No Description

Luis Neto 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
.github 659da3ebba Update semgrep.yml 8 months ago
.mac_resources 0c65daaa7d AUTH-2712 mac package build script and better config file handling when started as a service 5 years ago
.teamcity 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
carrier 887e486a63 TUN-7057: Remove dependency github.com/gorilla/mux 2 years ago
cfapi e144eac2af TUN-9171: Use `is_default_network` instead of `is_default` to create vnet's 2 days ago
cfio d1a4710aa2 TUN-6035: Reduce buffer size when proxying data 3 years ago
client 3bf9217de5 TUN-9319: Add dynamic loading of features to connections via ConnectionOptionsSnapshot 3 weeks ago
cmd 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
component-tests 9695829e5b TUN-8857: remove restriction for using FIPS and PQ 4 months ago
config 8c2eda16c1 TUN-8861: Add configuration for active sessions limiter 4 months ago
connection 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
credentials 553e77e061 chore: fix linter rules 2 months ago
datagramsession 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
diagnostic 7336a1a4d6 TUN-8914: Create a flags module to group all cloudflared cli flags 4 months ago
edgediscovery a3ee49d8a9 chore: Remove h2mux code 7 months ago
features 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
fips 31a870b291 TUN-8855: Update PQ curve preferences 4 months ago
flow 4eb0f8ce5f TUN-8861: Rename Session Limiter to Flow Limiter 4 months ago
hello b500e556bf TUN-7590: Remove usages of ioutil 1 year ago
ingress 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
internal 93acdaface TUN-7125: Add management streaming logs WebSocket protocol 2 years ago
ipaccess 99d4e48656 TUN-6016: Push local managed tunnels configuration to the edge 3 years ago
logger 2827b2fe8f fix: Use path and filepath operation appropriately 2 months ago
management 553e77e061 chore: fix linter rules 2 months ago
metrics 02e7ffd5b7 TUN-8792: Make diag/system endpoint always return a JSON 5 months ago
mocks 4eb0f8ce5f TUN-8861: Rename Session Limiter to Flow Limiter 4 months ago
orchestration 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
overwatch 2f70b05c64 AUTH-2169 make access login page more generic 5 years ago
packet 9da15b5d96 TUN-8640: Refactor ICMPRouter to support new ICMPResponders 6 months ago
proxy 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
quic 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
retry 553e77e061 chore: fix linter rules 2 months ago
signal 073c5bfdaa TUN-1562: Refactor connectedSignal to be safe to close multiple times 6 years ago
socks b500e556bf TUN-7590: Remove usages of ioutil 1 year ago
sshgen 687682120c TUN-8333: Bump go-jose dependency to v4 1 year ago
stream d1e338ee48 TUN-7545: Add support for full bidirectionally streaming with close signal propagation 1 year ago
supervisor 3bf9217de5 TUN-9319: Add dynamic loading of features to connections via ConnectionOptionsSnapshot 3 weeks ago
tlsconfig b500e556bf TUN-7590: Remove usages of ioutil 1 year ago
token 906452a9c9 TUN-8960: Connect to FED API GW based on the OriginCert's endpoint 3 months ago
tracing 53c523444e add: new go-fuzz targets 6 months ago
tunneldns b500e556bf TUN-7590: Remove usages of ioutil 1 year ago
tunnelrpc 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
tunnelstate 4b0b6dc8c6 TUN-8728: implement diag/tunnel endpoint 6 months ago
validation 53c523444e add: new go-fuzz targets 6 months ago
vendor 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
watcher 65247b6f0f TUN-7584: Bump go 1.20.6 1 year ago
websocket 887e486a63 TUN-7057: Remove dependency github.com/gorilla/mux 2 years ago
.docker-images e89bceca5e TUN-6825: Fix cloudflared:version images require arch hyphens 2 years ago
.dockerignore d54c8cc745 TUN-5129: Use go 1.17 and copy .git folder to docker build to compute version 3 years ago
.gitignore 599ba52750 TUN-8708: Bump python min version to 3.10 7 months ago
.gitlab-ci.yml 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
.golangci.yaml 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
CHANGES.md 2feccd772c Release 2025.1.1 4 months ago
Dockerfile 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
Dockerfile.amd64 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
Dockerfile.arm64 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
LICENSE c54e8cd8e6 TUN-5851: Update all references to point to Apache License 2.0 3 years ago
Makefile 236fcf56d6 DEVTOOLS-16383: Create GitlabCI pipeline to release Mac builds 1 month ago
README.md e0b1ac0d05 chore: Update tunnel configuration link in the readme 2 months ago
RELEASE_NOTES a62d63d49d Release 2025.5.0 3 weeks ago
build-packages-fips.sh 45f67c23fd TUN-8858: update go to 1.22.10 and include quic-go FIPS changes 4 months ago
build-packages.sh bd9e020df9 TUN-8583: change final directory of artifacts 10 months ago
catalog-info.yaml 86e8585563 SDLC-3727 - Adding FIPS status to backstage 1 month ago
cfsetup.yaml 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
check-fips.sh 70e675f42c TUN-5551: Reintroduce FIPS compliance for linux amd64 now as separate binaries 3 years ago
cloudflared.wxs 9e1f4c2bca Remove extraneous `period` from Path Environment Variable (#1009) 1 year ago
cloudflared_man_template 1ed9e0fceb AUTH-2644: Change install location and add man page 4 years ago
fmt-check.sh 515ad7cbee TUN-6917: Bump go to 1.19.3 2 years ago
github_message.py 4642316167 TUN-6823: Update github release message to pull from KV 2 years ago
github_release.py 236fcf56d6 DEVTOOLS-16383: Create GitlabCI pipeline to release Mac builds 1 month ago
go.mod 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
go.sum 96ce66bd30 TUN-9016: update go to 1.24 1 day ago
postinst.sh 28d556b8d4 AUTH-2858: Set file to disable autoupdate 4 years ago
postrm.sh 47ad3238dd TUN-8290: Remove `|| true` from postrm.sh 1 year ago
release_pkgs.py 5cfe9bef79 TUN-8842: Add Ubuntu Noble and 'any' debian distributions to release script 5 months ago
wix.json 0c65daaa7d AUTH-2712 mac package build script and better config file handling when started as a service 5 years ago

README.md

Cloudflare Tunnel client

Contains the command-line client for Cloudflare Tunnel, a tunneling daemon that proxies traffic from the Cloudflare network to your origins. This daemon sits between Cloudflare network and your origin (e.g. a webserver). Cloudflare attracts client requests and sends them to you via this daemon, without requiring you to poke holes on your firewall --- your origin can remain as closed as possible. Extensive documentation can be found in the Cloudflare Tunnel section of the Cloudflare Docs. All usages related with proxying to your origins are available under cloudflared tunnel help.

You can also use cloudflared to access Tunnel origins (that are protected with cloudflared tunnel) for TCP traffic at Layer 4 (i.e., not HTTP/websocket), which is relevant for use cases such as SSH, RDP, etc. Such usages are available under cloudflared access help.

You can instead use WARP client to access private origins behind Tunnels for Layer 4 traffic without requiring cloudflared access commands on the client side.

Before you get started

Before you use Cloudflare Tunnel, you'll need to complete a few steps in the Cloudflare dashboard: you need to add a website to your Cloudflare account. Note that today it is possible to use Tunnel without a website (e.g. for private routing), but for legacy reasons this requirement is still necessary:

  1. Add a website to Cloudflare
  2. Change your domain nameservers to Cloudflare

Installing cloudflared

Downloads are available as standalone binaries, a Docker image, and Debian, RPM, and Homebrew packages. You can also find releases here on the cloudflared GitHub repository.

User documentation for Cloudflare Tunnel can be found at https://developers.cloudflare.com/cloudflare-one/connections/connect-apps

Creating Tunnels and routing traffic

Once installed, you can authenticate cloudflared into your Cloudflare account and begin creating Tunnels to serve traffic to your origins.

TryCloudflare

Want to test Cloudflare Tunnel before adding a website to Cloudflare? You can do so with TryCloudflare using the documentation available here.

Deprecated versions

Cloudflare currently supports versions of cloudflared that are within one year of the most recent release. Breaking changes unrelated to feature availability may be introduced that will impact versions released more than one year ago. You can read more about upgrading cloudflared in our developer documentation.

For example, as of January 2023 Cloudflare will support cloudflared version 2023.1.1 to cloudflared 2022.1.1.

Development

Requirements

Build

To build cloudflared locally run make cloudflared

Test

To locally run the tests run make test

Linting

To format the code and keep a good code quality use make fmt and make lint

Mocks

After changes on interfaces you might need to regenerate the mocks, so run make mock