This repo exists because traffic integrity problems usually begin at the edge, not in the analytics warehouse.
The usual failure modes are familiar:
- pricing and product routes get scraped before rate limits tighten
- synthetic traffic consumes ad spend and distorts attribution
- forms become intake noise because edge rules are too broad or too late
- Cloudflare controls live in the dashboard but not in a reusable infrastructure pattern
cf-bot-shield-tf was designed as a Kinetic Gain portfolio build to show how Cloudflare WAF and bot controls can be expressed as repeatable Terraform-backed systems with commercial context attached.
The operating principle is simple:
- define the rule
- inspect the threat lane
- encode the shield in Terraform
- tune for both protection and acquisition safety