Overview
Cloudflare Tunnel allows an application or server to connect outbound to Cloudflare, so the service can be published without opening public inbound ports on the origin.
Recommended Steps
- Choose the application hostname, such as
app.example.comorstaging.example.com. - Install
cloudflaredon the server or supported environment. - Create a Tunnel in Cloudflare Zero Trust.
- Map the public hostname to the local service, such as
http://localhost:8080. - Add Cloudflare Access policies for private or staff-only applications.
- Close unnecessary inbound firewall ports after testing.
- Monitor Tunnel health and keep
cloudflaredupdated.
Common Mistakes to Avoid
- Publishing a private application without Access policies.
- Leaving the same service open publicly on the origin IP.
- Using Tunnel as a replacement for application updates and authentication.
- Forgetting to document who can access the protected application.