https://developers.cloudflare.com/web3/ipfs-gateway/concepts/dnslink/
If you add the frontend as a statically published IPFS hash on a subdomain, the integrity of the frontend can be cryptographically verified by CloudFlare before being served.
Because the content being served is determined by DNS pinning looked up by an untrusted ingress node, you can be certain that as long as the ingress is not compromised the user will get the right content.