Self-Host & Claude Agent Academy

Curriculum>Foundation>Module 1
Module 0125 Mins Read & LabLevel: Beginner

Cloudflare Domain Acquisition & DNS Routing

Acquire wholesale domains, configure authoritative DNS records, and secure edge traffic with SSL/TLS.

Module Executive Summary

A resilient self-hosted architecture starts with a domain name and bulletproof DNS management. In this module, you will learn how to acquire domains at wholesale cost via Cloudflare Registrar, configure A and CNAME routing records to your virtual server, understand the critical difference between DNS-Only and Proxied modes, and establish end-to-end SSL/TLS encryption.

What You Will Master

  • •Acquire a custom domain without markup using Cloudflare Registrar
  • •Point root and subdomain DNS records (A and CNAME) to an external server IP
  • •Distinguish between Cloudflare Proxied (Orange Cloud) and DNS-Only (Grey Cloud) modes
  • •Configure Full (Strict) SSL/TLS encryption and origin certificates for secure routing

Prerequisites & Setup

  • •A valid email address for creating a Cloudflare account
  • •A credit card or PayPal for domain registration (approx. $8-$12/year wholesale)

Jargon Buster • Module 1 Glossary

Beginner Friendly

Decoded in plain English with real-world analogies before you touch any terminal commands.

Domain NameTerm

A human-friendly web address (like google.com or yourdomain.com) that points to a server's numerical IP address.

Real-World Analogy: Like saving a friend's name in your phone contacts instead of memorizing their 10-digit phone number.
Why We Use It: Allows visitors and webhooks to reach your services without typing raw numbers.
DNS (Domain Name System)Term

The global lookup directory that converts readable domain names into numerical IP addresses.

Real-World Analogy: The internet's master GPS and telephone book.
Why We Use It: Translates n8n.yourdomain.com into your Oracle VM's public IPv4 address.
RegistrarTerm

An accredited organization authorized to sell and assign domain names to customers.

Real-World Analogy: The official government land registry office that sells and records deeds to real estate plots.
Why We Use It: Cloudflare sells domains at wholesale cost with 0 markup and free WHOIS privacy.
A RecordTerm

An Address Record that maps a domain name directly to a physical IPv4 address (e.g. 150.136.92.44).

Real-World Analogy: A street sign pointing directly to a specific physical house address.
Why We Use It: Connects your root domain (@) directly to your virtual machine.
CNAME RecordTerm

A Canonical Name record that creates an alias pointing one domain name to another domain name.

Real-World Analogy: Forwarding mail from a temporary nickname to your primary legal name.
Why We Use It: Routes subdomains like n8n.yourdomain.com or api.yourdomain.com to your root server.
Proxied (Orange Cloud)Term

Cloudflare's security mode where traffic routes through Cloudflare edge servers before reaching your VM.

Real-World Analogy: A security guard at the building entrance who checks IDs and shields the real building residents.
Why We Use It: Hides your server IP, stops DDoS attacks, and provides free automatic HTTPS.
DNS-Only (Grey Cloud)Term

Direct routing mode where traffic goes straight to your VM without passing through Cloudflare's proxy.

Real-World Analogy: An open direct highway to your front door with no toll booth or guard station.
Why We Use It: Mandatory for direct SSH (Port 22) or raw PostgreSQL connections (Port 5432).
SSL/TLS EncryptionTerm

A security protocol that scrambles data traveling between the visitor's browser and your server.

Real-World Analogy: Sealing a letter inside an armored, tamper-evident envelope before mailing it.
Why We Use It: Prevents credential theft and gives your website the trusted secure padlock.
Quick Hover Definitions:
Domain NameDNS (Domain Name System)RegistrarA RecordCNAME RecordProxied (Orange Cloud)DNS-Only (Grey Cloud)SSL/TLS Encryption

Architectural Topology & Data Flow

Interactive Architecture
Client / Visitor
https://n8n.yourdomain.com
HTTPS request
Orange Cloud
Cloudflare Edge
DDoS Mitigation & WAF
Full (Strict) TLS Termination
Authoritative DNS
A & CNAME Records
Fast 1.1.1.1 Anycast
Origin Oracle VM
Public IPv4: 150.x.x.x
Encrypted Origin Traffic
Security Guarantee: Your real server IP is masked behind Cloudflare Anycast edge network.Status: Proxied (Active)

Interactive Lab & Generator

Customize values below to generate tailored configurations for your stack.

Cloudflare DNS Table for agentstack.io
TYPENAMETARGET / VALUEPROXY STATUS
A@150.136.92.44Proxied (Orange)
CNAMEn8nagentstack.ioProxied (Orange)
CNAMEapiagentstack.ioProxied (Orange)
CNAMEappagentstack.ioProxied (Orange)

1. Why Cloudflare Registrar? The Wholesale Advantage

Most commercial domain registrars (GoDaddy, Namecheap, Network Solutions) operate on an aggressive upsell model: low promotional first-year pricing followed by 200%-400% renewal markups, plus recurring charges for basic privacy protection.

Cloudflare operates as an ICANN-accredited registrar that provides domains at cost—charging only what the registry registry (e.g., Verisign for .com) and ICANN mandate, with zero retail markup and complimentary WHOIS privacy protection forever.

Domain Pricing Comparison (Standard .com) - Traditional Registrars: $1.99 - $9.99 (Year 1) → $21.99 - $26.99/year renewals + upsells. - Cloudflare Registrar: $9.77/year flat (Registry wholesale price + ICANN fee).

You can register a domain directly through Cloudflare (dash.cloudflare.com) under Domain Registration → Register Domains, or transfer an existing domain from another registrar.

Existing Domain Recommendation
If you already own a domain at another registrar, you do not need to transfer the domain registration immediately. You can simply change your domain’s nameservers at your current registrar to Cloudflare’s assigned nameservers (e.g., alex.ns.cloudflare.com) to manage DNS for free.

2. Configuring DNS Records for Self-Hosted Services

Once your domain is active on Cloudflare, you must define DNS records that map human-readable domain names to your server’s public IP address. For our complete stack (VM, n8n, frontend dashboard, and webhooks), we will establish a clean subdomain convention.

Essential Records for Our Stack 1. Root Domain (@): Directs top-level traffic to your server public IP (Type: A). 2. n8n Automation Subdomain: Dedicated host for your workflow engine (Type: CNAME or A, e.g., n8n.yourdomain.com). 3. API / Agent Gateway: Subdomain for incoming webhooks or Claude-triggered endpoints (e.g., api.yourdomain.com). 4. Dashboard: Subdomain for your web frontend deployed in Module 8 (e.g., app.yourdomain.com).

cloudflare_dns_table.txtbash
Recommended DNS Record Configuration Table
Type   | Name    | IPv4 / Target              | Proxy Status | TTL
-------------------------------------------------------------------
A      | @       | <YOUR_ORACLE_VM_PUBLIC_IP> | Proxied      | Auto
CNAME  | n8n     | yourdomain.com             | Proxied      | Auto
CNAME  | api     | yourdomain.com             | Proxied      | Auto
CNAME  | app     | yourdomain.com             | Proxied      | Auto

3. Proxied (Orange Cloud) vs. DNS-Only (Grey Cloud)

Cloudflare provides a toggle switch for each DNS record that switches between two routing modes. Understanding this distinction is critical for self-hosted infrastructure:

Orange Cloud: Proxied - Traffic flows: Client &rarr; Cloudflare Edge Network (DDoS mitigation, CDN, WAF, SSL termination) &rarr; Your VM. - Your origin server's real IP address is masked from the public internet. - Crucial for n8n: Cloudflare automatically provides WebSocket support (which n8n requires for live execution canvases) and HTTP/2 or HTTP/3 acceleration. - Only standard HTTP/HTTPS ports (80, 443, 8080, 8443, etc.) can pass through the proxy.

Grey Cloud: DNS-Only - Traffic flows directly: Client &rarr; Your VM. - Required for non-HTTP protocols, such as direct SSH (Port 22) or raw database connections (PostgreSQL Port 5432). - Your VM's public IP is visible in public DNS queries.

Never Proxy Raw SSH or Database Ports
Cloudflare standard proxy only proxies HTTP/HTTPS web traffic. If you attempt to connect via SSH or psql to a proxied hostname (e.g., ssh [email protected]), connection will fail or be refused. Use the direct VM IP or a DNS-only hostname for SSH connections.

4. Setting SSL/TLS Encryption to Full (Strict)

Navigate to SSL/TLS &rarr; Overview in the Cloudflare dashboard. Cloudflare offers four encryption tiers:

  1. 1Off: Insecure plain text HTTP.
  2. 2Flexible: Encrypts traffic between browser and Cloudflare, but sends plain HTTP between Cloudflare and your origin server. Avoid this: it is vulnerable to man-in-the-middle attacks and causes redirect loops with modern reverse proxies.
  3. 3Full: Encrypts end-to-end, but accepts self-signed certificates on the origin server.
  4. 4Full (Strict): The recommended standard. Encrypts end-to-end and requires a valid trusted SSL certificate on your server (which our Caddy/Traefik reverse proxy in Module 3 will automatically provision via Let's Encrypt).
verify_dns.shbash
Terminal command to verify DNS propagation
# Query your domain via Cloudflare DNS resolver (1.1.1.1)
dig +short A yourdomain.com @1.1.1.1

# Query your n8n subdomain
dig +short CNAME n8n.yourdomain.com @1.1.1.1

# Test HTTPS handshake and certificate validity
curl -Iv https://yourdomain.com

Module 1 Practical Checkpoints

Check off each milestone as you execute the steps on your own infrastructure.

0 of 5 completed