Architecture · 6 Jul 2026 · 3 min
Why we run services behind Cloudflare tunnels
Traditional hosting assumes your server listens on the public internet. That means a firewall rule is the only thing between an exposed port and the rest of the world, and firewall rules are easy to get wrong.
Cloudflare tunnels invert that. The software on the node opens an outbound connection to Cloudflare and traffic is delivered back down that connection. The node never needs to accept inbound traffic for HTTP services, so there is no port to scan and no origin address to expose.
Two things follow from this. First, the attack surface for web-facing services shrinks to the tunnel itself rather than every service on the box. Second, migrating a service to a different node is a configuration change rather than a DNS cutover plus a firewall change.
It is not a substitute for securing what you run — you still need patches, key-only SSH and sensible per-service configuration. It removes one whole category of exposure, which is a good place to start.
Related
Tutorial
Tuning a Minecraft server that actually holds tick rate
Minecraft is effectively single-threaded, so flags and world settings matter far more than core count. Here is the order we tune things in.
Engineering
Why NVMe changes the shape of your workload
Storage latency decides whether an application is designed around waiting. Moving from spinning disks to NVMe removed a whole class of architecture problems.