01 / DECISION
この primitive を選ぶ時
origin を public reachable IP や inbound firewall rule なしで Cloudflare に接続したい時に使います。
02 / ARCHITECTURE
最小で説明可能な path を作る
named connector、scoped credential、explicit hostname mapping、redundant connector、private app の Access policy を設計します。
- 01contract を定義
origin を public reachable IP や inbound firewall rule なしで Cloudflare に接続したい時に使います。
- 02primitive を一つ追加
named connector、scoped credential、explicit hostname mapping、redundant connector、private app の Access policy を設計します。
- 03failure evidence を残す
direct origin access を外し、一つの connector を停止し、failover、denied identity、published hostname を確認します。
03 / REPRODUCE
confidence の前に evidence
direct origin access を外し、一つの connector を停止し、failover、denied identity、published hostname を確認します。
cloudflared tunnel list 04 / BOUNDARY
Production boundary
Tunnel connectivity は authorization ではありません。広い wildcard route や再利用可能 credential は blast radius を広げます。
05 / FIRST-PARTY SOURCES
一次資料を authoritative に保つ
product behavior、limit、pricing、availability は変わります。実行前に source を再確認してください。