Skip to content
Start here

Set up Cloudflare for Citadel

Point proxied (orange cloud) Cloudflare A records at the Citadel ingress IP, set SSL/TLS to Full, and fix domains that stay awaiting DNS.

Proxied Cloudflare DNS sends traffic to Citadel before the origin
Proxied A records point to Citadel. Grey-cloud records bypass protection.

Configure DNS and SSL

  1. Open your domain in Citadel and copy its ingress IP from the A record chip.
  2. In Cloudflare DNS, set the apex (@) and every hostname you want protected to that IP.
  3. Turn on Proxied (orange cloud) for each protected record.
  4. In Cloudflare SSL/TLS Overview, select Full or Full (strict) if the origin certificate is trusted.
  5. Return to Citadel. It checks awaiting domains about every minute; Check connection refreshes immediately.

Troubleshoot activation

A grey-cloud record, the wrong ingress IP, or Flexible SSL can leave a domain awaiting DNS or cause browser errors. DNS-only records skip Citadel entirely. Mail, TXT, and other non-web records remain in Cloudflare.

See DNS stays in Cloudflare and Origin and hostnames.

WhatsApp support