訳により、プロバイダーの評価および切り替えの障壁を低減
デジタルエクスペリエンスモニタリング (DEX) ツールキットと自動ルール推奨によるトラブルシューティングと運用
仕組み
このスタックは Cloudflare Skills リポジトリで利用可能です。各スキルファイルには、構造化された知識、意思決定ツリー、およびツール定義が含まれており、エージェントはコンテキストが一致した際に自動的にこれらを読み込みます。これをエージェントに与えて、ゼロトラスト環境のセットアップ、設定、管理を支援させましょう:
cloudflare-one スキルは一般的な製品ガイダンスをカバーしています。例えば、VPN インフラストラクチャを Cloudflare Tunnel や Cloudflare Mesh に置き換える最良の方法についてエージェントに尋ねた場合、このスキルは以下を行う方法を知っています:
既存の VPN アプリケーションのインベントリを作成し、各接続モデルに必要な接続方式を特定する
各アプリケーションを適切な Cloudflare プリミティブ(セルフホスト型 Access アプリケーション、Tunnel 接続サービス、または Mesh 接続ネットワークセグメント)にマッピングする
切り替え中の混乱を最小限に抑える推奨デプロイシーケンスを生成する
変更を加える前にチームがレビューできる構成サマリーを作成する
cloudflare-one-migration スキルはベンダー間の変換をカバーしています。例えば、Zscaler Private Access アプリケーションを Cloudflare Access へ移行する方法についてエージェントに尋ねた場合、このスキルは以下を行う方法を知っています:
Zscaler のアプリケーション定義を Cloudflare Access のアプリケーション定義にマッピングする
Zscaler のユーザーグループとポリシーを Cloudflare Access のポリシーに変換する
Cloudflare API を使用して、アカウント内に同等のリソースを作成する
移行された内容と手動レビューが必要な項目のサマリーを生成する
スタック内の移行ロジックは、Cloudflare の Descaler および Deskope プログラムで使用されているものと同じです。これらのプログラムでは、すでにエンタープライズ顧客を Zscaler や Netskope から Cloudflare One へ数ヶ月ではなく数時間で移行しています。このスタックにより、その機能がいつでも、スケジュールされた契約を待たずに、あらゆる顧客やパートナーに利用可能になります。
スタックの活用方法をもっと知る
Cloudflare One スタックはまた、以下も可能です:
あなたのライブアカウントで観測されるトラフィックに基づきセキュリティルールを推奨する
既存の Zscaler Private Access アプリケーションを自己ホスト型の Cloudflare Access アプリケーションへ自動的に移行する
セキュア Web ゲートウェイの HTTP ログ内の異常を検証し、ユーザーが直面している問題を解決するためのルールを構築する
DEX ツールキットを使用してユーザーの安定性をレポートし、主要なシナリオにおけるユーザー遅延を改善するためのアクションを実行する
スキルをエージェントから読み込む場合でも、カスタムツールの上に構築する場合でも、Cloudflare One スタックはこれらのユースケースおよびそれ以上をすべて処理します。
パートナー向けにも
これはすでに Cloudflare One 製品スイートを採用した顧客の継続的な管理を簡素化する一方で、Cloudflare パートナーネットワークのためのツールでもあります。パートナーはこれを使用して、顧客のデプロイをより迅速に行い、より効果的に管理し、精度を高めてトラブルシューティングを行い、問題を解決へと導くことができます。
次のステップ
Cloudflare One スタックは、今日から利用を開始できます。このスタックを最大限に活用するには、Cloudflare code mode MCP サーバーと組み合わせることをお勧めします。MCP サーバーは、認証情報をモデルのコンテキストから分離したまま、単一の圧縮されたインターフェースを通じてエージェントが Cloudflare API にライブでアクセスできるようにします。
Cloudflare One プロダクトの進化に伴い、Cloudflare One スタックも引き続き拡大していきます。追加の移行ソースに対応する新しいスキルや、より高度なトラブルシューティングワークフローの開発は既に進行中です。
顧客やパートナーがこのスキルファイルを利用する方法についてさらに理解を深めるにつれ、これらのスキルを中心に、より堅牢なツールリングを整備していく計画です。もしあなたが顧客またはパートナーで、このスタックが次に扱うべき内容に関するフィードバックを提供したい場合は、アカウントチームを通じてお問い合わせいただくか、リポジトリにイシューを開いてください。
原文を表示
Adopting or migrating to a Zero Trust network architecture can be a daunting task. Before a single policy changes, teams have to recall how their network is actually built: which applications exist, their authentication and authorization constructs, how traffic flows between them, and any assumptions the current architecture makes. This hands-on process requires practitioners to decode the intent behind every security and routing policy in place.
Today, we’re releasing the Cloudflare One stack, a set of skills you give to your agent to configure, deploy, and manage your Zero Trust environment for you. This toolkit is designed to help automate the process of learning an entirely new security suite and mapping your existing one into Cloudflare.
Cloudflare has worked with thousands of customers through exactly this process. That repetition built expertise on where migrations stall, what questions come up every time, and what it takes to move forward. The Cloudflare One stack packages that expertise and makes it more accessible than ever.
The agent gap in network security
Teams are already using agents to write code, triage alerts, and automate workflows. Organizations are increasingly asking for Cloudflare-provided tooling to help agents execute on security workflows. On their own, agents are not trained on the nuances of an organization's specific network topology or vendor configurations.
By providing prescriptive and authoritative guidance, organizations can layer this context into their existing toolkit to make better use of the security products they are already deploying.
Cloudflare has long been the easiest-to-deploy SASE vendor in the market. The stack extends that philosophy to agents: it gives them the context, tools, and structured reasoning they need to operate on your security infrastructure.
What is the Cloudflare One stack?
The Cloudflare One stack is a collection of skills that can be used with any agent. As with any skill, you can use them standalone, layer in your own context, or build tooling on top. It was purpose-built to help security practitioners across the entire lifecycle of evaluating, deploying, and managing Cloudflare One.
The stack was built by synthesizing hand-curated knowledge from employees with tens of thousands of hours of experience working with customers on Cloudflare One products. It contains tools for planning, managing, and implementing your user and agent security infrastructure on Cloudflare. It also contains handpicked logic for migrating from legacy vendors like Zscaler and Palo Alto Networks.
When used in conjunction with the Cloudflare code mode MCP server, the stack gives agents a typed interface to the Cloudflare API. Agents can query your live account, inspect configurations, and make changes through a curated set of Cloudflare-recommended workflows rather than ad-hoc API calls.
What’s in the stack?
The Cloudflare One stack ships as two lightweight skill files: cloudflare-one and cloudflare-one-migration. Together they cover migrating to, building an implementation for, managing, and troubleshooting your Cloudflare One deployment:
Remote access and VPN replacement with Cloudflare Access
User, network, device, and data security with Cloudflare Gateway
Connectivity with Cloudflare Tunnel, Cloudflare Mesh, and Cloudflare WAN
Migration guidance with explicit detail for moving from other SASE vendors
Network diagram interpretation and generation, so you can visualize proposed changes to your network in a way that is easy for you and your team to understand
Vendor concept translation, which maps concepts between SASE vendors to reduce the barrier to evaluating and switching providers
Troubleshooting and operations, with the Digital Experience Monitoring (DEX) toolkit and automated rule recommendations
How it works
The stack is available in the Cloudflare Skills repository. Each skill file contains structured knowledge, decision trees, and tool definitions that agents load automatically when the context matches. Give this to your agent and let it help you set up, configure, and manage your Zero Trust environment:
The cloudflare-one skill covers general product guidance. For example, if you ask an agent for the best way to replace your VPN infrastructure with Cloudflare Tunnel or Cloudflare Mesh, the skill knows how to:
Inventory your existing VPN applications and identify which connectivity model each requires
Map each application to the appropriate Cloudflare primitive — self-hosted Access application, Tunnel-connected service, or Mesh-connected network segment
Generate a recommended deployment sequence that minimizes disruption during cutover
Produce a configuration summary your team can review before making any changes
The cloudflare-one-migration skill covers vendor-to-vendor translation. For example, if you ask an agent to migrate your Zscaler Private Access applications to Cloudflare Access, the skill knows how to:
Map Zscaler application definitions to Cloudflare Access application definitions
Transform Zscaler user groups and policies into Cloudflare Access policies
Use the Cloudflare API to create the equivalent resources in your account
Generate a summary of what was migrated and what requires manual review
The migration logic in the stack is the same logic used in Cloudflare's Descaler and Deskope programs. Those programs have already moved enterprise customers from Zscaler and Netskope to Cloudflare One in hours rather than months. The stack makes that capability available to any customer or partner, at any time, without waiting for a scheduled engagement.
More ways to use the stack
The Cloudflare One stack can also:
Recommend security rules based on traffic seen in your live account
Automatically migrate your existing Zscaler Private Access applications into self-hosted Cloudflare Access applications
Investigate anomalies in your secure web gateway HTTP logs and build rules to resolve issues users are seeing
Report on user stability with the DEX toolkit and take actions to improve user latency in key scenarios
Whether you are loading the skill from an agent or building custom tooling on top, the Cloudflare One stack handles all of these use cases and more.
For partners, too
While this simplifies ongoing management for customers who have already adopted the Cloudflare One product suite, it is also a tool for the Cloudflare partner network. Partners can use it to help their customers deploy faster, manage more effectively, troubleshoot with increased accuracy, and drive issues to resolution.
What's next
You can start using the Cloudflare One stack today. To get the most out of the stack, pair it with the Cloudflare code mode MCP server. The MCP server gives your agent live access to the Cloudflare API through a single, compressed interface that keeps authentication credentials out of the model context.
The Cloudflare One stack will continue to expand as Cloudflare One products evolve. New skills for additional migration sources and more advanced troubleshooting workflows are already in development.
As we learn more about how customers and partners utilize these skills files, we plan to build more robust tooling around these skills. If you are a customer or partner and want to share feedback on what the stack should handle next, reach out through your account team or open an issue in the repository.
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み