Description
May 27, 2026 ยท View on GitHub
This script automatically enables Cloudflare I'm Under Attack Mode when the server load average becomes too high, and disables it once the load returns to normal.
It is designed to help mitigate traffic spikes, abusive requests, or potential DDoS situations by temporarily increasing Cloudflare protection automatically.
I think this scenario is completely useless in 2026, but I find it funny to give it a second life.
Configuration
Download the Repository
Clone the repository:
git clone https://github.com/your-repository/cloudflare-under-attack.git
Enter the project directory:
cd cloudflare-under-attack
Make the script executable:
chmod +x cloudflare-under-attack.sh
Configure Your API
Create a Cloudflare API Token from your Cloudflare dashboard:
- My Profile
- API Tokens
- Create Token
Recommended permissions:
Zone.Zone:Read
Zone.Settings:Edit
You will also need your:
- Zone ID
- API Token
Create / Edit .env
Create the environment file:
sudo nano /etc/cloudflare-under-attack.env
Example configuration:
API_TOKEN="your_cloudflare_api_token"
ZONE_ID="your_zone_id"
Secure the file:
sudo chmod 600 /etc/cloudflare-under-attack.env
sudo chown root:root /etc/cloudflare-under-attack.env
Cron
Edit the crontab:
sudo crontab -e
Run the script every minute:
* * * * * /opt/scripts/cloudflare-under-attack.sh >/dev/null 2>&1
Logs
View logs with:
journalctl -t cloudflare-under-attack
License
Cloudflare-Block are distributed under the The MIT License.