They mean after adding a ddos mitigation like cloudflare, you should rotate the origin server IP so the origin server's IP is no longer publicly known and thus not directly reachable by ddos attackers. The only way to now interact with the application is though Cloudflare's network. You should only have to do this once as long as the origin IP doesn't publicly leak.
Another step would be to add firewall rules to only allow inbound traffic from cloudflare IPs: https://www.cloudflare.com/ips/
3 + 1 = 4
Checkmate liberals.