Cloudflare Tunnel
This page helps you put Goiabada on the internet through a Cloudflare Tunnel: no inbound port, no certificate and no Nginx.
cloudflared, Cloudflare’s connector, runs on your server and connects out to Cloudflare. Cloudflare serves HTTPS for both hostnames and sends each request down that connection to the Docker Compose file the setup wizard writes:
Browser ── HTTPS ──▶ Cloudflare ── tunnel ──▶ cloudflared on the host ── HTTP ──▶ 127.0.0.1:9090 and :9091You need a domain on Cloudflare, a server with Docker, two hostnames under that domain, such as auth.example.com and admin.example.com, and the setup wizard. Both hostnames must share a registrable domain: see What every method needs.
Set it up
Section titled “Set it up”-
Generate and start Goiabada. Run the setup wizard, choose Production with reverse proxy, enter
https://auth.example.comandhttps://admin.example.com, then start the files it wrote, as Docker Compose describes:Terminal window docker compose up -dcurl http://127.0.0.1:9090/health # healthycurl http://127.0.0.1:9091/health # healthy -
Create a tunnel. In the Cloudflare Zero Trust dashboard, go to Networks → Tunnels & Mesh, choose Create a tunnel, pick Cloudflared, and name it, such as
goiabada. -
Install
cloudflaredon the server, with the commands the dashboard shows for your operating system. The tunnel shows as Healthy once it has connected; on the server,sudo systemctl status cloudflaredshows it running. If you runcloudflaredin Docker instead, add--network hostto the dashboard’sdocker run, so that127.0.0.1in the routes below is the server’s and not the container’s. -
Route both hostnames to Goiabada. On the tunnel’s Published application routes tab, add two routes, each of type
HTTP. Creating the tunnel ends on the form for the first one:Hostname URL auth.example.com127.0.0.1:9090admin.example.com127.0.0.1:9091Cloudflare creates a proxied
CNAMErecord for each. If it says a record with that name already exists, delete the old record under DNS → Records and add the route again. -
Turn on Always Use HTTPS, under SSL/TLS → Edge Certificates for your domain, so a browser that asks for
http://is sent tohttps://. -
Sign in at
https://admin.example.com, as First sign-in describes.
What this setup gives you
Section titled “What this setup gives you”- Nothing on the server is published.
cloudflaredconnects out, so the firewall can refuse every inbound connection, and the server’s address never appears in DNS. The Compose file publishes 9090 and 9091 on127.0.0.1alone, where onlycloudflaredand other processes on the host reach them. - Cloudflare holds the certificates for both hostnames, and the tunnel encrypts the hop from Cloudflare to
cloudflared. Goiabada serves plain HTTP on the host, and marks its cookiesSecurebecause its URLs arehttps://. - Each server sees the client’s address, which Cloudflare appends to
X-Forwarded-For: see Client IP and proxy trust. - The admin console reaches the auth server inside the Compose network, not through the tunnel: see The hop to the auth server.