Get started
To get started with Magic Cloud Networking you need to give Cloudflare permission to interact with cloud providers on your behalf. You might have multiple provider accounts for the same cloud provider — for example, you might want Cloudflare to manage virtual private clouds (VPCs) belonging to two different AWS accounts.
Once Cloudflare has the credentials required to access your cloud environments, Magic Cloud Networking will automatically begin discovering your cloud resources — like routing tables and virtual private networks. Discovered resources appear in your Cloud resource catalog.
Before you can connect Magic Cloud Networking to your cloud provider, you first need to create credentials with the correct permissions in your cloud provider.
- Create a custom access policy ↗ in your AWS account, and take note of the name you entered. Then, paste the following JSON code ↗ in the JSON tab:
-
Follow the instructions on AWS ↗ to create an IAM user up until step 4 — do not check the Provide users access to the AWS Management Console option.
-
In Give users permissions to manage their own security credentials (step 7 of the AWS instructions) select Attach policies directly, and add the following policies:
AmazonEC2ReadOnlyAccess
IAMReadOnlyAccess
NetworkAdministrator
<THE_NAME_OF_YOUR_CUSTOM_POLICY>
(from step 1).
-
Add an Access Key ↗ to the new user. Take note of the access key as you cannot retrieve this information later. Cloudflare will ask for this value when you make an AWS Cloud Integration.
- Register an application ↗ and skip the optional Redirect URL step.
- Add a client secret ↗ to the app registration. Take note of the secret value as you cannot retrieve this information later. Cloudflare will ask for this value when you make an Azure Cloud Integration.
- Add a role assignment ↗. The purpose of this step is to give the app that you registered in step 1 permission to access your Azure Subscription.
- In step 3 of the linked document, select the Contributor role from the Privileged administrator roles tab.
- In step 4 of the linked document, search for the app registration from step 1 when selecting members.
- Enable the Compute Engine API ↗.
- Create ↗ a service account.
- Grant the new service account the Compute Network Admin role.
- Create ↗ a service account key. Use the JSON key type.
- Log in to the Cloudflare dashboard ↗, and select your account.
- Select Manage Account > Cloud integrations.
- Go to Cloud integrations and select Add.
- Select your cloud provider to start the cloud integration wizard.
- Enter a descriptive name, and optionally a description, for your cloud integration.
- Select Continue.
- Enter the credentials that you have created in Set up cloud credentials. These allow Magic Cloud Networking to access the resources in your cloud provider.
- Select Authorize.
You have successfully connected your cloud provider to Magic Cloud Networking. Cloud resources found by Magic Cloud Networking are available in the Cloud resource catalog.
- Set up Magic WAN as an on-ramp to your cloud.
- Manage resources found by Magic Cloud Networking.
- Edit cloud integrations.