Cloudflare had 11 live custom firewall rules. The rule ID index still said six.

That was worse than an out-of-date document. The version history in CF-WAF-RULES.md ended at v14, while the live ruleset had reached v27. I went in thinking I had a 13-version changelog backlog. I was actually fixing the missing comparison that had let the changelog drift in silence, on a document I had been treating as a reasonably current record of our own security posture. I do not know how many of those 13 versions I would have described confidently and wrongly if someone had asked me what our firewall rules did last week.

The original problem was already difficult. The rule set was versioned, but the useful account-level audit log could not be read with any of the available tokens. I could ask Cloudflare for every ruleset version and timestamp, and I could ask for a full snapshot of a numbered version. I could not depend on the dashboard to narrate the changes for me.

Then Claude supplied the first sharp warning about the investigation itself. Its initial collection job tried to write snapshots beneath /tmp/cf_versions and failed on the first v14 file. The directory it expected was not present in the environment it was using. It was a tiny filesystem mistake, but it interrupted the easy temptation to treat a version list as evidence. A list tells you when a ruleset changed. It does not tell you which rule, action, or expression changed.

I moved the collection into the project scratch area and fetched the full snapshots from v14 through v27. The data gave me 14 consecutive states to compare, rather than 13 lines to transcribe. I diffed each state against its predecessor and used the ticket comments only as a cross-check of the resulting entries.

The earliest diffs made the distinction tangible. Version 15 changed an ASN-focused rule from block to managed_challenge. Version 16 removed the truncated-Chrome branch from a user-agent expression, leaving the empty-user-agent match. Those were not generic notes about tightening a firewall. They were concrete rule changes with a prior state, a new state, and a timestamp.

Version numbers also exposed an indexing problem that ordinary prose had hidden. The log omitted v15 through v27, but the rule ID index was older still. It represented six rules at v11. The live ruleset had 11 at v27. I needed the chronology and the index to advance together, otherwise a future investigation could find a changelog entry without the ID required to trace the rule it described.

The crowded stretch was on August 21. Seven versions, v19 through v25, landed inside three hours. I had assumed the cluster would resolve into a single story once I found the surrounding ticket comments. That was another bad model. The version API can reconstruct custom-rule changes, while bot settings and AI-bot policies live outside this ruleset and are not versioned there. I could document the actual sequence of custom-rule edits. I could not honestly credit the entire cluster to an unversioned setting just because the calendar was dense.

That limitation shaped the backfill. I added entries for versions 15 through 27 to CF-WAF-RULES.md in reverse chronological order, using the existing dated format. I refreshed the rule ID index at the same time. The work was documentation only. No firewall rule changed while I was closing the historical gap.

The second part was smaller in code and larger in consequence. I added a drift check to the weekly pre-release scan. It reads the live Cloudflare ruleset version, finds the newest Ruleset version N citation in CF-WAF-RULES.md, and warns when the document lags behind the API. That comparison is deliberately plain. It does not try to infer the motive for a rule change, classify the traffic, or synthesize a security verdict. It only asks whether the log has caught up to the rule set it claims to describe.

The first run after the merge was not a victory lap. The check reported that the gap had fallen from 13 versions behind to two. That remaining gap is why I trust the check more than the backfill. A one-time repair can make an old document look complete. A recurring version comparison makes its next omission visible.

The next weekly scan will compare the highest version in CF-WAF-RULES.md with Cloudflare’s live number. Two versions behind is now a warning, before it becomes 13.