Start here
Getting started with Citadel
Set up Citadel step by step: add your domain and origin, point proxied Cloudflare DNS records at the ingress IP, set SSL to Full, and pick a challenge mode.
How traffic reaches your site
Visitors reach Cloudflare through a proxied orange-cloud DNS record. Cloudflare forwards web traffic to Citadel, which checks requests before clean traffic reaches your origin server.
First-time setup
- In Citadel, add your root domain with the origin IP or hostname, port, and TLS-to-origin setting.
- Copy the Citadel ingress IP from the domain page.
- In Cloudflare DNS, point a proxied A record for the apex and each protected hostname to that IP.
- Set Cloudflare SSL/TLS to Full, or Full (strict) when the origin has a trusted certificate.
- Wait about a minute for Citadel to detect the connection, or select Check connection.
- Open Security and start with Auto (Balanced) challenge mode.
- Allowlist machine-facing paths such as
/api/and webhooks before using human interaction challenges.
Check protection
The domain should show Active / Proxied. A grey-cloud DNS-only record bypasses Citadel and does not provide Layer 7 protection.
See Cloudflare setup and Security levels.
