To prevent CDN bypassers, actually there is an undocumented feature built-in to Ghost.
If you set a key on “hostSettings.siteId” configuration value, then Ghost always expects this key on all requests with x-site-id request header. If you add this request header on your Cloudflare Rules, then direct requests to your Ghost instance bypassing Cloudflare will always fail.