Just reach out to someone at Cloudflare. I'm sure they'd love your business.
OpenZiti approach (1) for example:
a. enroll each side of the webhook w/ X.509 identity
b. X.509 gates a network overlay between the servers
c. each server initiates outbound sessions to the overlay
d. block everything else (deny-all inbound on both servers)
(1) disclosure: i am a maintainer of the openziti foss, and you can only (fully) use the technique above if you have enough control of both sides, e.g. use a Lambda function: https://blog.openziti.io/my-intern-assignment-call-a-dark-we...
I do wonder, though, how does OpenZiti deal with client certificates expiring? Do you not set/enforce an expiration date or do you have some kind of automated renewal mechanism?
for client endpoints, there are currently 2 choices and at least 3 in the future:
1. admins chooses to enable client endpoints to continue to auth with expired client certs. the admin revokes access (when necessary) at an endpoint level or at a service level (least privileged access) via those constructs, rather than cert constructs.
2. admins don't permit expired certs to be used. the admin is managing the certs.
3. as a third choice for client endpoints, ziti has plans to enable admins to use the API used by the fabric infra mentioned above. this is future, with timing mainly dependent on openziti community priorities and related work.
Bypassing the rules is a workaround, but not a fix
The WAF doesn't really matter for my use case as the route is handled by a CF worker, in fact I'd prefer it doesn't get in the way.