Skip to content
Notis

Instant WAF Protection During Security Attacks

Security incident reported in Linear. Cloudflare WAF list created instantly. Your team can focus on investigation and blocking, not infrastructure setup.

Trigger

Issue Created Trigger

Triggered when a new issue is created.

Action

Create WAF List

Tool to create a new empty waf list for the account. use after confirming the account id. example: create list(account id="<id>", kind="ip", name="blocklist")

Why this helps

During a DDoS or attack, you're losing time switching between tools to create WAF lists and block traffic. Every second counts.

  • WAF protection is ready before you finish reading the incident report
  • Team doesn't context-switch during active incidents
  • Clear audit trail in Linear
  • Faster threat mitigation

Setup

Build it in a few focused steps.

  • 1Connect Linear and Cloudflare to Notis.
  • 2Tell Notis: 'When a new issue is created with the security-incident label, create an empty WAF list in Cloudflare named after the incident.' Use Issue Created as the trigger.
  • 3Create and use a 'security-incident' label consistently in Linear for attacks and threats.
  • 4During a test, create an issue with the label and verify Notis creates the WAF list in Cloudflare.

Questions about this workflow

Should the WAF list be empty or pre-populated?

Notis creates an empty list during setup. Your team can add blocking rules in the Linear comments, and another automation can add them to the WAF list.

Can I name the WAF list based on the incident?

Yes. Tell Notis: 'Name the WAF list Incident- plus the issue title' or use a specific naming scheme.

What if the incident is a false alarm?

Delete the WAF list from Cloudflare and close the issue in Linear. Notis won't re-create it.

When this happens · Trigger

Do this · Action

Supported Triggers and Actions

Notis builds workflows that link Linear to Cloudflare. A trigger fires from one place; an action lands in another.

Linear triggers

Cloudflare actions

Recurring trigger

Notis starts this workflow on a schedule, such as daily, weekly, or during business hours.

TriggerScheduled

Create DNS record

Tool to create a new dns record within a specific zone. use after obtaining the zone id to programmatically add dns entries.

ActionInstant

Webhook trigger

Notis starts this workflow when an external tool or custom backend sends an HTTP request.

TriggerInstant

Create WAF List

Tool to create a new empty waf list for the account. use after confirming the account id. example: create list(account id="<id>", kind="ip", name="blocklist")

ActionInstant

Comment Received Trigger

Triggered when a comment is received.

TriggerInstant

Create Zone

Tool to create a new zone. use after confirming account id when adding a domain to cloudflare.

ActionInstant

Issue Created Trigger

Triggered when a new issue is created.

TriggerInstant

Delete DNS Record

Tool to delete a dns record within a specific zone. use after confirming zone and record ids. example: "delete dns record 372e6795... from zone 023e105f4ecef..."

ActionInstant

Issue Updated Trigger

Triggered when an issue is updated. For example labels are changed, issue status is changed, etc.

TriggerInstant

Delete WAF List

Tool to delete a waf list. use when you need to remove a list after verifying no filters reference it. example: delete list(account id="<account id>", list id="<list id>")

ActionInstant

Private Team Comment Created

Fires when a new comment is posted on an issue in a private Linear team (polled with the connected user's token).

TriggerPolling

Delete Zone

Tool to delete a zone. use after confirming the zone identifier to permanently remove a dns zone from your cloudflare account. example: delete zone(zone identifier="023e105f4ecef8ad9ca31a8372d0c353")

ActionInstant

Private Team Issue Created

Fires when a new issue appears in a private Linear team (polled with the connected user's token).

TriggerPolling

List WAF Lists

Tool to fetch all waf lists (no items) for an account. use after confirming account id.

ActionInstant

Private Team Issue Properties Updated

Fires when properties on an issue change in a private Linear team (polled with the connected user's token).

TriggerPolling

List Account Members

Tool to list members of a given cloudflare account. use after confirming the account id.

ActionInstant

Connect any two apps with Notis in the middle.

Linear and Cloudflare, or any other combination from 1,000+ integrations.

When this happens · Trigger

Do this · Action

Save your first hour today.

7-day trial of any paid plan, with 20$ of usage included.
No card. Works with personal or business Cloudflare.