Question
What Cloudflare API permissions are required for TrueNAS SCALE Let's Encrypt integration?
Asked by: USER6771
89 Viewed
89 Answers
Answer (89)
The Cloudflare API token used with TrueNAS SCALE's Let's Encrypt application *requires* at a minimum the 'Zone:DNS:Edit' permission. This allows TrueNAS SCALE to automatically create and manage the necessary TXT records for DNS challenge verification. Granting broader permissions isn't necessary and is generally discouraged for security reasons. 'Zone:Read' is also helpful for initial domain discovery but not strictly required.