Cloudflare proxying, tunnels, and AOP protect the active path. They do not erase historical DNS records, logs, screenshots, or third-party caches that may have exposed an old origin address.
Recommended sequence:
- Deploy
PublicHostnamewith proxied mode. - Deploy either
CloudflareOriginIngresstunnel mode or allowlist+AOP mode. - Rotate the origin IP or load-balancer target after Cloudflare is serving.
- Remove the old origin address from allowlists and monitoring probes.
- Record the rotation date and residual exposure window in the battle-test checklist.
If rotation is not possible, document the residual risk and keep X_ORIGIN_1
advisory until the deployment has compensating evidence.