Four settings, and choosing wrongly breaks the site.
OFF
No encryption between visitor and Cloudflare. Never use this.
FLEXIBLE
Visitors connect to Cloudflare over https; Cloudflare connects to your server over plain http.
This is the cause of most Cloudflare redirect loops. Your server redirects http to https, Cloudflare requests http again, and the cycle repeats.
FULL
Encrypted end to end, but Cloudflare does not verify your server's certificate. A self-signed or expired certificate is accepted.
FULL (STRICT)
Encrypted end to end, with Cloudflare verifying your server's certificate properly.
WHICH TO USE
Full (strict), once AutoSSL has issued a valid certificate on our server. That is the correct setting and the one to choose.
HOW TO CHANGE IT
Cloudflare dashboard > SSL/TLS > Overview.
IF YOU ARE SEEING A LOOP
Change to Full (strict) first. It resolves the majority of cases immediately.