All posts

Cloudflare One: The Zero Trust Stack, and How Agent Skills Accelerate Rollout and Migration

People at laptops in front of a global network map – Cloudflare One

On June 17, 2026, Cloudflare introduced the "Cloudflare One stack" — and took an unusual step in doing so: not a new product, but bundled domain knowledge in the form of Agent Skills for planning, rolling out, and migrating a Zero Trust environment. A good occasion to sort out what Cloudflare One actually is, and why this approach matters especially for the move to SASE/SSE.

What is Cloudflare One?

Cloudflare One is Cloudflare's SASE/SSE platform: it brings network and security together along Zero Trust principles and replaces the traditional chain of VPN, web proxy, and per-site appliances. The key building blocks:

Cloudflare Access (Zero Trust Network Access): verified, minimal access to individual applications instead of an all-around VPN, governed per user, device, and application.

Cloudflare Gateway (Secure Web Gateway): protection of users, devices, and data through DNS, web, and data filtering, including data loss prevention approaches.

Connectivity (Tunnel, Mesh & WAN): secure connection of sites, data centers, and cloud resources, without open ports and without classic MPLS.

Management & visibility (Digital Experience Monitoring): troubleshooting and user experience in view, supported by automated policy recommendations.

The gap: agents lack context

The real point of the "Cloudflare One stack" lies elsewhere. Anyone trying to configure a Zero Trust environment with the help of AI agents quickly hits a limit: a generic agent does not know the organization-specific topology — which sites, applications, and legacy systems are in use. That is exactly the missing domain knowledge the stack fills in.

The Cloudflare One stack: domain knowledge as skills

The stack consists of structured skill files that are based on real implementation experience and hand an agent the contextual knowledge it needs. Two skills are at the center: "cloudflare-one" for building and managing a Zero Trust environment, and "cloudflare-one-migration" for a guided move away from legacy vendors.

Migration without a big bang: away from Zscaler, Netskope, and the rest

In practice, the migration part is the most interesting. The stack supports vendor transitions (from Zscaler, Netskope, or Palo Alto, for example), translates existing rule sets, creates network diagrams, and proposes concrete configurations. Instead of a risky big-bang project, the transition becomes traceable and incremental. Which is what Zero Trust demands anyway.

Built for partners, too

Cloudflare explicitly aims the stack at partners who implement customer environments as well. The structured domain knowledge speeds up work that otherwise takes a lot of experience and manual effort: from assessing the current state to translating rules to going live.

Our view at KAEMI

As a Cloudflare partner, we see this above all as an accelerator for the move to SASE/SSE. We plan, implement, and manage Cloudflare One as a managed service, aligned with your requirements and in phases. Whether Zero Trust access, secure web gateway, or securely connecting your sites: the new stack helps make that journey faster and more traceable.

Want to secure access consistently with Zero Trust?

KAEMI designs, implements and manages SASE/SSE with Cloudflare One: ZTNA instead of VPN, verified access from anywhere — as a managed service.