Cutover
Migrate from Cloudflare
Move DNS, CDN, WAF, Workers, Pages, Turnstile, Tunnel, Email Routing, and Waiting Room to Zipper without a dual-running tax.
Cloudflare analogue: Cloudflare
Map the products
One Zipper workspace replaces several Cloudflare SKUs.
- ▸CDN / Cache → The Crown
- ▸WAF → The Keep
- ▸Turnstile → Portcullis
- ▸DDoS → The Moat
- ▸DNS → The Herald
- ▸SSL/TLS → The Vault
- ▸Rate limiting / API Shield → The Scepter
- ▸Analytics / Logpush → The Watchtower
- ▸Load Balancing → The Drawbridge
- ▸Images / Polish → The Gallery
- ▸R2 → The Archives
- ▸Access → The Throne Room
- ▸Workers → Edge Functions
- ▸Pages → Site Hosting
- ▸Queues → Job Queues
- ▸Workers AI → Edge AI
- ▸Stream → Video Delivery
- ▸Tunnel → Origin Connect
- ▸Email Routing → Emails
- ▸Waiting Room → Visitor Queue
DNS cutover
Export Cloudflare DNS (API or zone file). Create the Zipper zone. Recreate records. Proxied orange-cloud records become Herald records with “Proxy through The Crown”.
Lower Cloudflare TTL, then change nameservers. Keep Cloudflare as a secondary for 48 hours if you need a rollback.
Turnstile → Portcullis
Replace the Turnstile script with portcullis/v1/api.js. Siteverify URL changes; the JSON shape (success, challenge_ts, hostname) is familiar on purpose.
Workers → Edge Functions
Port fetch handlers to Zipper isolates. Cron Workers become functions with a cron string. Bindings to KV/R2 become Archives + Job Queues as needed.
Tunnel → Origin Connect
Replace cloudflared with a Zipper connector. The secret is zip_conn_…. Heartbeat keeps the tunnel in rotation. Pair with The Throne Room for identity-aware apps.
Next: Auth, tokens, and SSO · All docs · Create a free account