Cloudflare Tunnel
Use a cloudflare-tunnel unit when the host has no public address, or when you do not want to expose nginx to the internet. It runs Cloudflare’s cloudflared connector as a container on the dpl network. The connector opens an outbound connection to Cloudflare. Cloudflare terminates TLS and forwards requests through the tunnel to your http-server.
type: cloudflare-tunnelsecret: cf-tunnel-tokenFields:
| Field | Required | Default | Purpose |
|---|---|---|---|
secret |
Yes | Secret that stores the tunnel token. | |
image |
No | docker.io/cloudflare/cloudflared:latest |
Connector image. |
dpl runs remotely-managed tunnels. You create the tunnel in the Cloudflare Zero Trust dashboard (Networks, then Tunnels), and the dashboard gives you a token. Store it as a secret:
dpl secret create cf-tunnel-tokenAt deploy, dpl encrypts the token into the unit’s runtime env. dpl start passes it to the container as the TUNNEL_TOKEN environment variable. It is never written to the command line.
Routing
Section titled “Routing”Public hostnames are not configured in dpl. In the dashboard, each public hostname points at a service URL inside the dpl network:
http://dpl--<http-server>:80<http-server> is the name of your http-server unit. Cloudflare creates the DNS records. nginx still needs a domain unit for each hostname, as usual.
Companion settings
Section titled “Companion settings”- Set
http_port: falseon thehttp-serverand leavehttps_portoff, so the host publishes no ports. nginx stays reachable from the connector container on the dpl network. - Set
proxy: {type: cloudflare-tunnel}on eachdomainserved through the tunnel, so nginx logs the real client IP and passes the original scheme to apps. See Trusted proxy settings.
Deploy and readiness
Section titled “Deploy and readiness”dpl deploy cf-tunnelThe unit takes no path argument. dpl pulls the image if it is missing, hands the container to dpl serve, and waits for readiness.
The connector image has no shell, so dpl cannot run its port probe inside it. Readiness means the container started and stayed running. A token that Cloudflare rejects right away fails the deploy. A token revoked later shows up in the log while dpl serve restarts the connector with backoff.
Connector output is written to <base>/state/<unit>/log/runtime.log.