What Cloudflare API permissions are required for TrueNAS SCALE Let's Encrypt integration?

Responsive Ad Header

Question

Grade: Education Subject: Support
What Cloudflare API permissions are required for TrueNAS SCALE Let's Encrypt integration?
Asked by:
89 Viewed 89 Answers

Answer (89)

Best Answer
(433)
The Cloudflare API token used with TrueNAS SCALE's Let's Encrypt application *requires* at a minimum the 'Zone:DNS:Edit' permission. This allows TrueNAS SCALE to automatically create and manage the necessary TXT records for DNS challenge verification. Granting broader permissions isn't necessary and is generally discouraged for security reasons. 'Zone:Read' is also helpful for initial domain discovery but not strictly required.