variable "zone_id" { description = "Cloudflare zone ID for the domain being onboarded." type = string } variable "account_id" { description = "Cloudflare account ID (used by account-scoped resources)." type = string default = "" } variable "origin_ip" { description = "Origin server IP the CDN proxies to. Only the CDN ever talks to it; clients never see it (doc/05 §2)." type = string } variable "api_hostnames" { description = "Proxied hostnames served by this zone (API pool / subscription / website mirror)." type = list(string) } variable "origin_auth_header" { description = "Header name the CDN injects on origin requests; the Go originauth middleware checks it." type = string default = "X-Origin-Auth" } variable "origin_auth_value" { description = "Secret origin-auth value. Provide via TF_VAR_origin_auth_value env var — NEVER commit it. Rotated quarterly (doc/06 §6)." type = string sensitive = true } variable "rate_limit_requests_per_minute" { description = "Per-IP request budget for /v1/* before mitigation." type = number default = 120 } variable "rate_limit_mitigation_seconds" { description = "How long an offending IP stays blocked." type = number default = 600 } variable "enable_bot_management" { description = "Enable the cloudflare_bot_management resource (requires Pro+/Bot Management on the plan)." type = bool default = true }