The run branches on the kind of alert and then goes and gets numbers: probe results across locations for a health check, requests with the cached and uncached split plus 5xx and blocked traffic for anything traffic shaped, expiry date and days remaining for a certificate. It is API and data work ending in a short note, which is the shape Codex is most dependable on.
Run a staged conversation — no account needed. The agent handles it for real while a simulated world answers its tool calls; nothing touches real accounts, and nothing is actually sent.
HTTP DDoS attack detected and mitigated
Managed rule 6a2f began mitigating at 03:14 UTC. Peak 412,000 requests per second against /checkout/session, 94 percent from three autonomous systems. Mitigation is still active. Nothing in the payload about origin status.
Using this template drops you into a guided setup. It asks exactly this, nothing else:
Connect Cloudflare
One sign-in. The agent acts through your account, scoped to what this template uses.
Connect Slack
One sign-in. The agent acts through your account, scoped to what this template uses.
Alert rules
Which Cloudflare alerts deserve a channel post and what each kind means for you - your zones and who owns them, how seriously you take an attack alert next to a health check flip, and where somebody should look first when your origin throws errors or a certificate stops renewing.
Runs on Codex
Preselected for this page — connect your Codex account during setup, or switch to NoClick's built-in models with one click.
Watch it handle a test run
A staged conversation against a simulated world — then it’s live.
A health check flip and a request spike need entirely different fetches, and the payload already says which one arrived. Branching correctly on that is the first thing the run gets right.
Cached against uncached is what says whether origin load actually moved or the edge absorbed the whole thing. Both figures are pulled rather than characterised.
Read on zone analytics and health checks for the zones you point it at. Nothing in the template writes, so a token with no edit permission covers the entire job and removes any question of a firewall rule changing by accident. The notification policies themselves stay configured in Cloudflare and are routed into the workflow.
Free to start. Guided setup, a test run against staged conversations, and it's live.