Ruk-ComMANAGED CLOUDFLARE

GLOBAL CDN & WEBSITE SECURITY

A faster website.
Stronger protection.
Managed by Ruk-Com.

Put Cloudflare’s network to work for your website, with our Thai support team and AI Agent managing CDN, WAF and configuration through APIs.

1,000THB / domain / month

Ruk-Com management fee · Cloudflare plans and add-ons billed separately

Connect users to your business
Illustrative traffic detection Safe traffic Threat blocked
NETWORK & PROTECTION BYCloudflare
From the global edge
to your origin
01
Speed where it matters

Deliver closer. Reduce origin work.

02
Protection built around your site

Tune WAF, bots and API policies.

03
A team to take care of it

Analyze, adjust and verify with our Agent.

PERFORMANCE, BY DESIGN

Closer to your users.
Lighter on your origin.

Your website serves both public content and personal data. We plan what to cache and how traffic travels, improving delivery while preserving application behavior.

THE REQUEST JOURNEYIllustrative architecture
Your visitorsBrowsers · Mobile · Apps
HTTPS
Cloudflare edgeInspect requests + check cacheCache hit → return from edge
When needed
Your originApp · Database · Original files
CACHE
Serve a valid cached copy at the edge

Images, CSS, JavaScript and eligible public pages; a cache miss or expired content triggers an origin request according to policy.

BYPASS
Process private data at the origin

Cart, checkout, login and user-specific data need bypass rules, with cookies and application conditions reviewed.

01 / TTL

Fresh when it needs to be

Match cache lifetime to files, news, prices and content updates.

02 / CACHE KEY

Keep the right content together

Review query strings and supported conditions to avoid serving the wrong cached variant.

03 / PURGE

Make updates reach your users

Plan entitled cache-purge methods and verify important assets and pages after updates.

Measure your actual before and after
TTFBCache hit ratioOrigin requestsUser experience
AI + HUMAN EXPERTISE

AI helps with the work.
People govern the changes.

Ruk-Com Agent connects to Cloudflare APIs to gather signals, analyze behavior and help adjust supported settings. Our team defines access, scope and approvals around your systems.

Ruk-Com AgentIllustrative management workflow
Traffic · Cache · Security signalsCloudflare APIAuthorized accounts & zones
  1. 01

    Observe

    See what is happening

    Read entitled analytics and events to bring cache, error and traffic signals together.

  2. 02

    Analyze

    Put signals in context

    Compare trends with the baseline and examine performance, protection rules and origin behavior.

  3. 03

    Act

    Act within permission

    Help manage cache and API-supported rules within scope, with approval before high-impact changes.

  4. 04

    Verify

    Verify and inform the next step

    Check metrics and user journeys after changes, record the outcome and roll back when the plan requires it.

Approval before critical changes

DNS · WAF · Cache policy → Impact review → Authorized approval → Apply and verify

Only the access neededScope API tokens by resource and permission
A record of what changedRetain work records and available audit data
A prepared way backReview configuration and rollback before critical work
LAYERED PROTECTION

Intercept threats early.
Keep real users moving.

INTERNET TRAFFIC
01DDoS + WAFFilter threats and attack patterns
02Bots + TurnstileAssess behavior and risk
03API + TLSValidate APIs and connections
Your website & originRequests allowed by policy → App
A layered defense concept, tailored to your Cloudflare plan and architecture.
01

Address attacks and web exploits

Use DDoS protection and WAF Managed Rules for supported services. Tune custom rules around application paths and risks.

02

Manage bots with users in mind

Choose bot controls, rate limiting and Turnstile for forms, login and campaigns. Test their effect on essential crawlers and business services.

03

Protect APIs and origin connections

Assess API Shield entitlements, then plan Full (strict) TLS and Authenticated Origin Pulls where the origin supports them.

04

See risks in the browser

Consider Client-side security (Page Shield) for scripts and outbound connections, alongside AI crawler policies for content owners.

Our team reviews false positives and justified exceptions to keep protection aligned with legitimate use.

BUILD THE RIGHT CAPABILITY SET

A broad platform.
A precise fit for your business.

Start with your business priorities, then choose the products and settings you need. Open each category to explore what our team can assess and manage.

36 capabilities · 6 categories

These are capabilities available for assessment. Every feature is not included in every package. Entitlements, limits and data access depend on Cloudflare plans, subscriptions and add-ons. Confirm quoted features even on Enterprise.

Cache & smarter deliveryDeliver closer to users and reduce repeat origin requests7 features

Global CDN

Deliver cacheable content through Cloudflare’s edge network using your site’s rules.

Plan dependent

Cache Rules & Cache Keys

Define cache eligibility, content lifetime and cache keys while excluding private pages.

Capabilities vary by plan

Tiered Cache

Let edge locations share cached content through a hierarchy to reduce repeated origin fetches.

Topology varies by plan

Smart Shield / Argo Smart Routing

Assess Smart Shield packages for routing informed by network conditions and origin protection.

Additional package or contract

Cache Reserve

Keep eligible objects in a persistent cache tier to reduce origin fetches.

Package and usage based

HTTP/2 & HTTP/3

Use modern protocols for supported connections between visitors and Cloudflare.

Subject to compatibility

Brotli & Zstandard

Compress eligible content according to content type, configuration and browser support.

Configuration dependent
Images & WordPressReduce the weight of the content visitors download3 features

Cloudflare Images

Resize and transform images for different screens, with an assessment of storage and delivery needs.

Entitlement and usage based

Polish

Optimize supported origin images and deliver suitable formats with enabled features.

Supported plans

APO for WordPress

Extend caching for supported WordPress sites while testing plugins, cookies and member pages.

Plan dependent or add-on
DNS, TLS & availabilityPlan how visitors reach your site and connect to the origin6 features

DNS & DNSSEC

Manage DNS records and validate DNS responses with DNSSEC where the domain and registrar support it.

Domain configuration dependent

TLS / Full (strict)

Encrypt origin connections and validate certificates and hostnames using Full (strict) requirements.

Origin certificate required

Authenticated Origin Pulls

Let the origin authenticate Cloudflare connections with supported client certificate configurations.

Entitlement and origin support

Load Balancing

Distribute requests across origins and use health checks for policy-based failover.

Add-on service

Waiting Room

Queue visitors before they enter the site during campaigns, according to capacity and policy.

Plan or contract dependent

Redirect & Transform Rules

Manage redirects and supported request or response transformations, testing critical journeys.

Capabilities vary by plan
WAF, DDoS, bots & APIsMatch protection to your threats and legitimate users9 features

WAF Managed Rules

Use Cloudflare-maintained rulesets and tune exceptions when legitimate workflows are affected.

Rulesets vary by plan

WAF Custom Rules

Build conditions around paths, IPs, countries and request fields supported by your plan.

Limits and fields vary by plan

Rate Limiting

Set request thresholds to control abuse; assess Advanced Rate Limiting separately.

Advanced is an add-on

DDoS Protection

Apply DDoS protection to supported services and traffic routed through the chosen Cloudflare products.

Product-specific scope

Bot Management

Distinguish bot behavior from users and essential services with a suitable management tier.

Enterprise Bot Management add-on

Turnstile

Add checks to supported forms, with user-experience testing and server-side validation.

Application integration required

API Shield

Assess schema validation, mTLS and API discovery against enabled entitlements.

Confirm subscription with account team

Client-side security (Page Shield)

Inspect page scripts and outbound connections to help identify client-side risks.

Capabilities vary by plan

AI Crawler Controls

Set policies for AI crawlers and review their impact on relevant automated content access.

Capabilities vary by plan
Analytics, logs & evidenceMake informed decisions and verify the effect of changes5 features

Traffic & Security Analytics

Review request, cache and security-event trends using data available to your plan.

Data and retention vary by plan

Web Analytics / RUM

Observe real browser experiences, with an assessment of setup and privacy requirements.

Measurement setup required

GraphQL Analytics API

Query entitled datasets for analysis, reporting and Agent workflows.

Entitlement and query limits apply

Logs & Logpush

Send supported datasets to a log destination for investigation and analytics integration.

Dataset and storage costs vary

Audit Logs

Review recorded account changes and agree how supporting evidence will be retained.

Retention and export vary
Extend beyond the CDNAdditional products with a separately assessed scope and cost6 features

Workers & Snippets

Run edge logic such as request changes or response composition within each product’s limits.

Separate development scope

R2 Object Storage

Plan object storage for files and applications that need storage integration.

Usage-based service

Cloudflare Stream

Plan video ingestion, processing and delivery using a dedicated video service.

Separate service and usage

Zero Trust / Access

Control application access using identity and organizational policies with identity-provider integration.

Separate scope and licensing

Cloudflare Tunnel

Connect supported origin services through an outbound tunnel initiated at the origin.

Installation and design required

Spectrum

Assess proxying for TCP/UDP services beyond a standard web CDN deployment.

Protocol and contract restrictions

Product names and terms can change. We confirm current entitlements and costs before proposing the scope.

Cloudflare documentation
BUILT AROUND YOUR BUSINESS

Different websites.
Different priorities.

01 / COMMERCE

Commerce & campaigns

Product pages need speed; carts and checkout need accuracy. Prepare for campaign traffic without disrupting shoppers or payment webhooks.

Plan page-level caching
Test checkout and webhooks
Assess bots, rate limits and queues
02 / PORTALS & API

Business portals, SaaS & APIs

Keep user data separated and preserve sessions and integrations, with the evidence your team needs to investigate issues and review changes.

Set private-data bypass rules
Assess WAF and API Shield
Plan logs and management access
03 / CONTENT & GLOBAL

Media & international audiences

Deliver images and content across regions, control freshness and understand where slow delivery or origin load begins.

Tune TTL, purge and image delivery
Assess Tiered Cache / Smart Shield
Scope video delivery with Stream
MANAGEMENT BEYOND SETUP

From your current setup
to a working plan.

Ruk-Com connects your business goals with Cloudflare configuration, from initial setup to ongoing management. Scope, responsibilities and service terms are defined before work starts.

  1. 01

    Assess & baseline

    Review DNS, origin, traffic, critical paths and your current Cloudflare plan.

    Deliverable: system review and priorities
  2. 02

    Design & agree

    Select entitlements, plan cache and security policies, and define approvers and rollout.

    Deliverable: configuration plan and quote
  3. 03

    Configure & test

    Apply the plan, test web and API journeys, and prepare rollback steps.

    Deliverable: change record and test results
  4. 04

    Review & refine

    Review post-change results, rules and events with the Agent at the agreed cadence.

    Deliverable: review report and next actions
RUK-COM CLOUDFLARE MANAGEMENT

Cloudflare management.
A team for your website.

1,000THB / domain / month

Management per domain for performance and security within the agreed scope. Cloudflare plans and add-ons are charged separately based on your selection.

Talk to our team and get started
01

Cloudflare license & add-ons

Selected subscriptions, additional products, quotas and usage-based charges.

02

Ruk-Com management

Cloudflare configuration and tuning with AI Agent support, reporting and team coordination within the agreed scope.

03

How we work together

Account ownership, Agent permissions, review cadence, approvers, response channels, service hours and rollback plans.

BEFORE YOU START

Get the details clear.
Before connecting.

Useful answers for business, IT and security teams.

Share your requirements
01Can Ruk-Com manage our existing Cloudflare setup?

Yes. We review your current plan, account access, DNS and active rules, then propose changes. Account ownership, approvers and support handoffs are agreed before work starts.

02Do we need to move hosting or change nameservers?

Hosting can stay where it is if the origin supports the required connection. Nameserver changes depend on the Cloudflare setup: full setup generally requires a change, while partial setup has eligibility requirements. We check DNS, email and subdomains before planning the switch.

03How do you handle store pages and private member data?

We separate cacheable public pages and assets from carts, checkout, login and user-specific data. Cache bypass uses supported URL, cookie or request conditions, with real workflow testing before activation.

04Are all Cloudflare features included in the service?

They are not automatically included. Features, quotas, datasets and retention depend on plans, subscriptions and add-ons. Some products require additional purchases even on Enterprise. The quote separates Cloudflare licenses and add-ons from Ruk-Com management fees.

05What can the AI Agent do, and who approves changes?

Ruk-Com Agent connects to Cloudflare APIs to read data, analyze signals and help manage supported settings within granted permissions. High-impact DNS, WAF or cache-policy changes pass through the agreed approver, with verification and a rollback plan. It does not receive unrestricted automatic access.

06Do we need to share the main password or a global API key?

We plan access using account members and API tokens scoped to the required resources and permissions, with revocation and access lifetime agreed. Do not send secrets through public forms or chats. Access handover and revocation are agreed with your organization’s administrator.

07How will we know whether the changes helped?

We capture a baseline and compare suitable periods after the change, reviewing TTFB, cache hit ratio, origin requests and user experience alongside errors and security events. Results depend on traffic, application behavior, the origin and the agreed changes, so we assess your actual system.

08Could the WAF block customers or payment integrations?

False positives are possible. We review critical paths, webhooks and external services, test rules and tune technically justified exceptions, then monitor the rollout. Exceptions are limited to what is necessary to retain protection.

09How do we start, and what determines the cost?

Ruk-Com management costs THB 1,000 per domain per month. Cloudflare plans, add-ons and usage charges are billed separately according to the selected plan. Send your domain, origin setup and priorities via LINE @rukcom or email. Our team will confirm the scope, suitable plan and terms before work starts.

RUK-COM · MANAGED CLOUDFLARE

Take your website further.
With a team beside you.

Start with your domain, current setup and priorities. We’ll help plan performance, protection and a management scope that fits.

Cloudflare and the Cloudflare logo are trademarks of Cloudflare, Inc. The management service on this page is provided by Ruk-Com.