Skip to content

Block Worker subrequests from other zones

Last updated View as MarkdownAgent setup

The cf.worker.upstream_zone field identifies the zone that spawned a Workers subrequest. You can use this field in custom rules to mitigate unwanted Worker traffic.

Block subrequests from a specific zone

  • When incoming requests match:

    If you are using the expression editor:
    (cf.worker.upstream_zone eq "example.com")

  • Then take action: Block

Block all Worker subrequests except from your own zone

  • When incoming requests match:

    If you are using the expression editor:
    (not cf.worker.upstream_zone in {"" "your-zone.com"})

  • Then take action: Block

The empty string matches requests that did not come from a Worker, so this expression only blocks subrequests from other zones. Direct visitor traffic is not affected.

Was this helpful?