Hello,
I use cloudflare Zero Trust for my domains.
And I use LetsEncrypt on some servers. Unfortunately, when Zero Trust is enabled, certificate renewal via LetsEncrypt does not work.
Is there any way for path: *example.com/.well-known/acme-challenge/*
Add it to the exceptions so that it is not covered by Zero Trust?
If this is possible, please provide a procedure on what needs to be done to do this.
Nothing related to the WAF/Firewall rule for your domain.
You need to create another Cloudflare Access application in Zero Trust dashboard, to match the specific path that you would like to skip authentication for Let’s Encrypt cert renewal. Within the new Access application, the Access policy action should be Bypass everyone.