Cloudflare Worldedge community field guide

回顧版月刊 / 2025-09

Cloudflare Tunnel:向外連線,減少暴露

Outbound connector 可在不開 inbound path 下發布 origin,但 identity 與 routing 仍需要 policy。

期號
21 / 32
首次發布
來源查核
檔案誠信

月份代表課程編排位置;本文首次發布於 2026-08-10,不冒充歷史發布紀錄或過往活動。

01 / DECISION

何時值得加入這個 primitive

當 origin 應連向 Cloudflare,且不該有 public reachable IP 或 inbound firewall rule 時使用 Tunnel。

02 / ARCHITECTURE

建立最小且站得住腳的路徑

建立 named connector、限制 credentials、把明確 hostname 映射到 services、執行 redundant connectors,並為 private applications 搭配 Access policy。

  1. 01先命名 contract

    當 origin 應連向 Cloudflare,且不該有 public reachable IP 或 inbound firewall rule 時使用 Tunnel。

  2. 02只加入一個 primitive

    建立 named connector、限制 credentials、把明確 hostname 映射到 services、執行 redundant connectors,並為 private applications 搭配 Access policy。

  3. 03保留 failure evidence

    移除 direct origin access、停止一個 connector、測試 failover 與 denied identities,並確認每個 published hostname 都是有意設定。

03 / REPRODUCE

有證據,再有信心

移除 direct origin access、停止一個 connector、測試 failover 與 denied identities,並確認每個 published hostname 都是有意設定。

cloudflared tunnel list

04 / BOUNDARY

Production boundary

Tunnel connectivity 不是 authorization;過寬 wildcard route 或可重用 connector credentials 會擴大 blast radius。

05 / FIRST-PARTY SOURCES

讓第一方來源保持權威

產品行為、限制、價格與供應狀態會改變;採取行動前請重新核對這些來源。

01 / SOURCECloudflare Tunnelhttps://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/