How to Use Cloudflare Tunnel to Protect Private Applications

Overview

Cloudflare Tunnel allows an application or server to connect outbound to Cloudflare, so the service can be published without opening public inbound ports on the origin.

  1. Choose the application hostname, such as app.example.com or staging.example.com.
  2. Install cloudflared on the server or supported environment.
  3. Create a Tunnel in Cloudflare Zero Trust.
  4. Map the public hostname to the local service, such as http://localhost:8080.
  5. Add Cloudflare Access policies for private or staff-only applications.
  6. Close unnecessary inbound firewall ports after testing.
  7. Monitor Tunnel health and keep cloudflared updated.

Common Mistakes to Avoid

  • Publishing a private application without Access policies.
  • Leaving the same service open publicly on the origin IP.
  • Using Tunnel as a replacement for application updates and authentication.
  • Forgetting to document who can access the protected application.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support