iCloud Private Relay and Cloudflare geo blocking rules

I have a question, we currently use Cloudflare for our perimeter protection and CDN and other stuff do, one of the main aspects is our site relies on IP address location identification to source traffic to allow or not that traffic to our sites. with this new private relay that apple are shipping how are Cloudflare able to offer the same protection. with us its very much a compliance issue.


Cloudflares firewall and the cf object in Workers already correctly identify such users. From iCloud documentation:

Private Relay preserves the region the user is in, so your server can trust the region assigned to the IP address it sees. By default, connections are also associated with the city closest to the client, allowing your content to remain relevant.


Users can sometimes choose a less precise geographic location, but they cannot change their country.

