Cloudflare Tunnel

Zero Trust architecture: Expose your server without opening firewall ports.

vpn_lock Architecture

[Visitor] --> [Cloudflare Edge] --> [Terminated HTTPS]
|
(HTTP/2 Tunnel)
|
v
[cloudflared] --> [Traefik] --> [Container]

Generating API Token

DockerAZ requires a specific API Token to manage the tunnel.

2
Create Custom Token.
3
Add Permissions:
- Zone:Read
- DNS:Edit
- Account.Cloudflare Tunnel:Edit

Tunnel Status

The dashboard displays the unique Tunnel ID and current connection status. You can also view live logs from the cloudflared daemon.