Cloudflare CDN Deployment Tutorial

In the current network environment, exposing a website’s origin server IP without protection is actually a risky operation. Is there a service that can hide the IP and provide global (excluding mainland China) acceleration for websites? It would be even better if it could provide some additional protection.

This is where Cloudflare CDN (Content Delivery Network) becomes the obvious choice. The main reasons are that it’s free, has numerous global acceleration nodes, and provides some basic protection (it also offers advanced rules, but for beginners the default settings are usually sufficient).

Today’s tutorial will walk you through how to perfectly integrate Cloudflare in a Baota Panel environment.


Preparation

  1. A cloud server with Baota Panel installed.
  2. A domain name resolved to Cloudflare.

Step 1: Create a Website

  1. Log in to the Baota Panel and click 【Website】 → 【Add Site】 from the left menu.
  2. In the window, fill in your domain name in the Domain Name field (for example, enter on two lines: yuhuiculture.icu and www.yuhuiculture.icu).

After completing this step, don’t rush to deploy the website. Wait until DNS is configured before proceeding. Otherwise, your real IP might get logged, and the CDN protection won’t be very useful.


Step 2: Configure Cloudflare DNS and Enable the “Orange Cloud”

Many people use CF but discover the origin IP is still showing, which usually means this step wasn’t done correctly.

  1. Log in to the Cloudflare console and go to your domain management page. Click 【DNS】 from the left menu.
  2. Click 【Add Record】.
  3. Select A record type for Type.
  4. For Name, add two records: one set to @ (representing the root domain) and one set to www.
  5. In the IPv4 Address field, enter your server’s real public IP address (for example: 23.19.xx.xxx).

The most critical part here is to enable the two orange clouds behind. Enabling the orange cloud means you’re using Cloudflare’s CDN. If you don’t enable it, it’s no different from other DNS platforms.


Step 3: Configure SSL

This is the most challenging part of this tutorial, as many people encounter issues like infinite redirects, SSL certificate errors, and self-signed certificate trust problems here. However, if you follow my tutorial, you should be fine.

I recommend doing it in one step. Instead of using Baota to apply for a 3-month Let’s Encrypt certificate, we’ll directly use CF’s free self-signed origin server certificate, which is valid for up to 15 years so you basically don’t need to worry about SSL certificates.

1. Set Cloudflare’s Encryption Mode to “Full”

  • Find 【SSL/TLS】 → 【Overview】 from the CF left menu.
  • Here, set Encryption Mode to Full.

Note that if you select “Flexible” here, but Baota has strong HTTPS enabled with a Let’s Encrypt certificate configured, your website will immediately enter an infinite redirect loop (page won’t load, error: ERR_TOO_MANY_REDIRECTS).

2. Generate Cloudflare Certificate

  • Click 【SSL/TLS】 → 【Origin Server】 from the left menu.
  • Click the 【Create Certificate】 button on the page.
  • In the new configuration options:
    • Private Key Type: Keep the default RSA (2048).
    • Hostnames: You don’t need to change this; use the default content.
    • Certificate Validity Period: The default is 15 years. It’s recommended to set it to the full 15 years for peace of mind.

Keep the private key and certificate generated here. Don’t move from the page as you’ll need to copy them to Baota later.

3. Configure Baota’s SSL Certificate

With the certificate and private key in hand, we’ll go back to the Baota panel to configure SSL for the website. This is the relatively simple part.

  1. Go back to the Baota Panel, click on your website, and click 【Settings】.
  2. Click the 【SSL】 menu.
  3. Configure the certificate and private key:
    • Copy the code starting with -----BEGIN PRIVATE KEY----- and paste it into Baota’s 【Key (KEY)】.
    • Copy the code starting with -----BEGIN CERTIFICATE----- and paste it into Baota’s 【Certificate (PEM Format)】.
  4. After saving, enable forced SSL.


Step 4: Verify the Results

Everything is ready for the final verification that your domain is using Cloudflare’s CDN. It’s actually very simple.

  1. Open the itdog website and perform a ping test to check the resolved IP.

  2. Check if the resolved IP is not the origin IP, and the location attribution displays Anycast/cloudflare.com for all results.

At this point, you’ve completed the Cloudflare CDN deployment. You don’t need to worry about origin IP leakage. Cloudflare will also block some basic attacks for you. Most importantly, the global acceleration feature will speed up your website’s access.

16 Likes

Newbie good stuff I’ll save it first!

1 Like

Thank you for sharing

absolutely enough for a newbie

Favorite

1 Like

Thank you for the deployment tutorial White beginner’s福音(blessing)

look

1 Like

Nice tutorial, thank you for sharing

Learned. Thank you for sharing.

1 Like

Great tutorial, bookmarked!

learned

Favorite