Cloudflare Alert Triage Agent

Turns a Cloudflare alert into one Slack note that separates an origin problem from an attack, backs it with request and error counts from the zone, and names where to look first.

0 in use13
Loading preview…
Guided setup — test it before connecting anything.

Watch it work before it's live

Run a staged conversation — no account needed. The agent handles it for real while a simulated world answers its tool calls; nothing touches real accounts, and nothing is actually sent.

HTTP DDoS attack detected and mitigated

tienda.bellavia.mxBellavia Retail, account a91c4

Managed rule 6a2f began mitigating at 03:14 UTC. Peak 412,000 requests per second against /checkout/session, 94 percent from three autonomous systems. Mitigation is still active. Nothing in the payload about origin status.

Set up in minutes

Using this template drops you into a guided setup. It asks exactly this, nothing else:

  1. Connect Cloudflare

    One sign-in. The agent acts through your account, scoped to what this template uses.

  2. Connect Slack

    One sign-in. The agent acts through your account, scoped to what this template uses.

  3. Alert rules

    Which Cloudflare alerts deserve a channel post and what each kind means for you - your zones and who owns them, how seriously you take an attack alert next to a health check flip, and where somebody should look first when your origin throws errors or a certificate stops renewing.

  4. Choose which agent runs it

    NoClick's built-in models work out of the box — or bring Claude Code, Codex, and other coding agents on your own subscription.

  5. Watch it handle a test run

    A staged conversation against a simulated world — then it’s live.

About this agent

Cloudflare pages you about two completely different emergencies in the same flat voice: your origin has stopped answering, and the internet has turned up all at once. This agent reads the alert, counts how many probe locations still pass, pulls the zone's requests, cache split, 5xx and blocked traffic around the window, then posts one short Slack note saying which of those two you actually have. It cannot change a rule, a record or a certificate, so the note is evidence and the decision stays with your team.

What people use it for

  • Attack or outage, decided fast - A request spike the edge is absorbing and a 5xx spike with uncached traffic flat are opposite problems with opposite responses. The note answers which one it is from the zone's own numbers, before anybody opens a dashboard.
  • Certificates on forgotten hostnames - Renewal failures land on the subdomains nobody has thought about since 2023. The note carries the expiry date, the days left and how much traffic that hostname still serves, which is what decides between renewing it and retiring it.
  • Half the world is fine - Health checks failing from two probe locations while six pass is a routing problem, not a dead origin. Counting the passing locations takes thirty seconds and almost never gets done at three in the morning.
  • Nothing at the edge changes - No firewall rule written, no security mode toggled, no cache purged, no notification silenced. The worst outcome available to it is a Slack note you disagree with, posted where the people who can act are already reading.

Before you fork

What does it need from Cloudflare?

An API token that can read zone analytics and health checks on the zones you care about, the notification policies you want pointed at this workflow, and a Slack channel. Nothing it does requires edit permission, so a read only token covers the entire job. Your alert rules go in as a variable when you fork it.

Will every notification we have enabled end up in the channel?

Only the ones you route into this workflow, and then only when your alert rules say that kind is worth posting. Cloudflare's own notification policies remain the first filter, exactly as they are today. Start with one zone and the alert types that currently wake somebody up, then widen once you like what it writes.

Can it block the attack while we are asleep?

No. It cannot write a firewall or rate limiting rule, enable a security mode, or change DNS, and that limit is deliberate. Turning traffic away is a decision about which customers you are willing to lose, and it needs somebody who knows which countries are real revenue. What it does instead is hand that person the country and network breakdown they would otherwise spend ten minutes assembling.

Run it with your coding agent

Works with

More agents like this

Browse all agent templates →

Put Cloudflare Alert Triage Agent to work

Free to start. Guided setup, a test run against staged conversations, and it's live.