What's the best way to secure Dgraph Cloud (via GCP with HA (and replication) setup) from DDoS attacks?

Can I secure my GraphQL endpoint with Cloudflare? how? Sure with CNAME or something like that, but the original endpoint would be still accesable. This requires once again a setup like VPC, and this has to be done on Google Cloud. And i dunno if I even have access to that if I use dgraph cloud, else I still don’t wanna mess up with that (changing dgraph cloud network settings and so on)

I would really appreciate a Tutorial to safely do that