Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 7: Kiểm soát AI, MCP và crawler Part 7: AI controls, MCP, and crawlers Part 7: AI controls, MCP, and crawlers · Bài 1/4 Lesson 1/4 មេរៀន 1/4

Govern AI: thấy, cho phép an toàn, chặn data leak Govern AI: see it, allow safely, stop data leaks Govern AI: see it, allow safely, stop data leaks

Mô-đun 7 — Kiểm soát AI (Sử dụng AI an toàn)

Mục tiêu: Xem nhân viên đang dùng công cụ AI nào, ngăn dữ liệu nhạy cảm bị dán vào chúng, và bảo vệ mọi ứng dụng AI mà bạn tự xây.

👤 Ai làm việc này Nhóm bảo mật
⏱️ Thời gian ~45 phút
🎯 Kết thúc bạn sẽ có Tầm nhìn về việc dùng AI, một chính sách cho phép dùng AI an toàn, và bảo vệ dữ liệu ở cấp prompt
✋ Trước khi bắt đầu Đã xong Mô-đun 3 & 5 (thiết bị đã kết nối, TLS decryption bật). Các phần dựa trên DLP cần Enterprise.

🧭 Quy tắc vàng cho AI: quản trị, đừng cấm. Nếu bạn chặn cứng ChatGPT, người ta chỉ dùng trên điện thoại — và bạn mất hết tầm nhìn. Mục tiêu là cho phép AI một cách an toàn: nhìn thấy, kiểm soát hành động rủi ro, và ngăn dữ liệu nhạy cảm đi vào.


AI Security Suite của Cloudflare — bức tranh tổng thể

Mô-đun này (và các Mô-đun 5d, 6, 7b, 7c) cùng tạo nên AI Security Suite của Cloudflare: bảo mật và quản trị AI ở mọi nơi đổi mới diễn ra, xuyên suốt toàn bộ vòng đời AI — để bạn mở rộng việc áp dụng AI mà không hy sinh bảo mật. Nên xem các mảnh ghép khớp nhau thế nào trước khi đi sâu.

Bốn kết quả bộ giải pháp mang lại:

Kết quả Ý nghĩa Ở đâu trong hướng dẫn này
Giảm rủi ro shadow-AI Hiểu AI được dùng thế nào; quản lý công cụ rủi ro/chưa được phê duyệt bằng SaaS analytics + chính sách lưu lượng 5d — Shadow IT
Ngăn mất dữ liệu Phát hiện thông tin nhạy cảm trong lưu lượng hướng tới AI — xuyên suốt yêu cầu mô hình, phiên trình duyệt và đích SaaS 6 — DLP · mô-đun này
Quản trị quyền truy cập công cụ của agent Tập trung quyền truy cập máy chủ MCP nội bộ/bên thứ ba; chọn lọc công cụ & prompt sau chính sách zero-trust 7b — Secure AI & MCP
Giữ chi phí trong tầm kiểm soát Giới hạn chi tiêu theo thời gian thực để việc dùng AI luôn dự đoán được trên các mô hình & nhà cung cấp 7c — AI Gateway

Bốn trường hợp sử dụng xuyên suốt vòng đời AI:

Trường hợp sử dụng Công cụ chính Mô-đun
Bảo mật việc dùng AI của nhân viên SWG, DLP, RBI, CASB 5 · 6 · 5c · mô-đun này
Quản trị AI agent MCP server portals, ZTNA 7b
Xây dựng AI an toàn AI Gateway, Workers (host remote MCP servers) 7c
Bảo vệ ứng dụng dùng AI AI Security for Apps (WAF) Phần D2 bên dưới

📎 Một khả năng hướng dẫn này không thiết lập sâu: CASB / AI-SPM. CASB của Cloudflare bổ sung AI Security Posture Management — nó quét các công cụ SaaS và AI đã được phê duyệt để tìm cấu hình sai (dữ liệu chia sẻ quá mức, tích hợp rủi ro, thiết lập yếu) và giúp bạn khắc phục. Nó bổ sung cho các kiểm soát trong lưu lượng của bộ giải pháp này bằng các kiểm tra tư thế khi lưu trữ trên các công cụ AI bạn đã phê duyệt. Nếu bạn đã cấp phép CASB, hãy chạy quét AI-SPM song song với các mô-đun này. (Tham khảo: cloudflare.com/solutions/ai-security.)


Chúng ta sẽ làm: (A) phát hiện những gì đang được dùng → (B) cho phép-nhưng-hạn-chế → (C) bảo vệ prompt bằng DLP → (D) bảo vệ AI bạn tự xây → (E) quản trị AI agent.


Phần A — Phát hiện công cụ AI nào đang được dùng

  1. 👉 Zero Trust → Gateway → Analytics → Shadow IT Discovery (hoặc My Team → Shadow IT Discovery).
  2. 👉 Lọc loại ứng dụng thành Generative AI.
  3. 📺 Bạn sẽ thấy: Danh sách ứng dụng AI mà người dùng đã truy cập (ChatGPT, Gemini, Claude, Perplexity, Copilot…), kèm số người dùng và lượng lưu lượng.
  4. 👉 Với mỗi ứng dụng, đặt trạng thái: đánh dấu công cụ được phê duyệt là Approved và các công cụ khác là Unapproved.

✅ Điểm kiểm tra: Bạn giờ có bức tranh dựa trên bằng chứng về việc dùng AI — cơ sở cho chính sách sử dụng AI chấp nhận được của bạn.

🔎 Toàn bộ quy trình phát hiện→xem xét→áp dụng (cho mọi SaaS, không chỉ AI) cùng hành trình áp dụng AI nằm trong Mô-đun 5d — Shadow IT & AI Security Adoption.


Phần B — Cho phép AI, nhưng hạn chế hành động rủi ro

Thay vì chặn một ứng dụng AI, hãy cho phép nó đồng thời chặn các phần rủi ro (như tải tệp lên).

  1. 👉 Zero Trust → Gateway → Firewall Policies → HTTP → Add a policy.
  2. ⌨️ Tên: AI - allow with guardrails.
  3. 👉 Quy tắc: Selector Application → in → chọn các ứng dụng AI của bạn (ví dụ ChatGPT, Google Gemini, Claude, Perplexity).
  4. 👉 Mở rộng Application granular controls và chặn các hành động cụ thể, ví dụ:
    • Chặn Upload file
    • (tùy chọn) Chặn các hành động Share / create
  5. 👉 Action: Allow (với các chặn chi tiết đã áp dụng).
  6. 👉 Nhấp Create policy.

📺 Việc này làm gì: Người ta có thể trò chuyện với AI, nhưng không thể tải tài liệu của bạn vào đó.

✅ Điểm kiểm tra: Trên thiết bị thí điểm, bạn dùng ChatGPT bình thường, nhưng khi cố tải tệp lên thì bị chặn.


Phần C — Bảo vệ prompt bằng DLP (Enterprise)

Phần này quét những gì người dùng gõ vào công cụ AI và chặn các prompt chứa dữ liệu nhạy cảm.

Bước C1 — Bật phát hiện prompt AI

  1. 👉 Zero Trust → DLP → Detection entries (hoặc mở một DLP profile) → tìm AI prompt topics.
  2. 👉 Bật các chủ đề bạn quan tâm:
    • Content topics: PII, Source Code, Credentials & Secrets, Financial Information, Customer Data
    • Intent topics: nỗ lực jailbreak, yêu cầu mã độc hại, nỗ lực trích xuất dữ liệu cá nhân
  3. 💡 Hoặc chỉ chọn một profile có sẵn như "AI Prompt: PII" hoặc "AI Prompt: AI Security."

Bước C2 — Áp dụng (theo dõi trước!)

  1. 👉 Gateway → HTTP → Add a policy đặt tên AI prompts - MONITOR.
  2. 👉 Quy tắc: Selector DLP Profile → in → profile AI Prompt của bạn. Action Allow (chỉ ghi log).
  3. 👉 Chạy vài ngày; xem lại Gateway → Logs.
  4. 👉 Sau đó thêm chính sách ưu tiên cao hơn AI prompts - BLOCK với Action: Block cho các trường hợp độ tin cậy cao (ví dụ prompt chứa Credentials & Secrets).

✅ Điểm kiểm tra: Dán một secret/API key giả vào cuộc trò chuyện AI được phát hiện (và bị chặn bởi chính sách block), thấy được trong log.


Phần D — Bảo vệ ứng dụng AI bạn tự xây

Hai công cụ khác nhau, tùy cách AI được dùng:

D1 — Với AI theo chương trình / API (không cần client trên thiết bị): DLP cho AI Gateway

Nếu lập trình viên của bạn gọi mô hình AI qua Cloudflare AI Gateway:

  1. 👉 Cloudflare dashboard → AI → AI Gateway → chọn gateway của bạn.
  2. 👉 Mở Features → DLP → Set up.
  3. 👉 Gắn DLP profiles để quét requests and responses tới/từ nhà cung cấp AI.

💡 Cách này hoạt động không cần TLS decryption hay client trên thiết bị — nó kiểm tra lưu lượng ở lớp API. Rất phù hợp để quản trị các cuộc gọi app-to-AI.

🚪 AI Gateway làm nhiều hơn DLP — xác thực, guardrails, giới hạn chi phí/tốc độ, caching và ghi log cho mọi cuộc gọi AI mà ứng dụng của bạn thực hiện. Hướng dẫn đầy đủ: Mô-đun 7c — AI Gateway: Protect & Implement.

D2 — Với ứng dụng AI bạn mở cho người dùng: AI Security for Apps (WAF)

Nếu bạn host một ứng dụng/chatbot AI mà người khác truy cập qua web:

  1. 👉 Vào zone (website) host ứng dụng AI của bạn → Security → Settings (hoặc WAF → Detections).
  2. 👉 Bật các phát hiện AI Security for Apps — prompt injection và unsafe topics.
  3. 👉 Tạo WAF custom rule hành động (Block/Log) khi các phát hiện đó kích hoạt.

💡 Chúng khác nhau thế nào: AI Security for Apps chặn tấn công vào mô hình của bạn (prompt injection); DLP chặn dữ liệu nhạy cảm di chuyển. Dùng cả hai trên lưu lượng AI.

🕷️ Mối đe dọa vào chiều ngược lại: AI crawlers. Ngoài tấn công, bot AI còn crawl nội dung công khai của bạn để huấn luyện mô hình — giờ chiếm phần lớn lưu lượng internet. Để xem, cho phép/chặn, hoặc thậm chí tính phí chúng, xem Mô-đun 7d — The Agentic Internet: AI Crawler & Bot Control.


Phần E — Quản trị AI agent (MCP server portals) — tùy chọn/nâng cao

Nếu bạn mở công cụ cho AI agent qua Model Context Protocol (MCP):

  1. 👉 Zero Trust → Access controls → AI controls → MCP server portals.
  2. 👉 Thêm một portal, công bố các công cụ/prompt bạn muốn mở, và đặt Access policy phía trước để chỉ agent/người dùng được ủy quyền mới dùng được.

🔐 Đây là một chủ đề lớn riêng. Để có hướng dẫn đầy đủ — bảo mật từng máy chủ MCP, xây MCP portal, Managed OAuth cho AI client, service token cho bot, và ghi log cấp request + DLP — xem trang đi kèm: Mô-đun 7b — Secure AI & MCP with Access (MCP Server Portals).


✅ Hoàn thành Mô-đun 7!

Bây giờ bạn có:

  • ✅ Tầm nhìn về công cụ AI nào đang được dùng (Shadow IT)
  • ✅ Chính sách "cho phép nhưng hạn chế" cho ứng dụng AI
  • ✅ (Enterprise) DLP cấp prompt phát hiện/chặn prompt nhạy cảm
  • ✅ Bảo vệ cho AI bạn tự xây (lớp API và/hoặc lớp web)
  • ✅ (Tùy chọn) Quản trị AI agent qua MCP portals

Khắc phục nhanh

Vấn đề Cách khắc phục
Ứng dụng AI không xuất hiện trong Shadow IT Cần lưu lượng HTTP đi qua Gateway — xác nhận Mô-đun 5 (Gateway with WARP + decryption)
Prompt DLP không bắt được gì TLS decryption tắt, hoặc AI prompt topics chưa bật (Phần C1); cũng cần Enterprise
Chặn chi tiết "block upload" không có cho một ứng dụng Không phải mọi ứng dụng đều hỗ trợ mọi granular control — thay vào đó hãy chặn domain tải lên của ứng dụng, hoặc isolate nó
Người dùng phàn nàn AI bị chặn hoàn toàn Bạn đã tạo Block thay vì Allow+granular — chuyển sang mẫu ở Phần B

👉 Tiếp theo: Mô-đun 8 — Cloudflare WAN

Kết nối cả văn phòng và trung tâm dữ liệu với Cloudflare. (Tùy chọn; cần gói bổ sung mạng Enterprise.)

Module 7 — AI Controls (Safe AI Usage)

Goal: See which AI tools your people use, stop sensitive data from being pasted into them, and protect any AI apps you build yourself.

👤 Who does this Security team
⏱️ Time ~45 minutes
🎯 You'll finish with Visibility into AI usage, a policy that lets people use AI safely, and prompt-level data protection
✋ Before you begin Modules 3 & 5 done (devices connected, TLS decryption on). DLP-based parts need Enterprise.

🧭 The golden rule for AI: govern, don't ban. If you hard-block ChatGPT, people just use it on their phones — and you lose all visibility. The goal is to allow AI safely: see it, control risky actions, and stop sensitive data going in.


Cloudflare's AI Security Suite — the big picture

This module (and Modules 5d, 6, 7b, 7c) together make up Cloudflare's AI Security Suite: secure and govern AI everywhere innovation happens, across the whole AI lifecycle — so you can scale AI adoption without sacrificing security. It's worth seeing how the pieces fit before diving in.

Four outcomes the suite delivers:

Outcome What it means Where in this guide
Reduce shadow-AI risk Understand how AI is used; manage risky/unsanctioned tools with SaaS analytics + traffic policy 5d — Shadow IT
Prevent data loss Detect sensitive info in AI-bound traffic — across model requests, browser sessions, and SaaS destinations 6 — DLP · this module
Govern agent tool access Centralize access to internal/third-party MCP servers; curate tools & prompts behind zero-trust policy 7b — Secure AI & MCP
Keep costs under control Real-time spend limits so AI usage stays predictable across models & providers 7c — AI Gateway

Four use cases across the AI lifecycle:

Use case Primary tools Module
Secure workforce AI use SWG, DLP, RBI, CASB 5 · 6 · 5c · this module
Govern AI agents MCP server portals, ZTNA 7b
Build AI securely AI Gateway, Workers (host remote MCP servers) 7c
Protect AI-powered apps AI Security for Apps (WAF) Part D2 below

📎 One capability this onboarding doesn't set up in depth: CASB / AI-SPM. Cloudflare's CASB adds AI Security Posture Management — it scans your sanctioned SaaS and AI tools for misconfigurations (over-shared data, risky integrations, weak settings) and helps you fix them. It complements the in-traffic controls in this suite with at-rest posture checks on the AI tools you've approved. If you've licensed CASB, run its AI-SPM scans alongside these modules. (Reference: cloudflare.com/solutions/ai-security.)


We'll do: (A) discover what's used → (B) allow-but-restrict → (C) protect prompts with DLP → (D) protect AI you build → (E) govern AI agents.


Part A — Discover which AI tools are in use

  1. 👉 Zero Trust → Gateway → Analytics → Shadow IT Discovery (or My Team → Shadow IT Discovery).
  2. 👉 Filter the application type to Generative AI.
  3. 📺 What you'll see: A list of AI apps your users have accessed (ChatGPT, Gemini, Claude, Perplexity, Copilot…), with how many users and how much traffic.
  4. 👉 For each app, set a status: mark sanctioned tools Approved and others Unapproved.

✅ Checkpoint: You now have an evidence-based picture of AI usage — the basis for your AI acceptable-use policy.

🔎 The full discover→review→enforce workflow (for all SaaS, not just AI) plus the AI-adoption journey is in Module 5d — Shadow IT & AI Security Adoption.


Part B — Allow AI, but restrict risky actions

Instead of blocking an AI app, allow it while blocking the risky parts (like file uploads).

  1. 👉 Zero Trust → Gateway → Firewall Policies → HTTP → Add a policy.
  2. ⌨️ Name: AI - allow with guardrails.
  3. 👉 Rule: Selector Application → in → select your AI apps (e.g. ChatGPT, Google Gemini, Claude, Perplexity).
  4. 👉 Expand Application granular controls and block specific actions, e.g.:
    • Block Upload file
    • (optionally) Block Share / create actions
  5. 👉 Action: Allow (with the granular blocks applied).
  6. 👉 Click Create policy.

📺 What this does: People can chat with the AI, but can't upload your documents into it.

✅ Checkpoint: On a pilot device, you can use ChatGPT normally, but attempting to upload a file is blocked.


Part C — Protect prompts with DLP (Enterprise)

This scans what users type into AI tools and blocks prompts containing sensitive data.

Step C1 — Turn on AI prompt detection

  1. 👉 Zero Trust → DLP → Detection entries (or open a DLP profile) → find AI prompt topics.
  2. 👉 Enable the topics you care about:
    • Content topics: PII, Source Code, Credentials & Secrets, Financial Information, Customer Data
    • Intent topics: jailbreak attempts, requests for malicious code, attempts to extract personal data
  3. 💡 Or just select a ready-made profile like "AI Prompt: PII" or "AI Prompt: AI Security."

Step C2 — Enforce it (monitor first!)

  1. 👉 Gateway → HTTP → Add a policy named AI prompts - MONITOR.
  2. 👉 Rule: Selector DLP Profile → in → your AI Prompt profile. Action Allow (logs only).
  3. 👉 Run it for a few days; review Gateway → Logs.
  4. 👉 Then add a higher-priority policy AI prompts - BLOCK with Action: Block for the high-confidence cases (e.g. prompts containing Credentials & Secrets).

✅ Checkpoint: Pasting a fake secret/API key into an AI chat is detected (and blocked by the block policy), visible in logs.


Part D — Protect AI apps you build

Two different tools, depending on how AI is used:

D1 — For programmatic / API AI (no device client needed): DLP for AI Gateway

If your developers call AI models through Cloudflare AI Gateway:

  1. 👉 Cloudflare dashboard → AI → AI Gateway → select your gateway.
  2. 👉 Open Features → DLP → Set up.
  3. 👉 Attach DLP profiles to scan the requests and responses to/from AI providers.

💡 This works without TLS decryption or the device client — it inspects traffic at the API layer. Great for governing app-to-AI calls.

🚪 AI Gateway does much more than DLP — authentication, guardrails, cost/rate limits, caching, and logging for every AI call your apps make. Full walkthrough: Module 7c — AI Gateway: Protect & Implement.

D2 — For AI apps you expose to users: AI Security for Apps (WAF)

If you host an AI app/chatbot that others reach over the web:

  1. 👉 Go to the zone (website) hosting your AI app → Security → Settings (or WAF → Detections).
  2. 👉 Enable AI Security for Apps detections — prompt injection and unsafe topics.
  3. 👉 Create a WAF custom rule that acts (Block/Log) when those detections fire.

💡 How they differ: AI Security for Apps stops attacks on your model (prompt injection); DLP stops sensitive data moving. Use both on AI traffic.

🕷️ The other inbound threat: AI crawlers. Beyond attacks, AI bots crawl your public content to train models — now the majority of internet traffic. To see, allow/block, or even charge them, see Module 7d — The Agentic Internet: AI Crawler & Bot Control.


Part E — Govern AI agents (MCP server portals) — optional/advanced

If you expose tools to AI agents via the Model Context Protocol (MCP):

  1. 👉 Zero Trust → Access controls → AI controls → MCP server portals.
  2. 👉 Add a portal, publish the tools/prompts you want to expose, and put an Access policy in front so only authorized agents/users can use them.

🔐 This is a big topic on its own. For the full walkthrough — securing individual MCP servers, building an MCP portal, Managed OAuth for AI clients, service tokens for bots, and request-level logging + DLP — see the companion page: Module 7b — Secure AI & MCP with Access (MCP Server Portals).


✅ Module 7 complete!

You now have:

  • ✅ Visibility into which AI tools are used (Shadow IT)
  • ✅ An "allow but restrict" policy for AI apps
  • ✅ (Enterprise) Prompt-level DLP detecting/blocking sensitive prompts
  • ✅ Protection for AI you build (API layer and/or web layer)
  • ✅ (Optional) Governance for AI agents via MCP portals

Quick troubleshooting

Problem Fix
AI apps don't appear in Shadow IT Needs HTTP traffic through Gateway — confirm Module 5 (Gateway with WARP + decryption)
Prompt DLP not catching anything TLS decryption off, or AI prompt topics not enabled (Part C1); also needs Enterprise
Granular "block upload" not available for an app Not all apps support every granular control — block the app's upload domain instead, or isolate it
Users complain AI is fully blocked You created a Block instead of Allow+granular — switch to the Part B pattern

👉 Next: Module 8 — Cloudflare WAN

Connect whole offices and data centers to Cloudflare. (Optional; requires Enterprise network add-on.)

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Kiến trúc tham chiếu Reference architecture ស្ថាបត្យកម្មយោង Chung / đa lĩnh vực Cross-cutting ឆ្លងកាត់ / ពហុវិស័យ

AI Security for Apps Reference Architecture AI Security for Apps Reference Architecture AI Security for Apps Reference Architecture

/reference-architecture/architectures/ai-security-for-apps

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access một ứng dụng web thông qua tên máy chủ riêng của nó mà không có Cloudflare One Client Access a web application via its private hostname without the Cloudflare One Client Access កម្មវិធីបណ្តាញតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់វាដោយគ្មាន Cloudflare One Client

Với Cloudflare cách ly trình duyệt và các chính sách giải quyết, người dùng có thể kết nối với các ứng dụng dựa trên web riêng tư thông qua tên máy chủ riêng của họ.

With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

ជាមួយនឹង Cloudflare គោលការណ៍ញែកកម្មវិធីរុករក និងដំណោះស្រាយ អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធីដែលមានមូលដ្ឋានលើបណ្តាញឯកជនតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់ពួកគេ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access và bảo mật cơ sở dữ liệu MySQL bằng cách sử dụng Cloudflare Tunnel và chính sách mạng Access and secure a MySQL database using Cloudflare Tunnel and network policies Access និងធានានូវមូលដ្ឋានទិន្នន័យ MySQL ដោយប្រើ Cloudflare Tunnel និងគោលការណ៍បណ្តាញ

Sử dụng mạng riêng của Cloudflare Tunnel, người dùng có thể kết nối với các ứng dụng dựa trên TCP/UDP, chẳng hạn như cơ sở dữ liệu. Bạn có thể thiết lập chính sách mạng thực hiện các điều khiển zero trust để xác định ai và những gì access có thể sử dụng các ứng dụng đó bằng cách sử dụng Cloudflare One Client.

Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.

ដោយប្រើបណ្តាញឯកជនរបស់ Cloudflare Tunnel អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធី TCP/UDP ដែលមានមូលដ្ឋានលើកម្មវិធីរុករកតាមអំពើចិត្ត ដូចជាមូលដ្ឋានទិន្នន័យជាដើម។ អ្នកអាចរៀបចំគោលការណ៍បណ្តាញដែលអនុវត្តការគ្រប់គ្រង zero trust ដើម្បីកំណត់ថាតើនរណា និងអ្វីដែលអាច access កម្មវិធីទាំងនោះដោយប្រើ Cloudflare One Client ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Tạo API thành access D1 bằng cách sử dụng Proxy Worker Build an API to access D1 using a proxy Worker បង្កើត API ទៅ access D1 ដោយប្រើប្រូកស៊ីកម្មករ

Hướng dẫn này cho thấy cách tạo một API cho phép bạn chạy truy vấn an toàn chống lại một cơ sở dữ liệu D1. API có thể được sử dụng để tùy chỉnh các điều khiển access và/hoặc giới hạn các bảng có thể được truy vấn.

This tutorial shows how to create an API that allows you to securely run queries against a D1 database. The API can be used to customize access controls and/or limit what tables can be queried.

ការបង្រៀននេះបង្ហាញពីរបៀបបង្កើត API ដែលអនុញ្ញាតឱ្យអ្នកដំណើរការសំណួរដោយសុវត្ថិភាពប្រឆាំងនឹងមូលដ្ឋានទិន្នន័យ D1 ។ API អាចត្រូវបានប្រើដើម្បីប្ដូរតាមបំណង access គ្រប់គ្រង និង/ឬកំណត់តារាងដែលអាចសួរបាន។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths