Skip to content

Cloudflare Tunnel

This page helps you put Goiabada on the internet through a Cloudflare Tunnel: no inbound port, no certificate and no Nginx.

cloudflared, Cloudflare’s connector, runs on your server and connects out to Cloudflare. Cloudflare serves HTTPS for both hostnames and sends each request down that connection to the Docker Compose file the setup wizard writes:

Browser ── HTTPS ──▶ Cloudflare ── tunnel ──▶ cloudflared on the host ── HTTP ──▶ 127.0.0.1:9090 and :9091

You need a domain on Cloudflare, a server with Docker, two hostnames under that domain, such as auth.example.com and admin.example.com, and the setup wizard. Both hostnames must share a registrable domain: see What every method needs.

  1. Generate and start Goiabada. Run the setup wizard, choose Production with reverse proxy, enter https://auth.example.com and https://admin.example.com, then start the files it wrote, as Docker Compose describes:

    Terminal window
    docker compose up -d
    curl http://127.0.0.1:9090/health # healthy
    curl http://127.0.0.1:9091/health # healthy
  2. Create a tunnel. In the Cloudflare Zero Trust dashboard, go to Networks → Tunnels & Mesh, choose Create a tunnel, pick Cloudflared, and name it, such as goiabada.

  3. Install cloudflared on the server, with the commands the dashboard shows for your operating system. The tunnel shows as Healthy once it has connected; on the server, sudo systemctl status cloudflared shows it running. If you run cloudflared in Docker instead, add --network host to the dashboard’s docker run, so that 127.0.0.1 in the routes below is the server’s and not the container’s.

  4. Route both hostnames to Goiabada. On the tunnel’s Published application routes tab, add two routes, each of type HTTP. Creating the tunnel ends on the form for the first one:

    Hostname URL
    auth.example.com 127.0.0.1:9090
    admin.example.com 127.0.0.1:9091

    Cloudflare creates a proxied CNAME record for each. If it says a record with that name already exists, delete the old record under DNS → Records and add the route again.

  5. Turn on Always Use HTTPS, under SSL/TLS → Edge Certificates for your domain, so a browser that asks for http:// is sent to https://.

  6. Sign in at https://admin.example.com, as First sign-in describes.

  • Nothing on the server is published. cloudflared connects out, so the firewall can refuse every inbound connection, and the server’s address never appears in DNS. The Compose file publishes 9090 and 9091 on 127.0.0.1 alone, where only cloudflared and other processes on the host reach them.
  • Cloudflare holds the certificates for both hostnames, and the tunnel encrypts the hop from Cloudflare to cloudflared. Goiabada serves plain HTTP on the host, and marks its cookies Secure because its URLs are https://.
  • Each server sees the client’s address, which Cloudflare appends to X-Forwarded-For: see Client IP and proxy trust.
  • The admin console reaches the auth server inside the Compose network, not through the tunnel: see The hop to the auth server.