Cloudflare Tunnel
Publish a private service without opening a port.
- made by
- Cloudflare
Magic Ship is one shop in Vancouver, BC, working remotely with clients worldwide. We are not a partner, reseller, or certified vendor of Cloudflare - we just build with this.
What Cloudflare Tunnel is
Cloudflare Tunnel runs a small daemon next to a service that holds an outbound connection to Cloudflare's network. Requests for the hostname arrive at Cloudflare and are delivered down that connection, so the origin needs no public IP and no inbound firewall rule. Access policies can sit in front of it.
How we use it
We use it to put an internal or self-hosted service on a real hostname with TLS in minutes, which is how demo environments and internal tools get shared with a client. The tunnel configuration lives in version control next to the compose file, so the hostname mapping is reviewable rather than folklore. Zero Trust policies in front of a tunnel are how we gate a staging surface without building auth into it first.
Where it is the wrong choice
It puts Cloudflare in the path of every request, which some clients cannot accept for data residency or vendor reasons, and it is a poor fit for latency-sensitive or non-HTTP protocols. A VPN or a private network link is the right answer there.
Service lines it turns up in
Related tools
More in Infrastructure and deploy
Other tools in the same service lines
Building something on Cloudflare Tunnel?
Send the problem rather than a job spec. You get an answer on scope, on fit, and on whetherCloudflare Tunnel is even the right call for it.
Start a projectCloudflare Tunnel and Cloudflare are trademarks of their respective owners, used here to say what we work with.