How to solve the problem of source IP leakage and DD attacks even when using Cloudflare CDN?

This or alternatively, a simpler approach would be to use what’s called a cloudflare tunnel. It should be a one-time setup and then you should be able to mostly close off your firewall for inbound connections.