Skip to content

Architecture · 6 Jul 2026 · 3 min

Why we run services behind Cloudflare tunnels

Traditional hosting assumes your server listens on the public internet. That means a firewall rule is the only thing between an exposed port and the rest of the world, and firewall rules are easy to get wrong.

Cloudflare tunnels invert that. The software on the node opens an outbound connection to Cloudflare and traffic is delivered back down that connection. The node never needs to accept inbound traffic for HTTP services, so there is no port to scan and no origin address to expose.

Two things follow from this. First, the attack surface for web-facing services shrinks to the tunnel itself rather than every service on the box. Second, migrating a service to a different node is a configuration change rather than a DNS cutover plus a firewall change.

It is not a substitute for securing what you run — you still need patches, key-only SSH and sensible per-service configuration. It removes one whole category of exposure, which is a good place to start.