263 comments

[ 1.4 ms ] story [ 64.6 ms ] thread
It's a nice ability, but I dont like the terms of use.
On what url were those? Or Cloudflare's TOS in general ?
I just spent a week writing a harness around the existing tunnels to make this by hand.
Historically, we’ve found that their tunnels have really high latency variance. For example something that’s normally 30-50ms to ec2 is now 115ms-750ms
Because it travels along their edge. It's apples and oranges to your AWS tunnel.
No, they claim their edge is better for residential connections to your backend. We tried multiple SF to us-east-1 and it was always substantially worse
No-ip gives out free dynamic DNS with a static URL. I use it for Sunshine desktop streaming when I travel.
Yeah, but then you are always exposing your public IP.
Exposing it to what exactly? The internet? Yes that's how it works
This requires no port forwarding, so someone brute force scanning your IP won't find this and your open port. they also might have a harder time figuring out what service has been exposed since the port number itself will be unknown.
If somebody learns that such-and-such DynDNS URL is mine, they can always do a DNS lookup to find my current IP address. They can:

- find my approximate physical location

- regularly scan ports on my IP and wait for me to accidentally expose a service I didn't mean to

- track me in any access logs they have access to

They can, and do, do this with or without DynDNS.
Do you mean by getting the information from Cloudflare, or some other way? With DynDNS though, finding out my IP is trivial and does not require any special powers or skills, it is just a DNS lookup.

PS. Just re-watched your matrix LED pendant video. It is so well done, both the project, and the accompanying video!

They're scanning all IPs all the time. If your home router has a public IP and a firewall log, check it
But with Cloudflare tunnel (and similar tools), there are no open ports on the origin server.
Is this their version of https://tailscale.com/tailcat ? I can't tell if you need to auth

edit: yeah, it says no account creation, neat!

More like their version of Tailscale funnel I think
I believe with tailscale you don’t have to trust a 3rd party with your cleartext traffic
But you do seem to get to host a https version of your app in case you need features locked behind secure context.
That can't be right. If they're hosting on a different DNS they have an absolute need to MITM ssl/tls traffic. Can't work otherwise.

So cloudflare sees your plaintext.

This is handy, but I wonder how much it will cannibalize their services. I have a simple app deployed on cloudflare for a very niche single purpose use, but I wouldn't have bothered if I had this. Serving it from my own machine would have been fine.
Not many people run their local machine 24/7.
What does reality look like on this nowadays?

My initial thought was desktops generally run 24/7, with laptops running when in use. At least for the customer at the market intersection for this type of product.

I often tell my dev colleagues to avoid having their PC turned on all the time, be it because of the electricity bill cost, environmental impact or simply to make the longevity of the hardware a little longer. Granted almost everyone just ignores those things even if they're conscious of it, so I'd say you're right
There's pros and cons on the longevity side. 24/7 use causes more wear to mechanical parts (fans for instance) but can be better for the electronics, as heat cycles are a big part of the problem there.
Very few people own desktops anymore. Generally people only buy desktops if they need to run a GPU, such as for gaming or running a local model.
Yeah my desktop is on 24/7. Laptop is on when in use. Phone is on all the time too, of course, but I don't use it for browsing or work nearly as much as my desktop.
There are people who turn off their computer?
You do if you're hosting a website on it :-)
Maybe it's a nice way to quickly test a new service or change over the internet without going through the git process, same way one would use ngrok - I could see that being helpful when prototyping / pocs, etc - before deploying changes to your app via the proper channel, especially if you are already using cloudflare for your domains/apps. As other people said, it probably would not be practical or scalable for most people to run an app 24/7 from their laptop using their home or office internet connection.
Tunneling was something that recently fell out of the work I've been doing [1]. I've used Cloudflare Tunnels before but I just have low trust with them recently with how big they are getting. All of these nice things come at the cost of pushing _a lot_ of traffic through their systems.

[1]: https://dntls.substack.com/p/the-new-internet

This is pretty great and I think this will be quite important in the age where everyone has their self-hosted services.
If there's any company in the world that can survive a lot of extra traffic being pushed through their systems it's Cloudflare.

I bet these new tunnels end up being a fraction of a percentage point of their network traffic.

They see all the traffic in cleartext. Plus you have to trust them not to maliciously alter your traffic. As a US company, their options may be limited if they are coerced by their government to do so.
Reality check - you are not pushing “_a lot_” of traffic relative to any hyperscaler or large scale CDN. They push hundreds of Tbps sustained. You don’t peak at a few Mbps.

They can monitor extreme outliers. It’s not an issue for them.

I think they're talking about market capture risks
In hindsight, that was probably a confusing sentence. I was more pointing out how much traffic flows trough their systems which ends up making it an attractive honeypot, especially as a U.S. company.
Sure any centralization of infra is an obvious risk for a myriad of reasons eg DoS, manipulation, honeypots, etc.

But again my point applies - the chances they get enough people using it that it becomes a meaningfully worse security target than lots of other existing things seems … super low.

It’s a big world, people make many choices I can’t understand (nix? Haskell? Php? <flame wars to /dev/null>). Even if this product nailed it - the number of people who can use it is minuscule - yes even as we add Claude-enabled PMs to the software dev ranks.

Alt view with the old saying - “put all your eggs in one basket … and watch that basket!”

[delayed]
True. Same reason Hurricane Electric peers promiscuously. I'm surprised more networks don't, to be honest - wouldn't say DTAG prefer that you peer with DTAG than peer with HE upstream of DTAG?
Interesting how 4/4 other replies didn't get the centralisation concern despite it being a fairly often discussed topic
Yeah, it reminds me of Google. Fool me twice ...

I'm not trusting any of these corporates any more

Your opening piqued my interest, but:

“The substrate itself consists of a few systems…”

I doubt that this is how wordy your communication is.

“It consists of a few systems” would be adequate. And if we had prior context about what else exists that surrounds “the substrate” the “substrate itself” distinction would be meaningful, but it’s not, because you are referring to one object, which is the system you built, and I doubt any enzymes act on it, so it’s likely not a substrate.

Don't all these free proxy services always fall prey to blacklists because scammers,etc abuse them until they're useless?
Wow, exfiltrating data has never been easier!
Can confirm. Coming from ngrok, the main reason we had to make tunneling not anonymized etc was because of scammers, etc on the internet. Other players in the space bypass this by open sourcing the tech, or separating the architecture entirely. This is cool and all, but ultimately gives nefarious actors on the internet more opportunities.
How does “open sourcing the tech” “give nefarious actors on the internet more opportunities”? Sounds like a paltry excuse for not open sourcing your tech.
Probably why they used the trycloudflare.com domain as they expect it to be blocked.
Does this have a more generous allowance than ngrok? From what I can read no limits are mentioned
These are the limitations mentioned on the docs [1]. Quick Tunnels are subject to a hard limit on the number of concurrent requests that can be proxied at any point in time. Currently, this limit is 200 in-flight requests. If a Quick Tunnel hits this limit, the HTTP response will return a 429 status code. Quick Tunnels do not support Server-Sent Events (SSE).

[1]: https://developers.cloudflare.com/cloudflare-one/networks/co...

My AI discovered this days ago when I wanted to deploy a new vibe coded website (it was to keep score while playing whist and rentz)

Thought it was very cool

If your a hobbiest or dev just testing your services, it makes more sense to utilize onion services imho.

It does the exact same thing, except supported by a global network of volunteers around the world.

Sure, you get some latency, but this is actually ideal for testing. You should know how your service operates in non optimal lightning fast conditions.

This has existed for a long time and has been abused by quite a few people. I've seen some cc nodes using a random known cloudflare site and spoofing hostname to a temporary cloudflare site. IMO this should require a login at bare minimum.
if you think people won't abuse it because you're making them log in with a free email address...
what a sloppy website, did cloudflare fired bunch of ui/ux designer? Every text is slop lol.
yep, and all those fired and remaining are busy ai-native proofing their careers and tokenmaxxing everything including copy
Looks like they straight up vibe coded the landing page lol.
I like Cloudflare Tunnels a lot, but something that annoys me is that officially you're not allowed to use them for streaming video, meaning I can't put it in front of my Jellyfin without breaking TOS.

I think that rule is more of a "we reserve the right to..." rule, but it makes me sad because I'd rather not open up ports on my router to expose my Jellyfin to my parents.

I discovered and set this up the other day, added jellyfin, immich and forgejo and was really happy about the result for five minutes, before I discovered that limitation in the TOS. Now I only use it for forgejo. Have you found a different solution to exposing jellyfin?
i just use wireguard or tailscale, provision a subdomain with a custom ssl and resolve to a nat ip.
Use pangolin (you can self host), been using it for a while and it’s great, under the hood it’s a vpn+reverse proxy which you can do yourself too. In pangolin you can have public or private resources, where private ones you need to authenticate through pangolin first (either pass or others like pin number for your parents so easy to remember). When you link your domain for public ones, I suggest you make a sub domain for it, so your apps will be a sub to your subdomain, that way you keep control of your main domain while having automatic assignment for your apps rather than manually, and if you didn’t issue a certificate, that sub.subdomain is basically invisible on the internet unless you host a service to expose it.
Bandwidth costs money and streaming video costs several orders of magnitude more than just your random web/dev apps. Asking CF to foot the bill for entertainment streaming is really quite a lot.
I know. I'm not "upset" over it, just that it makes the service less useful for me.
You can put nginx with basic auth in front of jellyfin
Are we in an age where no one even bothers to open the product pages they generate? The first subtitle with the font color almost matching the background. Or it's even worse that a human looked at it and said "yep, that's OK"?
I find it shocking that they shipped this claudecopy.
Cloudflare is going full vibecoding for at least one year. They are high on AI psychosis.
For someone looking for an opensource solutions, following is an awesome resource for tunnelling

https://github.com/anderspitman/awesome-tunneling

I have played around with frp, bore and ngrok.

frp is nice. I have the tiniest Amazon Lightsail instance running a tunnel to a Minecraft server in my basement. It’s cheaper than getting a fixed IP from my ISP, at sufficiently low traffic.
The website looks broken in dark mode on Firefox.
Quick Tunnels look great for demos and temporary dev environments. I’d still be hesitant to make them part of a long-lived production setup.
You should be more than hesitant - don’t do it. They literally market them for quick demos. And not long lived production.
I use for the exact same thing. Running "cloudflared tunnel" sets up a temp solution. No log in needed, pretty convenient.
What's the difference between this and their previous Cloudflare Tunnels solution?
As far as I can tell, the difference is that they made a new website? The cloudflared instant tunnels have been around for years, including json output as far as I know.
This gives a random trycloudflare.com subdomain each run, the other requires a domain and tunnel key on your account.
It looks like tunnels can do some non https stuff these days? But it's a bit unclear
Cool but the obvious flaw with this is that CF leaks DNS-records. So bots will find these urls instantly. Not sure why they have not fixed that or if it is even possible to fix.
Love this, very cool.

I used to use a service called ngrok for this, but it's nice that Cloudflare is offering one now.