To make sure only Cloudflare-owned IP addresses can access your AWS instance:

  1. Go to ec2 -> Security Groups (or click this link) -> Create Security Group
  2. In "inbound" click add rule.
  3. Set HTTPS as the type (or custom TCP if you want to use another port)
  4. For the "source", enter the following string.,,,,,,,,,,,,,,2400:cb00::/32,2606:4700::/32,2803:f800::/32,2405:b500::/32,2405:8100::/32,2a06:98c0::/29,2c0f:f248::/32

Cloudflare may have added new IP ranges since this blog post, so make sure to check at