Everything you wanted to know about using Cloudflare Zero Trust Argo tunnels for your personal network. For those like me who were still confused even after reading the article, I think this is the lowdown:
- ZT tunnels let you expose private resources/services to the internet (or your users) via Cloudflare’s edge network. You install cloudflared on an internal host, and register a “tunnel” so that requests to a hostname or IP get forwarded securely into your network (similar to tailscale).
- Unlike classic VPNs (which open full network access) or traditional Cloudflare tunnels (which merely publish a service), this approach adds granular access control; you can define exactly who can access which resource, based on identity, device posture, login method, etc.
- It also solves NAT/firewall issues often faced by P2P-based overlays (e.g., Tailscale) by routing everything through Cloudflare’s network, avoiding connectivity failures when peer-to-peer fails.
For in-browser auth you can then use Cloudflare Access, or you can install the cloudflare Warp client which is a VPN-like thing that would give you full control over the access to whatever service(s) you were exposing this way.
The timing of this post is almost comical.
Maybe a bunch of lemmytors read it and went to try, resulting in an unexpected volume.

Ironic.

I see SO much cloudflare stuff on here, I have to believe they are ads/astroturfing. I can’t understand why so many self-hosting people would tie their services to them. In my mind it completely defeats the point to self hosting in the first place.
I don’t trust cloudflare, especially not with stuff like zero trust. They’re a terrible company and I think they should fail.
Tbf, I dont this Argo Tunnel has anything to do with zero trust. The product has just been nested under that umbrella.
It seems you’re right
Would you be willing to share more about your position? I’ve been happy with their service, but want to be fully informed about who I’m doing business with
They’re protecting scammers and other bad actors, their infra is run by junior DevOps “engineers” and every now and then they find another way to fuck half the internet.
They’re part of what’s wrong with USA-centric hosting nowadays.
Others posted good articles and thoughts aswell :)
and every now and then they find another way to fuck half the internet.
Like literally today lol, it has been giving me shit all morning.
Is there a European equivalent? At the moment I only do ddns with them and they are my registrar but don’t use the tunnela
This read is a good start:
Looks like a totally legit domain. Much trusting.
It is - that’s just how URLs in non-latin fonts look unfortunately. URLs, (and a ton of tech infrastructure) is hugely English/latin script biased.
The URL is Japanese.
Normally when i post these links i add a notice, as it seems not too many people know yet, but as suggest by another comment: this is puny code.
I can’t remember the exact technical details of it, but that’s how links are generated for non-Latin languages. If you go to the actual site it will display as the intended url
It’s punycode. Get with the times.
just access it through cloudfarse… you’ll be fine!
Could start with the fact that they go down about once a month now and take half the Internet with them.
They’re having a major outage as I’m reading this, lol.
I know, after I posted that I was looking at their outages and worrying that my 1/month estimate too much of an exaggeration cause they hadn’t had a big one in a bit.
Ah OK, so when you said “terrible company” you meant performance? I’ve had great performance with them so far fortunately
For me it’s reliability and generally scummy business practices.
They protect scammers and sell big data centres solutions that protect from DoS attacks 🤡
I wasn’t the original person that replied.
That’s less a problem with cloud flare it self and more just a issue of anything the scope and scale of what they have become. Even a better company would face the same issues.
It’s fair to argue that they we should spread things out more to make them more resilient.
But that’s more a knock against centralization than the service at hand. It’s also fair to show that they’re good enough that they were able to reach this point. Or more accurately. Everyone else was worse so they reached this point.
It always feels like blaming cloudford at this point is much like blaming the horse for its Rider.
I only started using Cloudflare tunnels recently, but I’m now using the self hosted alternative Pangolin on a VPS for private services, and I keep the Cloudflare tunnel for public web hosting, i.e WordPress. This also allows easy restriction to the WordPress login page for other users via Google auth etc which is something very simple with CF.
Having split up my private/public services to seperate tunnels also means I don’t stand the chance of taking the public services offline with my constant tinkering of Pangolin and the VPS it runs on.
I have pushed the CF tunnel for file transfers occasionally (which is against their terms), but it hits remarkable speeds for a ‘free’ service.
Is there a reason not to use pangolin for the public stuff too?
I’m just about to make the switch from CloudFlare to pangolin on VPS, and I wanna make sure I’m not missing anything
For those interested:
I’m interested to know if anyone is using a Cloudflare tunnel to stream audio? It breaks their terms but I’ve read that they tend to ignore it.
I access my Navidrome and Invideous instance without any issues. I am the only user on my network, so that would be a consideration if a lot of people were using your streaming services.
Idk about audio but they rate limit video pretty quickly. Audio might be low enough bandwidth for them to not care, but be cautious
I run audio and video through tunnels just fine. Last I checked they dropped the requirements for HTML only content and as long as you don’t abuse the service and cache too much data you’re OK with video and audio content.
I run audiobookshelf through it and it works flawlessly.
deleted by creator
This has been on my list of things to try for a while, but I’m currently in “if-it-aint-broke-dont-fix-it” mode.










