1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413 414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432 433 434 435 436 437 438 439 440 441 442 443 444 445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482 483 484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563 564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624 625 626 627 628 629 630 631 632 633 634 635 636 637 638 639 640 641 642 643 644 645 646 647 648 649 650 651 652 653 654 655 656 657 658 659 660 661 662 663 664 665 666 667 668 669 670 671 672 673 674 675 676 677 678 679 680 681 682 683 684 685 686 687 688 689 690 691 692 693 694 695 696 697 698 699 700 701 702 703 704 705 706 707 708 709 710 711 712 713 714 715 716 717 718 719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751 752 753 754 755 756 757 758 759 760 761 762 763 764 765 766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798 799 800 801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821 822 823 824 825 826 827 828 829 830 831 832 833 834 835 836 837 838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880 881 882 883 884 885 886 887 888 889 890 891 892 893 894 895 896 897 898 899 900 901 902 903 904 905 906 907 908 909 910 911 912 913 914 915 916 917 918 919 920 921 922 923 924 925 926 927 928 929 930 931 932 933 934 935 936 937 938 939 940 941 942 943 944 945 946 947 948 949 950 951 952 953 954 955 956 957 958 959 960 961 962 963 964 965 966 967 968 969 970 971 972 973 974 975 976 977 978 979 980 981 982 983 984 985 986 987 988 989 990 991 992 993 994 995 996 997 998 999 1000 1001 1002 1003 1004 1005 1006 1007 1008 1009 1010 1011 1012 1013 1014 1015 1016 1017 1018 1019 1020 1021 1022 1023 1024 1025 1026 1027 1028 1029 1030 1031 1032 1033 1034 1035 1036 1037 1038 1039 1040 1041 1042 1043 1044 1045 1046 1047 1048 1049 1050 1051 1052 1053 1054 1055 1056 1057 1058 1059 1060 1061 1062 1063 1064 1065 1066 1067 1068 1069 1070 1071 1072 1073 1074 1075 1076 1077 1078 1079 1080 1081 1082 1083 1084 1085 1086 1087 1088 1089 1090 1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114 1115 1116 1117 1118 1119 1120 1121 1122 1123 1124 1125 1126 1127 1128 1129 1130 1131 1132 1133 1134 1135 1136 1137 1138 1139 1140 1141 1142 1143 1144 1145 1146 1147 1148 1149 1150 1151 1152 1153 1154 1155 1156 1157 1158 1159 1160 1161 1162 1163 1164 1165 1166 1167 1168 1169 1170 1171 1172 1173 1174 1175 1176 1177 1178 1179 1180 1181 1182 1183 1184 1185 1186 1187 1188 1189 1190 1191 1192 1193 1194 1195 1196 1197 1198 1199 1200 1201 1202 1203 1204 1205 1206 1207 1208 1209 1210 1211 1212 1213 1214 1215 1216 1217 1218 1219 1220 1221 1222 1223 1224 1225 1226 1227 1228 1229 1230 1231 1232 1233 1234 1235 1236 1237 1238 1239 1240 1241 1242 1243 1244 1245 1246 1247 1248 1249 1250 1251 1252 1253 1254 1255 1256 1257 1258 1259 1260 1261 1262 1263 1264 1265 1266 1267 1268 1269 1270 1271 1272 1273 1274 1275 1276 1277 1278 1279 1280 1281 1282 1283 1284 1285 1286 1287 1288 1289 1290 1291 1292 1293 1294 1295 1296 1297 1298 1299 1300 1301 1302 1303 1304 1305 1306 1307 1308 1309 1310 1311 1312 1313 1314 1315 1316 1317 1318 1319 1320 1321 1322 1323 1324 1325 1326 1327 1328 1329 1330 1331 1332 1333 1334 1335 1336 1337 1338 1339 1340 1341 1342 1343 1344 1345 1346 1347 1348 1349 1350 1351 1352 1353 1354 1355 1356 1357 1358 1359 1360 1361 1362 1363 1364 1365 1366 1367 1368 1369 1370 1371 1372 1373 1374 1375 1376 1377 1378 1379 1380 1381 1382 1383 1384 1385 1386 1387 1388 1389 1390 1391 1392 1393 1394 1395 1396 1397 1398 1399 1400 1401 1402 1403 1404 1405 1406 1407 1408 1409 1410 1411 1412 1413 1414 1415 1416 1417 1418 1419 1420 1421 1422 1423 1424 1425 1426 1427 1428 1429 1430 1431 1432 1433 1434 1435 1436 1437 1438 1439 1440 1441 1442 1443 1444 1445 1446 1447 1448 1449 1450 1451 1452 1453 1454 1455 1456 1457 1458 1459 1460 1461 1462 1463 1464 1465 1466 1467 1468 1469 1470 1471 1472 1473 1474 1475 1476 1477 1478 1479 1480 1481 1482 1483 1484 1485 1486 1487 1488 1489 1490 1491 1492 1493 1494 1495 1496 1497 1498 1499 1500 1501 1502 1503 1504 1505 1506 1507 1508 1509 1510 1511 1512 1513 1514 1515 1516 1517 1518 1519 1520 1521 1522 1523 1524 1525 1526 1527 1528 1529 1530 1531 1532 1533 1534 1535 1536 1537 1538 1539 1540 1541 1542 1543 1544 1545 1546 1547 1548 1549 1550 1551 1552 1553 1554 1555 1556 1557 1558 1559 1560 1561 1562 1563 1564
|
# cloudflare-python
> [!WARNING]
> Soon there will be two Python packages for accessing Cloudflare's API.
>
> 1. This original [package](https://github.com/cloudflare/python-cloudflare), which was initially introduced [here](https://blog.cloudflare.com/python-cloudflare/).
> 2. A ground-up rewrite of the SDK, released under `3.*`, at some point in the future. See [here](https://github.com/cloudflare/python-cloudflare/discussions/191)
>
> If you like using this package in it's present form, it is highly recommended that you pin to the `2.*` releases now.
>
> ```bash
> $ cat ${YOUR_PROJECT}/requirements.txt
> cloudflare==2.19.*
> $
> ```
>
> For manual upgrades; the following will work cleanly:
> ```bash
> $ pip install --upgrade cloudflare==2.19.*
> ...
> Successfully installed cloudflare-2.19.4
> $
> [!WARNING]
> Release `2.20.*` is now available and it will produce a warning message explaining all this via stderr (the standard error output).
> This messages does not stop the program from operating, it's just a warning.
> If you wish to surpress this message (which is a bad idea because pinning to `2.19.*` is the right thing to do), then do the following in your code:
> ```python
> cf = CloudFlare.CloudFlare(..., warnings=False)
> ```
> Or, if you use `cli4`, then the following.
> ```bash
> $ cli4 -w False ...
>```
> [!WARNING]
> Release `3.*` will not be code-compatible/call-compatible with previous releases (i.e. release `1.*` and `2.*`).
When you see this README complete change you will know that `3.*` has been released; however, until then, this code will be released under a `2.19.*` release number.
## Package stats
[](https://pepy.tech/project/cloudflare)
[](https://pepy.tech/project/cloudflare)
[](https://pepy.tech/project/cloudflare)
[](https://pepy.tech/project/cloudflare)
[](https://pepy.tech/project/cloudflare)
## Instant how-to-use example
If you want to call the following API call:
```
https://api.cloudflare.com/client/v4/zones/{zone_id}/dns_records/{dns_record_id}
```
It would translates to the following Python code:
```python
results = cf.zones.dns_records(zone_id, dns_record_id)
```
Many more examples are below and/or in the `examples` folder.
## Installation
Two methods are provided to install this software.
Use PyPi (see [package](https://pypi.python.org/pypi/cloudflare) details) or GitHub (see [package](https://github.com/cloudflare/python-cloudflare) details).
### Via PyPI
```bash
$ sudo pip install cloudflare
$
```
Yes - that simple! (the sudo may not be needed in some cases).
### Via github
```bash
$ git clone https://github.com/cloudflare/python-cloudflare
$ cd python-cloudflare
$ ./setup.py build
$ sudo ./setup.py install
$
```
Or whatever variance of that you want to use.
There is a Makefile included.
## Cloudflare name change - dropping the capital F
In Sepember/October 2016 the company modified its company name and dropped the capital F.
However, for now (and for backward compatibility reasons) the class name stays the same.
## Cloudflare API version 4
The Cloudflare API can be found [here](https://api.cloudflare.com/).
Each API call is provided via a similarly named function within the **CloudFlare** class.
A full list is provided below.
## Example code
All example code is available on GitHub (see [package](https://github.com/cloudflare/python-cloudflare) in the [examples](https://github.com/cloudflare/python-cloudflare/tree/master/examples) folder).
## Blog
This package was initially introduced [here](https://blog.cloudflare.com/python-cloudflare/) via Cloudflare's [blog](https://blog.cloudflare.com/).
## Getting Started
A very simple listing of zones within your account; including the IPv6 status of the zone.
```python
import CloudFlare
def main():
cf = CloudFlare.CloudFlare()
zones = cf.zones.get()
for zone in zones:
zone_id = zone['id']
zone_name = zone['name']
print("zone_id=%s zone_name=%s" % (zone_id, zone_name))
if __name__ == '__main__':
main()
```
This example works when there are less than 50 zones (50 is the default number of values returned from a query like this).
Now lets expand on that and add code to show the IPv6 and SSL status of the zones. Lets also query 100 zones.
```python
import CloudFlare
def main():
cf = CloudFlare.CloudFlare()
zones = cf.zones.get(params = {'per_page':100})
for zone in zones:
zone_id = zone['id']
zone_name = zone['name']
settings_ssl = cf.zones.settings.ssl.get(zone_id)
ssl_status = settings_ssl['value']
settings_ipv6 = cf.zones.settings.ipv6.get(zone_id)
ipv6_status = settings_ipv6['value']
print("zone_id=%s zone_name=%s" % (zone_id, zone_name))
print("ssl_status=%s ipv6_status=%s" % (ssl_status, ipv6_status))
if __name__ == '__main__':
main()
```
In order to query more than a single page of zones, we would have to use the raw mode (described more below).
We can loop over many get calls and pass the page parameter to facilitate the paging.
Raw mode is only needed when a get request has the possibility of returning many items.
```python
import CloudFlare
def main():
cf = CloudFlare.CloudFlare(raw=True)
page_number = 0
while True:
page_number += 1
raw_results = cf.zones.get(params={'per_page':5,'page':page_number})
zones = raw_results['result']
for zone in zones:
zone_id = zone['id']
zone_name = zone['name']
print("zone_id=%s zone_name=%s" % (zone_id, zone_name))
total_pages = raw_results['result_info']['total_pages']
if page_number == total_pages:
break
if __name__ == '__main__':
main()
```
A more complex example follows.
```python
import CloudFlare
def main():
zone_name = 'example.com'
cf = CloudFlare.CloudFlare()
# query for the zone name and expect only one value back
try:
zones = cf.zones.get(params = {'name':zone_name,'per_page':1})
except CloudFlare.exceptions.CloudFlareAPIError as e:
exit('/zones.get %d %s - api call failed' % (e, e))
except Exception as e:
exit('/zones.get - %s - api call failed' % (e))
if len(zones) == 0:
exit('No zones found')
# extract the zone_id which is needed to process that zone
zone = zones[0]
zone_id = zone['id']
# request the DNS records from that zone
try:
dns_records = cf.zones.dns_records.get(zone_id)
except CloudFlare.exceptions.CloudFlareAPIError as e:
exit('/zones/dns_records.get %d %s - api call failed' % (e, e))
# print the results - first the zone name
print("zone_id=%s zone_name=%s" % (zone_id, zone_name))
# then all the DNS records for that zone
for dns_record in dns_records:
r_name = dns_record['name']
r_type = dns_record['type']
r_value = dns_record['content']
r_id = dns_record['id']
print('\t', r_id, r_name, r_type, r_value)
exit(0)
if __name__ == '__main__':
main()
```
## Providing Cloudflare Username and API Key
When you create a **CloudFlare** class you can pass some combination of these four core parameters.
* `email` - The account email (only if an API Key is being used)
* `api` - The API Key (if coding prior to Issue-114 being merged)
* `token` - The API Token (if coding after to Issue-114)
* `certtoken` - Optional Origin-CA Certificate Token
This parameter controls how the data is returned from a successful call (see notes below).
* `raw` - An optional Raw flag (True/False) - defaults to False
Timeouts (10s) and Retries (5) are configured by default. Should you wish to override them, use these settings:
* `global_request_timeout` - How long before each API call to Cloudflare should time out (in seconds)
* `max_requests_retries` - How many times to retry an API call when DNS lookups, socket connections, or connect timeouts occur.
> NOTE: `max_request_retries` is only available when `use_sessions` is not disabled.
The following paramaters are for debug and/or development usage
* `debug` - An optional Debug flag (True/False) - defaults to False
* `use_sessions` - An optional Use-Sessions flag (True/False) - defaults to True
* `profile` - An optional Profile name (the default is `Cloudflare`)
* `base_url` - An optional Base URL (only used for development)
email=None, key=None, token=None, certtoken=None, debug=False, raw=False, use_sessions=True, profile=None, base_url=None):
### Issue-114
After [Issue-114](https://github.com/cloudflare/python-cloudflare/issues/114) was coded and merged, the use of `token` and `key` changed; however, is backward compatible (amazingly!).
If you are using only the API Token, then don't include the API Email. If you are coding prior to Issue-114, then the API Key can also be used as an API Token if the API Email is not used.
### Python code to create class
```python
import CloudFlare
# A minimal call - reading values from environment variables or configuration file
cf = CloudFlare.CloudFlare()
# A minimal call with debug enabled
cf = CloudFlare.CloudFlare(debug=True)
# An authenticated call using an API Token (note the missing email)
cf = CloudFlare.CloudFlare(token='00000000000000000000000000000000')
# An authenticated call using an API Email and API Key
cf = CloudFlare.CloudFlare(email='user@example.com', key='00000000000000000000000000000000')
# An authenticated call using an API Token and CA-Origin info
cf = CloudFlare.CloudFlare(token='00000000000000000000000000000000', certtoken='v1.0-...')
# An authenticated call using an API Email, API Key, and CA-Origin info
cf = CloudFlare.CloudFlare(email='user@example.com', key='00000000000000000000000000000000', certtoken='v1.0-...')
# An authenticated call using using a stored profile (see below)
cf = CloudFlare.CloudFlare(profile="CompanyX"))
```
If the account email and API key are not passed when you create the class, then they are retrieved from either the users exported shell environment variables or the .cloudflare.cfg or ~/.cloudflare.cfg or ~/.cloudflare/cloudflare.cfg files, in that order.
If you're using an API Token, any `cloudflare.cfg` file must either not contain an `email` and `key` attribute (or they can be zero length strings) and the `CLOUDFLARE_EMAIL` `CLOUDFLARE_API_KEY` environment variable must be unset (or zero length strings), otherwise the token (`CLOUDFLARE_API_TOKEN` or `token` attribute) will not be used.
There is one call that presently doesn't need any email or token certification (the */ips* call); hence you can test without any values saved away.
### Using shell environment variables
Note (for latest version of code):
* `CLOUDFLARE_EMAIL` has replaced `CF_API_EMAIL`.
* `CLOUDFLARE_API_KEY` has replaced `CF_API_KEY`.
* `CLOUDFLARE_API_TOKEN` has replaced `CF_API_TOKEN`.
* `CLOUDFLARE_API_CERTKEY` has replaced `CF_API_CERTKEY`.
Additionally, these two variables are available for testing purposes:
* `CLOUDFLARE_API_EXTRAS` has replaced `CF_API_EXTRAS`.
* `CLOUDFLARE_API_URL` has replaced `CF_API_URL`.
The older environment variable names can still be used.
```bash
$ export CLOUDFLARE_EMAIL='user@example.com'
$ export CLOUDFLARE_API_KEY='00000000000000000000000000000000'
$ export CLOUDFLARE_API_CERTKEY='v1.0-...'
$
```
Or if using API Token.
```bash
$ export CLOUDFLARE_API_TOKEN='00000000000000000000000000000000'
$ export CLOUDFLARE_API_CERTKEY='v1.0-...'
$
```
These are optional environment variables; however, they do override the values set within a configuration file.
### Using configuration file to store email and keys
The default profile name is `Cloudflare` for obvious reasons.
```bash
$ cat ~/.cloudflare/cloudflare.cfg
[Cloudflare]
email = user@example.com # Do not set if using an API Token
key = 00000000000000000000000000000000
certtoken = v1.0-...
extras =
$
```
More than one profile can be stored within that file.
Here's an example for a work and home setup (in this example work has an API Token and home uses email/key).
```bash
$ cat ~/.cloudflare/cloudflare.cfg
[Work]
token = 00000000000000000000000000000000
[Home]
email = home@example.com
key = 00000000000000000000000000000000
$
```
To select a profile, use the `--profile profile-name` option for `cli4` command or use `profile="profile-name"` in the library call.
```bash
$ cli4 --profile Work /zones | jq '.[]|.name' | wc -l
13
$
$ cli4 --profile Home /zones | jq '.[]|.name' | wc -l
1
$
```
Here is the same in code.
```python
#!/usr/bin/env python
import CloudFlare
def main():
cf = CloudFlare.CloudFlare(profile="Work")
...
```
### Passing your own HTTP headers to API calls
There are very specific case where a user of the library needs to add custom headers to all HTTP calls.
This is rarly needed.
The addition headers can be passed via the confuration file as follows:
```bash
$ cat ~/.cloudflare/cloudflare.cfg
...
http_headers =
X-Header1:value
X-Header2: value1 value2 value3
X-Header3: "this is life as we know it"
X-Header4: 'two single quotes'
X-Header5:
...
$
```
Each line should have a header noun, a colon, and a verb.
You can also pass these via Python calls.
```python
import CloudFlare
http_headers = [
'X-Header1:value',
'X-Header2: value1 value2 value3',
'X-Header3: "this is life as we know it"',
'X-Header4: \'two single quotes\'',
'X-Header5:',
]
cf = CloudFlare.CloudFlare(http_headers=http_headers)
...
```
These header values can also be passed via `cli4` command (many times) - use the `-v` option to see the debug messages:
```
$ cli4 -v --header 'X-something:' --header 'X-whatever:whatever' /zones > /tmp/results.json
...
--header "X-something: " \
--header "X-whatever: whatever " \
...
$
```
### Advanced use of configuration file for authentication based on method
The configuration file can have values that are both generic and specific to the method.
Here's an example where a project has a different API Token for reading and writing values.
```bash
$ cat ~/.cloudflare/cloudflare.cfg
[Work]
token = 0000000000000000000000000000000000000000
token.get = 0123456789012345678901234567890123456789
$
```
When a GET call is processed then the second token is used. For all other calls the first token is used.
Here's a more explict verion of that config:
```bash
$ cat ~/.cloudflare/cloudflare.cfg
[Work]
token.delete = 0000000000000000000000000000000000000000
token.get = 0123456789012345678901234567890123456789
token.patch = 0000000000000000000000000000000000000000
token.post = 0000000000000000000000000000000000000000
token.put = 0000000000000000000000000000000000000000
$
```
This can be used with email values also.
### About /certificates and certtoken
The *CLOUDFLARE_API_CERTKEY* or *certtoken* values are used for the Origin-CA */certificates* API calls.
You can leave *certtoken* in the configuration with a blank value (or omit the option variable fully).
The *extras* values are used when adding API calls outside of the core codebase.
Technically, this is only useful for internal testing within Cloudflare.
You can leave *extras* in the configuration with a blank value (or omit the option variable fully).
## Exceptions and return values
### Response data
The response is build from the JSON in the API call.
It contains the **results** values; but does not contain the paging values.
You can return all the paging values by calling the class with raw=True. Here's an example without paging.
```python
#!/usr/bin/env python
import json
import CloudFlare
def main():
cf = CloudFlare.CloudFlare()
zones = cf.zones.get(params={'per_page':5})
print("len=%d" % (zones.length()))
if __name__ == '__main__':
main()
```
The results are as follows.
```
5
```
When you add the raw option; the APIs full structure is returned. This means the paging values can be seen.
```python
#!/usr/bin/env python
import json
import CloudFlare
def main():
cf = CloudFlare.CloudFlare(raw=True)
zones = cf.zones.get(params={'per_page':5})
print("len=%d" % (zones.length()))
print(json.dumps(zones, indent=4, sort_keys=True))
if __name__ == '__main__':
main()
```
This produces.
```
5
{
"result": [
...
],
"result_info": {
"count": 5,
"page": 1,
"per_page": 5,
"total_count": 31,
"total_pages": 7
}
}
```
A full example of paging is provided below.
### Exceptions
The library will raise **CloudFlareAPIError** when the API call fails.
The exception returns both an integer and textual message in one value.
```python
import CloudFlare
...
try
r = ...
except CloudFlare.exceptions.CloudFlareAPIError as e:
exit('api error: %d %s' % (e, e))
...
```
The other raised response is **CloudFlareInternalError** which can happen when calling an invalid method.
In some cases more than one error is returned. In this case the return value `e` is also an array.
You can iterate over that array to see the additional error.
```python
import sys
import CloudFlare
...
try
r = ...
except CloudFlare.exceptions.CloudFlareAPIError as e:
if len(e) > 0:
sys.stderr.write('api error - more than one error value returned!\n')
for x in e:
sys.stderr.write('api error: %d %s\n' % (x, x))
exit('api error: %d %s' % (e, e))
...
```
### Exception handling
Here's code using the CLI command `cli4` of the responses passed back in exceptions.
First a simple get with a clean (non-error) response.
```bash
$ cli4 /zones/:example.com/dns_records | jq -c '.[]|{"name":.name,"type":.type,"content":.content}'
{"name":"example.com","type":"MX","content":"something.example.com"}
{"name":"something.example.com","type":"A","content":"10.10.10.10"}
$
```
Next a simple/single error response.
This is simulated by providing incorrect authentication information.
```bash
$ CLOUDFLARE_EMAIL='someone@example.com' cli4 /zones/
cli4: /zones - 9103 Unknown X-Auth-Key or X-Auth-Email
$
```
More than one call can be done on the same command line. In this mode, the connection is preserved between calls.
```bash
$ cli4 /user/organizations /user/invites
...
$
```
Note that the output is presently two JSON structures one after the other - so less useful that you may think.
Finally, a command that provides more than one error response.
This is simulated by passing an invalid IPv4 address to a DNS record creation.
```bash
$ cli4 --post name='foo' type=A content="NOT-A-VALID-IP-ADDRESS" /zones/:example.com/dns_records
cli4: /zones/:example.com/dns_records - 9005 Content for A record is invalid. Must be a valid IPv4 address
cli4: /zones/:example.com/dns_records - 1004 DNS Validation Error
$
```
## Included example code
The [examples](https://github.com/cloudflare/python-cloudflare/tree/master/examples) folder contains many examples in both simple and verbose formats.
You can see the installed path of these files directly via `cli4 -e` (or `cli4 --examples`) command.
```bash
$ cli4 -e
Python .py files:
...
/opt/homebrew/lib/python3.11/site-packages/examples/example_always_use_https.py
...
Bash .sh files:
...
/opt/homebrew/lib/python3.11/site-packages/examples/example_paging_thru_zones.sh
...
$
```
The exact path will vary depending on your system.
The above example is MacOS and Python 3.9 hence the `/opt/homebrew/lib/python3.11/site-packages/` path.
One Linux, the Python pip command may install the code is a system location like `/usr/lib/python3/dist-packages` or `~/.local/lib/python3.9/site-packages/` or something different.
The `cli4 -e` command will try to decode the location and display the example files.
If you are running release before Python 3.9 then you will be asked to install the following:
```bash
$ pip install importlib_resources
...
$
```
It will show up if you are running on an older system. For example, this is the results from running on Win7:
```bash
U:\Users\Bobby>cli4 -e
Module "importlib_resources" missing - please "pip install importlib_resources" as your Python version is lower than 3.9
U:\Users\Bobby>python -V
Python 3.8.3
U:\Users\Bobby>
```
Upgrading from an older version of Python is always recommended. Upgrading from Win7 is by-default even more important!
## A DNS zone code example
```python
#!/usr/bin/env python
import sys
import CloudFlare
def main():
zone_name = sys.argv[1]
cf = CloudFlare.CloudFlare()
zone_info = cf.zones.post(data={'jump_start':False, 'name': zone_name})
zone_id = zone_info['id']
dns_records = [
{'name':'foo', 'type':'AAAA', 'content':'2001:d8b::1'},
{'name':'foo', 'type':'A', 'content':'192.168.0.1'},
{'name':'duh', 'type':'A', 'content':'10.0.0.1', 'ttl':120},
{'name':'bar', 'type':'CNAME', 'content':'foo'},
{'name':'shakespeare', 'type':'TXT', 'content':"What's in a name? That which we call a rose by any other name ..."}
]
for dns_record in dns_records:
r = cf.zones.dns_records.post(zone_id, data=dns_record)
exit(0)
if __name__ == '__main__':
main()
```
## A DNS zone delete code example (be careful)
```python
#!/usr/bin/env python
import sys
import CloudFlare
def main():
zone_name = sys.argv[1]
cf = CloudFlare.CloudFlare()
zone_info = cf.zones.get(params={'name': zone_name})
zone_id = zone_info['id']
dns_name = sys.argv[2]
dns_records = cf.zones.dns_records.get(zone_id, params={'name':dns_name + '.' + zone_name})
for dns_record in dns_records:
dns_record_id = dns_record['id']
r = cf.zones.dns_records.delete(zone_id, dns_record_id)
exit(0)
if __name__ == '__main__':
main()
```
## CLI
All API calls can be called from the command line via the `cli4` command.
Additionally, the `cli4` command will convert domain name or account name prefixed with a colon (`:`) into the correct identifier.
e.g. to view `example.com` you can use `cli4 /zones/:example.com`.
You can pass the zone identifier (or account identifier or any identifier) with a colon followed by the identifier as a hex number 32 characters long.
```bash
$ cli4 [-V|--version] [-h|--help] [-v|--verbose] \
[-e|--examples] \
[-q|--quiet] \
[-j|--json] [-y|--yaml] [-n|--ndjson] [-i|--image] \
[-r|--raw] \
[-d|--dump] \
[-A|--openapi url] \
[-b|--binary] \
[-p|--profile profile-name] \
[-h|--header additional-header] \
[-w|--warnings [True|False]] \
[--get|--patch|--post|--put|--delete] \
[item=value|item=@filename|@filename ...] /command ...
```
### CLI parameters for POST/PUT/PATCH
For API calls that need to pass data or parameters there is various formats to use.
The simplest form is `item=value`. This passes the value as a string within the APIs JSON data.
If you need a numeric value passed then `==` can be used to force the value to be treated as a numeric value within the APIs JSON data.
For example: `item==value`.
if you need to pass a list of items; then `[]` can be used. For example:
```bash
pool_id1="11111111111111111111111111111111"
pool_id2="22222222222222222222222222222222"
pool_id3="33333333333333333333333333333333"
cli4 --post global_pools="[ ${pool_id1}, ${pool_id2}, ${pool_id3} ]" region_pools="[ ]" /user/load_balancers/maps
```
Data or parameters can be either named or unnamed.
It can not be both.
Named is the majority format; as described above.
Unnamed parameters simply don't have anything before the `=` sign, as in `=value`.
This format is presently only used by the Cloudflare Load Balancer API calls.
For example:
```bash
cli4 --put ="00000000000000000000000000000000" /user/load_balancers/maps/:00000000000000000000000000000000/region/:WNAM
```
Data can also be uploaded from file contents. Using the `item=@filename` format will open the file and the contents uploaded in the POST.
### CLI output
The default output from the CLI command is in JSON.
It can also output YAML format (i.e. human readable).
This is controled by the `--yaml` or `--json` flags (JSON is the default).
There is also a `--ndjson` flag for use with line based JSON data - this is mainly used for log data.
Additonally the output can be plain text or binary image format depending on the results from the API call (some calls results in non JSON results).
The `--image` flag will return the data in the same format as the API's results.
### Simple CLI calls
* `cli4 /user/billing/profile`
* `cli4 /user/invites`
* `cli4 /zones/:example.com`
* `cli4 /zones/:example.com/dnssec`
* `cli4 /zones/:example.com/settings/ipv6`
* `cli4 --put /zones/:example.com/activation_check`
* `cli4 /zones/:example.com/keyless_certificates`
* `cli4 /zones/:example.com/analytics/dashboard`
### More complex CLI calls
Here is the creation of a DNS entry, followed by a listing of that entry and then the deletion of that entry.
```bash
$ $ cli4 --post name="test" type="A" content="10.0.0.1" /zones/:example.com/dns_records
{
"id": "00000000000000000000000000000000",
"name": "test.example.com",
"type": "A",
"content": "10.0.0.1",
...
}
$
$ cli4 /zones/:example.com/dns_records/:test.example.com | jq '{"id":.id,"name":.name,"type":.type,"content":.content}'
{
"id": "00000000000000000000000000000000",
"name": "test.example.com",
"type": "A",
"content": "10.0.0.1"
}
$ cli4 --delete /zones/:example.com/dns_records/:test.example.com | jq -c .
{"id":"00000000000000000000000000000000"}
$
```
There's the ability to handle dns entries with multiple values.
This produces more than one API call within the command.
```bash
$ cli4 /zones/:example.com/dns_records/:test.example.com | jq -c '.[]|{"id":.id,"name":.name,"type":.type,"content":.content}'
{"id":"00000000000000000000000000000000","name":"test.example.com","type":"A","content":"192.168.0.1"}
{"id":"00000000000000000000000000000000","name":"test.example.com","type":"AAAA","content":"2001:d8b::1"}
$
```
Here are the cache purging commands.
```bash
$ cli4 --delete purge_everything=true /zones/:example.com/purge_cache | jq -c .
{"id":"00000000000000000000000000000000"}
$
$ cli4 --delete files='[http://example.com/css/styles.css]' /zones/:example.com/purge_cache | jq -c .
{"id":"00000000000000000000000000000000"}
$
$ cli4 --delete files='[http://example.com/css/styles.css,http://example.com/js/script.js]' /zones/:example.com/purge_cache | jq -c .
{"id":"00000000000000000000000000000000"}
$
$ cli4 --delete tags='[tag1,tag2,tag3]' /zones/:example.com/purge_cache | jq -c .
cli4: /zones/:example.com/purge_cache - 1107 Only enterprise zones can purge by tag.
$
```
A somewhat useful listing of available plans for a specific zone.
```bash
$ cli4 /zones/:example.com/available_plans | jq -c '.[]|{"id":.id,"name":.name}'
{"id":"00000000000000000000000000000000","name":"Pro Website"}
{"id":"00000000000000000000000000000000","name":"Business Website"}
{"id":"00000000000000000000000000000000","name":"Enterprise Website"}
{"id":"0feeeeeeeeeeeeeeeeeeeeeeeeeeeeee","name":"Free Website"}
$
```
### Cloudflare CA CLI calls
Here's some Cloudflare CA calls. Note the need of the `zone_id=` parameter with the basic `/certificates` call.
```bash
$ cli4 /zones/:example.com | jq -c '.|{"id":.id,"name":.name}'
{"id":"12345678901234567890123456789012","name":"example.com"}
$
$ cli4 zone_id=12345678901234567890123456789012 /certificates | jq -c '.[]|{"id":.id,"expires_on":.expires_on,"hostnames":.hostnames,"certificate":.certificate}'
{"id":"123456789012345678901234567890123456789012345678","expires_on":"2032-01-29 22:36:00 +0000 UTC","hostnames":["*.example.com","example.com"],"certificate":"-----BEGIN CERTIFICATE-----\n ... "}
{"id":"123456789012345678901234567890123456789012345678","expires_on":"2032-01-28 23:23:00 +0000 UTC","hostnames":["*.example.com","example.com"],"certificate":"-----BEGIN CERTIFICATE-----\n ... "}
{"id":"123456789012345678901234567890123456789012345678","expires_on":"2032-01-28 23:20:00 +0000 UTC","hostnames":["*.example.com","example.com"],"certificate":"-----BEGIN CERTIFICATE-----\n ... "}
$
```
A certificate can be viewed via a simple GET request.
```bash
$ cli4 /certificates/:123456789012345678901234567890123456789012345678
{
"certificate": "-----BEGIN CERTIFICATE-----\n ... ",
"expires_on": "2032-01-29 22:36:00 +0000 UTC",
"hostnames": [
"*.example.com",
"example.com"
],
"id": "123456789012345678901234567890123456789012345678",
"request_type": "origin-rsa"
}
$
```
Creating a certificate. This is done with a `POST` request. Note the use of `==` in order to pass a decimal number (vs. string) in JSON. The CSR is not shown for simplicity sake.
```bash
$ CSR=`cat example.com.csr`
$ cli4 --post hostnames='["example.com","*.example.com"]' requested_validity==365 request_type="origin-ecc" csr="$CSR" /certificates
{
"certificate": "-----BEGIN CERTIFICATE-----\n ... ",
"csr": "-----BEGIN CERTIFICATE REQUEST-----\n ... ",
"expires_on": "2018-09-27 21:47:00 +0000 UTC",
"hostnames": [
"*.example.com",
"example.com"
],
"id": "123456789012345678901234567890123456789012345678",
"request_type": "origin-ecc",
"requested_validity": 365
}
$
```
Deleting a certificate can be done with a `DELETE` call.
```bash
$ cli4 --delete /certificates/:123456789012345678901234567890123456789012345678
{
"id": "123456789012345678901234567890123456789012345678",
"revoked_at": "0000-00-00T00:00:00Z"
}
$
```
### Paging CLI calls
The `--raw` command provides access to the paging returned values.
See the API documentation for all the info.
Here's an example of how to page thru a list of zones (it's included in the examples folder as `example_paging_thru_zones.sh`).
Note the use of `==` to pass a number vs a string as paramater.
```bash
:
tmp=/tmp/$$_
trap "rm ${tmp}; exit 0" 0 1 2 15
PAGE=0
while true
do
cli4 --raw per_page==5 page==${PAGE} /zones > ${tmp}
domains=`jq -c '.|.result|.[]|.name' < ${tmp} | tr -d '"'`
result_info=`jq -c '.|.result_info' < ${tmp}`
COUNT=` echo "${result_info}" | jq .count`
PAGE=` echo "${result_info}" | jq .page`
PER_PAGE=` echo "${result_info}" | jq .per_page`
TOTAL_COUNT=`echo "${result_info}" | jq .total_count`
TOTAL_PAGES=`echo "${result_info}" | jq .total_pages`
echo COUNT=${COUNT} PAGE=${PAGE} PER_PAGE=${PER_PAGE} TOTAL_COUNT=${TOTAL_COUNT} TOTAL_PAGES=${TOTAL_PAGES} -- ${domains}
if [ "${PAGE}" == "${TOTAL_PAGES}" ]
then
## last section
break
fi
# grab the next page
PAGE=`expr ${PAGE} + 1`
done
```
It produces the following results.
```bash
COUNT=5 PAGE=1 PER_PAGE=5 TOTAL_COUNT=31 TOTAL_PAGES=7 -- accumsan.example auctor.example consectetur.example dapibus.example elementum.example
COUNT=5 PAGE=2 PER_PAGE=5 TOTAL_COUNT=31 TOTAL_PAGES=7 -- felis.example iaculis.example ipsum.example justo.example lacus.example
COUNT=5 PAGE=3 PER_PAGE=5 TOTAL_COUNT=31 TOTAL_PAGES=7 -- lectus.example lobortis.example maximus.example morbi.example pharetra.example
COUNT=5 PAGE=4 PER_PAGE=5 TOTAL_COUNT=31 TOTAL_PAGES=7 -- porttitor.example potenti.example pretium.example purus.example quisque.example
COUNT=5 PAGE=5 PER_PAGE=5 TOTAL_COUNT=31 TOTAL_PAGES=7 -- sagittis.example semper.example sollicitudin.example suspendisse.example tortor.example
COUNT=1 PAGE=7 PER_PAGE=5 TOTAL_COUNT=31 TOTAL_PAGES=7 -- varius.example vehicula.example velit.example velit.example vitae.example
COUNT=5 PAGE=6 PER_PAGE=5 TOTAL_COUNT=31 TOTAL_PAGES=7 -- vivamus.example
```
### Paging thru lists (using cursors)
Some API calls use cursors to read beyond the initally returned values. See the API page in order to see which API calls do this.
```bash
$ ACCOUNT_ID="00000000000000000000000000000000"
$ LIST_ID="00000000000000000000000000000000"
$
$ cli4 --raw /accounts/::${ACCOUNT_ID}/rules/lists/::${LIST_ID}/items > /tmp/page1.json
$ after=`jq -r '.result_info.cursors.after' < /tmp/page1.json`
$ echo "after=$after"
after=Mxm4GVmKjYbFjy2VxMPipnJigm1M_s6lCS9ABR9wx-RM2A
$
```
Once we have the `after` value, we can pass it along in order to read the next hunk of values. We finish when `after` returns as null (or isn't present).
```bash
$ cli4 --raw cursor="$after" /accounts/::${ACCOUNT_ID}/rules/lists/::${LIST_ID}/items > /tmp/page2.json
$ after=`jq -r '.result_info.cursors.after' < /tmp/page2.json`
$ echo "after=$after"
after=null
$
```
We can see the results now in two files.
```bash
$ jq -c '.result[]' < /tmp/page1.json | wc -l
25
$
$ jq -c '.result[]' < /tmp/page2.json | wc -l
5
$
$ for f in /tmp/page?.json ; do jq -r '.result[]|.id,.ip,.comment' < $f | paste - - - ; done | column -s' ' -t
0fe44928258549feb47126a966fbf4a0 0.0.0.0 all zero
2e1e02120f5e466f8c0e26375e4cf4c8 1.0.0.1 Cloudflare DNS a
9ca5fd0ac6f54fdbb9dedd3fb72ce2da 1.1.1.1 Cloudflare DNS b
b3654987446743738c782f36ebe074f5 10.0.0.0/8 RFC1918 space
90bec8ce37d242faa2e27d1e78c1d8e2 103.21.244.0/22 Cloudflare IP
970a3c810cda41af9bef2c36a1892f7e 103.22.200.0/22 Cloudflare IP
3ec8516158bf4f3cac18210f611ee541 103.31.4.0/22 Cloudflare IP
ee9d268367204e6bb8e5e4c907f22de8 104.16.0.0/12 Cloudflare IP
93ae02eda9774c45840af367a02fe529 108.162.192.0/18 Cloudflare IP
62891ebf6db44aa494d79a6401af185e 131.0.72.0/22 Cloudflare IP
cac40cd940cc470582b8c912a8a12bea 141.101.64.0/18 Cloudflare IP
f6d5eacd81a2407f8e0d81caee21e7f8 162.158.0.0/15 Cloudflare IP
3d538dfc38ab471d9d3fe78332acfa4e 172.16.0.0/12 RFC1918 space
f353cb8f98424837ad35382a22b9debe 172.64.0.0/13 Cloudflare IP
78f3e1a0bafc41f88d4d40ad49a642e0 173.245.48.0/20 Cloudflare IP
c23a545475c54c32a7681c6b508d3e80 188.114.96.0/20 Cloudflare IP
f693237c9e294fe481221cbc2d7c20ef 190.93.240.0/20 Cloudflare IP
6d465ab3a0994c07827ebdcf8f34d977 192.168.0.0/16 RFC1918 space
1ad1e634b3664bac939086185c62faf7 197.234.240.0/22 Cloudflare IP
5d2968e7b3114d8e869a379d71c8ba86 198.41.128.0/17 Cloudflare IP
6a69de60b31448fa864f0a3ac5abe8d0 224.0.0.0/24 Multicast
30749cce89af4ab3a80e308294f46a46 240.0.0.0/4 Class E
2b32c67ea4d044628abe39f28662d8f0 255.255.255.255 all ones
cc7cd828b2fb4bcfb9391c2d3ef8d068 2400:cb00::/32 Cloudflare IP
b30d4cbd7dcd48729e8ebeda552e48a8 2405:8100::/32 Cloudflare IP
49db60758c8344959c338a74afc9748a 2405:b500::/32 Cloudflare IP
96e9eca1923c40d5a84865145f5a5d6a 2606:4700::/32 Cloudflare IP
21bc52a26e10405d89b7180ddcf49302 2803:f800::/32 Cloudflare IP
ff78f842188e4b869eb5389ae9ab8f41 2a06:98c0::/29 Cloudflare IP
0880cdfc40b14f6fa0639522a728859d 2c0f:f248::/32 Cloudflare IP
$
```
The `result_info.cursors` area also contains a `before` value for reverse scrolling.
As with `per_page` scrolling, raw mode is used.
### DNSSEC CLI calls
```bash
$ cli4 /zones/:example.com/dnssec | jq -c '{"status":.status}'
{"status":"disabled"}
$
$ cli4 --patch status=active /zones/:example.com/dnssec | jq -c '{"status":.status}'
{"status":"pending"}
$
$ cli4 /zones/:example.com/dnssec
{
"algorithm": "13",
"digest": "41600621c65065b09230ebc9556ced937eb7fd86e31635d0025326ccf09a7194",
"digest_algorithm": "SHA256",
"digest_type": "2",
"ds": "example.com. 3600 IN DS 2371 13 2 41600621c65065b09230ebc9556ced937eb7fd86e31635d0025326ccf09a7194",
"flags": 257,
"key_tag": 2371,
"key_type": "ECDSAP256SHA256",
"modified_on": "2016-05-01T22:42:15.591158Z",
"public_key": "mdsswUyr3DPW132mOi8V9xESWE8jTo0dxCjjnopKl+GqJxpVXckHAeF+KkxLbxILfDLUT0rAK9iUzy1L53eKGQ==",
"status": "pending"
}
$
```
### Zone file upload (i.e. import) CLI calls (uses BIND format files)
Refer to [Import DNS records](https://api.cloudflare.com/#dns-records-for-a-zone-import-dns-records) on API documentation for this feature.
```bash
$ cat zone.txt
example.com. IN SOA somewhere.example.com. someone.example.com. (
2017010101
3H
15
1w
3h
)
record1.example.com. IN A 10.0.0.1
record2.example.com. IN AAAA 2001:d8b::2
record3.example.com. IN CNAME record1.example.com.
record4.example.com. IN TXT "some text"
$
$ cli4 --post file=@zone.txt /zones/:example.com/dns_records/import
{
"recs_added": 4,
"total_records_parsed": 4
}
$
```
### Zone file upload (i.e. import) Python calls (uses BIND format files)
Because `import` is a keyword (or reserved word) in Python we append a `_` (underscore) to the verb in order to use.
The `cli4` command does not need this edit.
```python
#
# "import" is a reserved word and hence we add '_' to the end of verb.
#
r = cf.zones.dns_records.import_.post(zone_id, files={'file':fd})
```
See [examples/example_dns_import.py](https://github.com/cloudflare/python-cloudflare/tree/master/examples/example_dns_import.py) for working code.
### Zone file download (i.e. export) CLI calls (uses BIND format files)
The following is documented within the **Advanced** option of the DNS page within the Cloudflare portal.
```bash
$ cli4 /zones/:example.com/dns_records/export | egrep -v '^;;|^$'
$ORIGIN .
@ 3600 IN SOA example.com. root.example.com. (
2025552311 ; serial
7200 ; refresh
3600 ; retry
86400 ; expire
3600) ; minimum
example.com. 300 IN NS REPLACE&ME$WITH^YOUR@NAMESERVER.
record4.example.com. 300 IN TXT "some text"
record3.example.com. 300 IN CNAME record1.example.com.
record1.example.com. 300 IN A 10.0.0.1
record2.example.com. 300 IN AAAA 2001:d8b::2
$
```
The egrep is used for documentation brevity.
This can also be done via Python code with the following example.
```python
#!/usr/bin/env python
import sys
import CloudFlare
def main():
zone_name = sys.argv[1]
cf = CloudFlare.CloudFlare()
zones = cf.zones.get(params={'name': zone_name})
zone_id = zones[0]['id']
dns_records = cf.zones.dns_records.export.get(zone_id)
for l in dns_records.splitlines():
if len(l) == 0 or l[0] == ';':
continue
print(l)
exit(0)
if __name__ == '__main__':
main()
```
### Cloudflare Workers
Cloudflare Workers are described on the Cloudflare blog at
[here](https://blog.cloudflare.com/introducing-cloudflare-workers/) and
[here](https://blog.cloudflare.com/code-everywhere-cloudflare-workers/), with the beta release announced
[here](https://blog.cloudflare.com/cloudflare-workers-is-now-on-open-beta/).
The Python libraries now support the Cloudflare Workers API calls. The following javascript is lifted from [https://cloudflareworkers.com/](https://cloudflareworkers.com/) and slightly modified.
```bash
$ cat modify-body.js
addEventListener("fetch", event => {
event.respondWith(fetchAndModify(event.request));
});
async function fetchAndModify(request) {
console.log("got a request:", request);
// Send the request on to the origin server.
const response = await fetch(request);
// Read response body.
const text = await response.text();
// Modify it.
const modified = text.replace(
"<body>",
"<body style=\"background: #ff0;\">");
// Return modified response.
return new Response(modified, {
status: response.status,
statusText: response.statusText,
headers: response.headers
});
}
$
```
Here's the website with it's simple `<body>` statement
```bash
$ curl -sS https://example.com/ | fgrep '<body'
<body>
$
```
Now lets add the script. Looking above, you will see that it's simple action is to modify the `<body>` statement and make the background yellow.
```bash
$ cli4 --put @- /zones/:example.com/workers/script < modify-body.js
{
"etag": "1234567890123456789012345678901234567890123456789012345678901234",
"id": "example-com",
"modified_on": "2018-02-15T00:00:00.000000Z",
"script": "addEventListener(\"fetch\", event => {\n event.respondWith(fetchAndModify(event.request));\n});\n\nasync function fetchAndModify(request) {\n console.log(\"got a request:\", request);\n\n // Send the request on to the origin server.\n const response = await fetch(request);\n\n // Read response body.\n const text = await response.text();\n\n // Modify it.\n const modified = text.replace(\n \"<body>\",\n \"<body style=\\\"background: #ff0;\\\">\");\n\n // Return modified response.\n return new Response(modified, {\n status: response.status,\n statusText: response.statusText,\n headers: response.headers\n });\n}\n",
"size": 603
}
$
```
The following call checks that the script is associated with the zone. In this case, it's the only script added by this user.
```bash
$ cli4 /user/workers/scripts
[
{
"created_on": "2018-02-15T00:00:00.000000Z",
"etag": "1234567890123456789012345678901234567890123456789012345678901234",
"id": "example-com",
"modified_on": "2018-02-15T00:00:00.000000Z"
}
]
$
```
Next step is to make sure a route is added for that script on that zone.
```bash
$ cli4 --post pattern="example.com/*" script="example-com" /zones/:example.com/workers/routes
{
"id": "12345678901234567890123456789012"
}
$
$ cli4 /zones/:example.com/workers/routes
[
{
"id": "12345678901234567890123456789012",
"pattern": "example.com/*",
"script": "example-com"
}
]
$
```
With that script added to the zone and the route added, we can now see the website has been modified because of the Cloudflare Worker.
```bash
$ curl -sS https://example.com/ | fgrep '<body'
<body style="background: #ff0;">
$
```
All this can be removed; hence bringing the website back to its initial state.
```bash
$ cli4 --delete /zones/:example.com/workers/script
12345678901234567890123456789012
$ cli4 --delete /zones/:example.com/workers/routes/:12345678901234567890123456789012
true
$
$ curl -sS https://example.com/ | fgrep '<body'
<body>
$
```
Refer to the Cloudflare Workers API documentation for more information.
## Cloudflare Instant Logs
Please see https://developers.cloudflare.com/logs/instant-logs for all the information on how to use this feature.
The `cli4` command along with the Python libaries can be used to control the instant logs; however, the websocket reading is outside the scope of this library.
To query the states of the instant logs:
```bash
$ cli4 /zones/:example.com/logpush/edge/jobs | jq .
[]
$
```
To add monitoring:
```bash
$ cli4 --post \
='{
"fields": "ClientIP,ClientRequestHost,ClientRequestMethod,ClientRequestURI,EdgeEndTimestamp,EdgeResponseBytes,EdgeResponseStatus,EdgeStartTimestamp,RayID",
"sample": 1,
"filter": "",
"kind": "instant-logs"
}' \
/zones/:example.com/logpush/edge/jobs | jq .
{
"destination_conf": "wss://logs.cloudflare.com/instant-logs/ws/sessions/00000000000000000000000000000000",
"fields": "ClientIP,ClientRequestHost,ClientRequestMethod,ClientRequestURI,EdgeEndTimestamp,EdgeResponseBytes,EdgeResponseStatus,EdgeStartTimestamp,RayID",
"filter": "",
"kind": "instant-logs",
"sample": 1,
"session_id": "00000000000000000000000000000000"
}
$
```
To see the results:
```bash
$ cli4 /zones/:example.com/logpush/edge/jobs | jq .
[
{
"fields": "ClientIP,ClientRequestHost,ClientRequestMethod,ClientRequestURI,EdgeEndTimestamp,EdgeResponseBytes,EdgeResponseStatus,EdgeStartTimestamp,RayID",
"filter": "",
"kind": "instant-logs",
"sample": 1,
"session_id": "00000000000000000000000000000000"
}
]
$
```
## Cloudflare GraphQL
The GraphQL interface can be accessed via the command line or via Python.
```
query="""
query {
viewer {
zones(filter: {zoneTag: "%s"} ) {
httpRequests1dGroups(limit:40, filter:{date_lt: "%s", date_gt: "%s"}) {
sum { countryMap { bytes, requests, clientCountryName } }
dimensions { date }
}
}
}
}
""" % (zone_id, date_before[0:10], date_after[0:10])
r = cf.graphql.post(data={'query':query})
httpRequests1dGroups = zone_info = r['data']['viewer']['zones'][0]['httpRequests1dGroups']
```
See the [examples/example_graphql.sh](examples/example_graphql.sh) and [examples/example_graphql.py](https://github.com/cloudflare/python-cloudflare/tree/master/examples/example_graphql.py) files for working examples.
Here is the working example of the shell version:
```bash
$ examples/example_graphql.sh example.com
2020-07-14T02:00:00Z 34880
2020-07-14T03:00:00Z 18953
2020-07-14T04:00:00Z 28700
2020-07-14T05:00:00Z 2358
2020-07-14T06:00:00Z 34905
2020-07-14T07:00:00Z 779
2020-07-14T08:00:00Z 35450
2020-07-14T10:00:00Z 17803
2020-07-14T11:00:00Z 32678
2020-07-14T12:00:00Z 19947
2020-07-14T13:00:00Z 4956
2020-07-14T14:00:00Z 34585
2020-07-14T15:00:00Z 3022
2020-07-14T16:00:00Z 5224
2020-07-14T18:00:00Z 79482
2020-07-14T21:00:00Z 10609
2020-07-14T22:00:00Z 5740
2020-07-14T23:00:00Z 2545
2020-07-15T01:00:00Z 10777
$
```
For more information on how to use GraphQL at Cloudflare, refer to the [Cloudflare GraphQL Analytics API](https://developers.cloudflare.com/analytics/graphql-api).
It contains a full overview of Cloudflare's GraphQL features and keywords.
## Cloudflare AI
See https://blog.cloudflare.com/workers-ai-update-stable-diffusion-code-llama-workers-ai-in-100-cities/ for the introduction,
along with https://developers.cloudflare.com/workers-ai/models/ for the nitty gritty details.
There are three AI calls included within the example folder.
### Image creation.
```bash
$ python examples/example_ai_images.py A happy llama running through an orange cloud > /tmp/image.png
$
$ file /tmp/image.png
/tmp/image.png: PNG image data, 1024 x 1024, 8-bit/color RGB, non-interlaced
$
```
### Translation.
```bash
$ python examples/example_ai_translate.py I\'ll have an order of the moule frites
Je vais avoir une commande des frites de moule
$
```
### Speech Recognition with the openai/whisper model.
The following downloads a speech as an mp3 file and passes it to the AI API.
It does a very good job transcribing; however, there's a good chance these mp3 files were use for training.
That said, the example code is here to show how the API works vs testing the AI/ML quality.
```bash
$ python examples/example_ai_speechrecognition.py
mp3 received: length=700367
My fellow Americans, Michelle and I have been so touched by all the well wishes that we've received over the past few weeks. But tonight, tonight it's my turn to say thanks.
$
```
This is presently work-in-progress because of the non-Python calling method. The syntax could change in the future.
They can also be called via `cli4`.
```bash
$ cli4 --image --post text="I'll have an order of the moule frites" source_lang=english target_lang=french /accounts/:AccountID/ai/run/@cf/meta/m2m100-1.2b
{'translated_text': 'Je vais avoir une commande des frites de moule'}
$
```
Presently you will need the following in your `cloudflare.cfg` file.
```bash
$ cat ~/.cloudflare/cloudflare.cfg
[CloudFlare]
global_request_timeout = 120
max_request_retries = 1
extras =
/accounts/:id/ai/run/@cf/meta/llama-2-7b-chat-fp16
/accounts/:id/ai/run/@cf/meta/llama-2-7b-chat-int8
/accounts/:id/ai/run/@cf/mistral/mistral-7b-instruct-v0.1
/accounts/:id/ai/run/@cf/openai/whisper
/accounts/:id/ai/run/@cf/meta/m2m100-1.2b
/accounts/:id/ai/run/@cf/huggingface/distilbert-sst-2-int8
/accounts/:id/ai/run/@cf/microsoft/resnet-50
/accounts/:id/ai/run/@cf/stabilityai/stable-diffusion-xl-base-1.0
/accounts/:id/ai/run/@cf/baai/bge-base-en-v1.5
/accounts/:id/ai/run/@cf/baai/bge-large-en-v1.5
/accounts/:id/ai/run/@cf/baai/bge-small-en-v1.5
$
```
As the `@` (at) symbol and the `.` (dot) symbol aren't allowed in python variable names; you'll have the replace `@cf` with `at_cf` and `.` with `_`.
There's already notes above that state that `-` (dash) is replaced with `_` in the code.
That will be needed with some model names.
The `cli4` command does not need this edit. It is done on the fly!
For example, the following code is valid:
```python
r = cf.accounts.ai.run.at_cf.openai.whisper.post(account_id, data=audio_data)
r = cf.accounts.ai.run.at_cf.meta.m2m100_1_2b.post(account_id, data=translate_data)
r = cf.accounts.ai.run.at_cf.stabilityai.stable_diffusion_xl_base_1_0.post(account_id, data=image_create_data)
```
Or you can use the `find()` call can will do this conversion for you.
```python
translate_data = {'text':"I'll have an order of the moule frites", 'source_lang':'english', 'target_lang':'french'}
m = cf.find('/accounts/:id/ai/run/@cf/meta/m2m100-1.2b')
r = m.post(account_id, data=translate_data)
print(r['translated_text'])
```
You will also have to run with a version of the library above `2.18.2`.
## Implemented API calls
The `--dump` argument to cli4 will produce a list of all the call implemented within the library.
```bash
$ cli4 --dump
/certificates
/ips
/organizations
...
/zones/ssl/analyze
/zones/ssl/certificate_packs
/zones/ssl/verification
$
```
### Table of commands
An automatically generated table of commands is provided [here](TABLE-OF-COMMANDS.md).
## Adding extra API calls manually
Extra API calls can be added via the configuration file
```bash
$ cat ~/.cloudflare/cloudflare.cfg
[Cloudflare]
extras =
/client/v4/command
/client/v4/command/:command_identifier
/client/v4/command/:command_identifier/settings
$
```
While it's easy to call anything within Cloudflare's API, it's not very useful to add items in here as they will simply return API URL errors.
Technically, this is only useful for internal testing within Cloudflare.
## Issues
The following error can be caused by an out of date SSL/TLS library and/or out of date Python.
```bash
/usr/local/lib/python2.7/dist-packages/requests/packages/urllib3/util/ssl_.py:318: SNIMissingWarning: An HTTPS request has been made, but the SNI (Subject Name Indication) extension to TLS is not available on this platform. This may cause the server to present an incorrect TLS certificate, which can cause validation failures. You can upgrade to a newer version of Python to solve this. For more information, see https://urllib3.readthedocs.org/en/latest/security.html#snimissingwarning.
SNIMissingWarning
/usr/local/lib/python2.7/dist-packages/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see https://urllib3.readthedocs.org/en/latest/security.html#insecureplatformwarning.
InsecurePlatformWarning
```
The solution can be found [here](https://urllib3.readthedocs.org/en/latest/security.html#insecureplatformwarning) and/or [here](http://stackoverflow.com/questions/35144550/how-to-install-cryptography-on-ubuntu).
## Python 2.x vs 3.x support
As of May/June 2016 the code is now tested against pylint.
This was required in order to move the codebase into Python 3.x.
The motivation for this came from [Danielle Madeley (danni)](https://github.com/danni).
~~While the codebase has been edited to run on Python 3.x, there's not been enough Python 3.x testing performed.~~
~~If you can help in this regard; please contact the maintainers.~~
As of January 2020 the code is Python3 clean.
As of January 2020 the code is shipped up to pypi with Python2 support removed.
As of January 2020 the code is Python3.8 clean. The new `SyntaxWarning` messages (i.e. `SyntaxWarning: "is" with a literal. Did you mean "=="?`) meant minor edits were needed.
As of late 2023 the code is Python3.11 clean.
As of April 2024 the code is officially marked as 3.x only (3.6 and above to be specific) such that it can become PEP561 specific.
## pypi and GitHub signed releases
As of October/2022, the code is signed by the maintainers personal email address: `mahtin@mahtin.com` `7EA1 39C4 0C1C 842F 9D41 AAF9 4A34 925D 0517 2859`
## Credit
This is based on work by [Felix Wong (gnowxilef)](https://github.com/gnowxilef) found [here](https://github.com/cloudflare-api/python-cloudflare-v4).
It has been seriously expanded upon.
## Changelog
An automatically generated CHANGELOG is provided [here](CHANGELOG.md).
## Copyright
Copyright (c) 2016 thru 2024, Cloudflare. All rights reserved.
Previous portions copyright [Felix Wong (gnowxilef)](https://github.com/gnowxilef).
|