Cloudflare Worldedge community field guide

RETROSPECTIVE EDITION / 2025-09

Cloudflare Tunnel: connect outward, expose less

An outbound connector can publish an origin without opening an inbound path, but identity and routing still need policy.

ISSUE
21 / 32
FIRST PUBLISHED
SOURCE CHECKED
Archive integrity

The edition month is a curriculum position. This article was first published on 2026-08-10 and is not presented as a historical release or past activity.

01 / DECISION

When this primitive earns a place

Use Tunnel when an origin should connect to Cloudflare without a publicly reachable IP or inbound firewall rule.

02 / ARCHITECTURE

Build the smallest defensible path

Create a named connector, scope credentials, map explicit hostnames to services, run redundant connectors, and pair private applications with Access policy.

  1. 01Name the contract

    Use Tunnel when an origin should connect to Cloudflare without a publicly reachable IP or inbound firewall rule.

  2. 02Add one primitive

    Create a named connector, scope credentials, map explicit hostnames to services, run redundant connectors, and pair private applications with Access policy.

  3. 03Capture failure evidence

    Remove direct origin access, stop one connector, test failover and denied identities, and verify every published hostname is intentional.

03 / REPRODUCE

Evidence before confidence

Remove direct origin access, stop one connector, test failover and denied identities, and verify every published hostname is intentional.

cloudflared tunnel list

04 / BOUNDARY

The production boundary

Tunnel connectivity is not authorization. Broad wildcard routes or reusable connector credentials can expand blast radius.

05 / FIRST-PARTY SOURCES

Keep first-party sources authoritative

Product behavior, limits, pricing, and availability can change. Re-check these sources before acting.

01 / SOURCECloudflare Tunnelhttps://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/