7 ms·
Tunnel via Cloudflare to any TCP service
- novalgrapefruit 3y ago[dead]
- rabuse 3y agoCloudflare tunnels have been a blessing for me, as someone locked behind an apartments router trying to host services without the ability to forward ports. The fact that it's free, is the cherry on top.
- datenyan 3y agoHow have you found it for hosting services? I found it struggled with something as simple as an Apache webserver, though perhaps that's just something to do with my internet itself.
- justsomehnguy 3y agoMy $5 is on the MTU mismatch.
- geraldhh 3y agothe internet is not going to accept bigger packets just because someone wants to add vpn-encapsulation (additional data). you either account for the overhead (mssfix) or your payload gets fragmented and performance goes to shit, deal with it 8)
- InvaderFizz 3y agoI've had my Plex server behind Cloudflare Tunnels for years, never had any performance or reliability issues. Another great use case is for SSH to a server quite some distance away. I find that the latency when using a cloudflare tunnel to SSH on average better than whatever route my ISP would normally take.
- Grimburger 3y ago> Plex server behind Cloudflare Tunnels for years Unless I'm missing something here, there's no way Cloudflare is allowing that much traffic through tunnels for free. Is this just setting up the initial plex connection through the tunnel and then going p2p?
- detaro 3y ago> there's no way Cloudflare is allowing that much traffic through tunnels for free What's the limit?
- InvaderFizz 3y agoNope, 100% of my external users go through CF tunnels. The downside is that the caching results in the entire file being cached immediately if the user is not using transcoding, but most of my users are utilizing transcoding. I put a bandwidth limiter on my Cloudflare tunnel to limit it to 100Mbps I don't have any actual stats, but there appear to be about 10-20 hours a day of remote streaming, mostly at 3Mbps. So we're only looking at 400-800GB on average per month. Also, you can use Cloudflare unregistered free tunnels just like the article, but using registered tunnels makes it so you don't have to update the Plex url every time you reconnect. I used unregistered tunnels until Cloudflare made tunnels available on free tier accounts with no bandwidth charges.
- _a9 3y agoIve been using a tunnel to share my jellyfin server to friends for about a year. Its pretty much a proxy for it (add jellyfin:port to the config, start cloudflared, access on jellyfin.my.domain on cloudflare). I havent had any issues with bandwidth but it depends on how much you push through it. Ive seen stories throughout the years of people pushing 30-50TB before getting a temp ban from using cloudflare services. Of course DNS still works but you just cant use their proxy/cdn/tunnels/etc
- piperswe 3y agoI've pushed quite a lot of traffic over Tunnels with no issues - IME it performs just as well as sending the traffic over Cloudflare without the Tunnel.
- pnpnp 3y agoFWIW you can do the same thing with a cloud server & a couple bucks a month. I use AWS/t4g.nano reserved instance & WireGuard, and I think it runs me less than half a beer a month.
- entangledqubit 3y agoI started doing this a year ago and it's been super solid and low maintenance.
- discardedrefuse 3y agoIf you're going to pay for AWS, might as well use Oracle's free tier. It is extremely generous. And you have to specifically change a setting to leave the free tier; So you it's not that easy to get accidentally billed for a misconfig. Yes, yes...I know..."ORACLE"!? choking sounds But at this point, they're no worse a company than Amazon. I've been very happy with their free tier for my home use. There's a bit of learning curve...just like AWS, but they give you a ton of free stuff, including training.
- nulbyte 3y ago+1 for Oracle. Their free tier for compute is better than Google's: Up to four free ARM VMs and up to two AMD VMs.
- matthewaveryusa 3y agoAnd the 10TB of free egress. Their proprietary stuff is very generous as well. Also 3000 emails/day -- really great offering tbh
- metadat 3y agoOracle OCI will randomly shut your instances down, which is super annoying. I stopped bothering to boot them back up again. Used to be a huge proponent, it was a good 4 years of freebies. But this too shall pass.
- 3y ago
- SadTrombone 3y agoI see options in my Cloudflare control panel to tunnel things besides HTTP(S) services (including TCP and SSH) via Cloudflare Tunnel. Am I misunderstanding the blog post?
- jchw 3y agoI think you're right. I'm using Cloudflare Tunnels with SSH just fine, though I haven't tried anything else yet. They definitely have a direct integration for SSH.
- amluto 3y agoThey have an SSH authentication solution, but IMO it’s rather half-baked. Definitely not a top-tier Cloudflare product.
- jchw 3y agoI am not using their solution for SSH authentication, but I am using Cloudflare Tunnels to access SSH normally. I'm actually surprised it can be used this way, but it seems it can.
- rattt 3y agoYeah it supports generic tcp forwarding, I only tried it once when it released but worked without issues. Needs cloudflared on the client as well but so does the method in the blogpost so should be about the same: https://developers.cloudflare.com/cloudflare-one/applications/non-http/arbitrary-tcp/ https://developers.cloudflare.com/cloudflare-one/application...
- accrual 3y agoI've been thinking about using a tunnel like this to host a retro computing website. My idea was to run OpenBSD i386 on an AMD K6-III (1999) host, then use the built-in webserver httpd(8) to render and serve a static site. The machine would be tunneled via Wireguard to a VPS, and the VPS could optionally terminate the TLS (and transmit plain HTTP over WG) to free up some CPU cycles. :)
- glenngillen 3y agoWe’ve been working on something (https://github.com/build-trust/ockam https://github.com/build-trust/ockam) that enables exactly this, among a whole host of other use cases. If you check out some of the code examples in the docs you’ll see how to setup a tunnel using the CLI. For other use cases there’s also the programming libraries (only Rust atm, though I was spiking a TypeScript/Node PoC this week) which might provide more flexibility. Personally I’m excited by the idea of being able to move this kind of secure by design connectivity all the way into the application layer though.
- m3kw9 3y agoWhy would I want to do that? Would certain firewalls setup cause issues?
- Toutouxc 3y agoCloudflare tunnel does support SSH on top of the main HTTP offering, but if it didn’t, it would be the kind of use case for this. And generally anything that talks something-over-TCP but not HTTP, so XMPP maybe? Databases, cameras and other IoT stuff? And if you’re asking why anyone would even do that, like why use Tunnel at all, then well, many people are behind all kinds of NAT or, like me, on a public IP with my ISP’s stateful firewall preventing anyone from talking to me. CF Tunnel allows you to hide all that in a nice outgoing TCP connection and if your firewall allows that (which it probably does), you’re golden.
- jftuga 3y agoI wrote something tangentially related, but for single user. "gofwd" is a cross-platform TCP port forwarder with Duo 2FA and Geographic IP integration. Its use case is to help protect services when using a VPN is not possible. Before a connection is forwarded, the remote IP address is geographically checked against city, region (state), and/or country. Distance (in miles) can also be used. If this condition is satisfied, a Duo 2FA request can then be sent to a mobile device. The connection is only forwarded after Duo has verified the user. https://github.com/jftuga/gofwd https://github.com/jftuga/gofwd
- adamch 3y agoYou don't need a websocket proxy. CF tunnel supports TCP and UDP just fine.
- moontear 3y agoThis is what I was wondering when reading the article. I do SSH forwarding just fine with a CF tunnel. No extra services needed.
- geraldhh 3y agogood find! the audience probably feels more comfortable working with technologies that have a "web" prefix and or can be deployed to a shared webhosting account aka cloud
- thegeekpirate 3y agoJust wanted to inform you that your HN profile as well as your blog's "About me" need to be updated. Cheers!
- ztgasdf 3y ago> Error validating origin URL: Currently Cloudflare Tunnel does not support udp protocol. You sure?
- boringuser2 3y agoNobody has yet mentioned that they get full unencrypted access to all of your traffic if you do this, so I shall.
- dave4420 3y agoJust like any VPN.
- mrAssHat 3y agoThat's why you shouldn't buy VPN services. Buy a hosting instead and host your VPN yourself. This is bonkers that people so actively discuss this. That's like using 3rd party service to access your bank account.
- zamnos 3y agowhich millions of people do. So many of them that Intuit bought mint.com.
- Grimburger 3y ago> Buy a hosting instead and host your VPN yourself. So the ISP gets access instead of the VPN? All this does is shift trust, not remove it.
- mrAssHat 3y agoHow does ISP get insecure traffic? Your connection to your VPN (and then from there to your bank) should be encrypted and none of inbetween hosts should be able to decrypt it.
- usr1106 3y agoThe submitted blog post says it.
- efrecon 3y agoI wrote something similar to be able to run vscode against any remote machine. This was before vscode's own tunnels. https://github.com/efrecon/sshd-cloudflared https://github.com/efrecon/sshd-cloudflared It automatically runs a dockerised sshd to access your directory. The sshd is configured using your github's keys to protect access.
- nirui 3y agoOK... if you want to know the REAL benefit of doing this... With this method, you effectively turn Cloudflare into a transport, which enables you to get around the limitation of Cloudflare. Say what if you want to transport UDP packets now (for your Wireguard for example)? Cloudflare don't really support that currently, but now it's achievable (albeit, not the best way). The software used, both websocat, and gost is there to convert/proxy (non-Cloudflare specific) WebSocket connections to arbitrary TCP/UDP (supported by gost). You need to install them on both end of your endpoint through, to enable full conversion (App TCP client -> websocat/gost client -> [Cloudflare via Websocket] -> websocat/gost server -> App TCP server). Also, you can use Tor network to do similar things, just with .onion service. Tor only supports TCP proxying (if I remembered it correctly), now you can do UDP too.
- lapinot 3y agoI'm quite surprised to read what feels like a cloudflare ad from THC..
- alexellisuk 3y agoHi, I'm the author of Inlets. We've seen a recent rise in users looking to tunnel TCP traffic w/o these kinds of hacks and additional tools. I wrote up a quick guide back in early May - seems relevant to this article as one of the newest users couldn't get Cloudflare to work with TCP how he wanted. https://inlets.dev/blog/2023/05/04/expose-local-tcp-ports.html https://inlets.dev/blog/2023/05/04/expose-local-tcp-ports.ht...
- anderspitman 3y agoCloudflare Tunnel is a great service, but if you're looking for selfhosted alternatives I maintain a list here: https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling
- hotpotamus 3y agoI don't know if Corkscrew is still relevant, but if you're maintaining a list, it might have a place there. I forget exactly why, but I used it some years ago. https://github.com/bryanpkc/corkscrew https://github.com/bryanpkc/corkscrew