All templates

Automated Bunny.net Pull Zone Config Audit

Every Monday, WebRun opens the Bunny.net panel, reads the origin URL, hostnames, edge rules and security settings on every pull zone, compares each zone against the pattern the rest follow, posts the drift to Slack, and drafts a Gmail summary for the engineer who owns the CDN.

Runs on WebRun · Strict Lockdown policy
Every Monday at 9:00 AM WebRunorchestrates each step
1 Bunny.net read every pull zone's settings
2 Slack post the configuration drift
3 Gmail draft the owner's summary
In short

How do I audit the configuration on my Bunny.net pull zones?

WebRun opens the Bunny.net panel every Monday, reads the origin, hostnames, edge rules and security settings on every pull zone, and compares each against the pattern the rest follow. It posts the drift to Slack and drafts a Gmail summary, so a forgotten rule is caught before it bites.

  • Zones that drifted from the rest are named every Monday
  • Origin and security differences are reviewed before they cause an incident
  • The CDN owner gets a drafted weekly summary without writing it

Built for platform engineers · DevOps teams · web agencies · SaaS operations

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens panel.bunny.net in a real browser with your saved login - no setup, no API keys.

  2. 1
    Bunny.net - read every pull zone's settings
    bunny.net
    WebRun in Bunny.net: read every pull zone's settings
    WebRun opens Bunny.net to read every pull zone's settings.
    • Open the Bunny.net panel and list every pull zone
    • Read the origin URL, the attached hostnames, and the certificate status on each
    • Read the edge rules and note zones with rules the others do not have
    • Read the security settings and flag anything left open that is locked elsewhere
    • Compare each zone against the pattern the majority of zones follow

    Done when Every pull zone has a current settings snapshot and its differences from the rest are noted.

  3. 2
    Slack - post the configuration drift
    slack.com
    WebRun in Slack: post the configuration drift
    WebRun opens Slack to post the configuration drift.
    • Post the drift report to your engineering channel
    • List each zone with the setting that differs and what the other zones do
    • Put anything touching origin exposure or security settings at the top
    • Note the zones that matched the pattern with nothing to review

    Done when The engineering channel has this week's configuration drift report.

  4. 3
    Gmail - draft the owner's summary
    gmail.com
    WebRun in Gmail: draft the owner's summary
    WebRun opens Gmail to draft the owner's summary.
    • Draft a Gmail summary addressed to the engineer who owns the CDN
    • Include the zone list, the differences found, and what changed since last week
    • Leave the message as a draft for a human to read and send

    Done when A weekly summary is drafted in Gmail and waiting for review.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
panel.bunny.net
ScheduleRuns automatically on this cadence
Every Monday at 9:00 AM
DeliveryHow each run's result reaches you
Drift report · Slack
OutputWhat each run produces - A weekly report of pull zones whose origin, hostnames, edge rules or security settings differ from the rest of the estate.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it change any of my zone settings?

No. WebRun reads the panel and reports what differs. Editing an origin, a hostname, an edge rule, or a security setting stays with your engineers, so a live CDN is never reconfigured by an automation.

How does it know what the right setting is?

It compares each zone against the pattern the rest of your zones follow, so the odd one out is what gets flagged. You can also give WebRun your own baseline in plain language and it checks against that instead.

How is this different from CDN performance reporting?

Performance reporting reads traffic: hits, bandwidth, cache ratio. This run reads configuration: origins, hostnames, edge rules, and security settings, which is where a forgotten rule or an exposed origin hides.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.