About this project

# Cloudflare Tunnel client (cloudflared) `cloudflared` is the official command-line client for Cloudflare Tunnel. It runs as a daemon between the Cloudflare network and your origin (e.g., a web server), allowing Cloudflare to route client requests to your origin without requiring you to open inbound ports on your firewall. Your origin can remain as closed as possible. ## Key Features - **Secure tunneling**: Proxies HTTP/websocket traffic from Cloudflare's edge to your origin over an outbound-only connection. - **Layer 4 access**: Supports TCP traffic (e.g., SSH, RDP) to Tunnel-protected origins via `cloudflared access` commands, or through the WARP client for private origins. - **Flexible routing**: Route traffic to a Tunnel via public DNS records, Cloudflare Load Balancers, or private network routes for WARP clients. - **TryCloudflare**: Test Tunnels without adding a website to Cloudflare using a temporary quick tunnel. ## Installation Downloads are available as standalone binaries, Docker images, and Debian/RPM/Homebrew packages. See the [releases page](https://github.com/cloudflare/cloudflared/releases) and [official docs](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/downloads/) for platform-specific instructions (macOS, Linux, Windows, Docker). To build from source, install Go (>= 1.26) and run `make cloudflared`. ## Getting Started 1. Add a website to your Cloudflare account and change its nameservers to Cloudflare. 2. Install `cloudflared`. 3. Authenticate with your Cloudflare account. 4. Create a Tunnel and route traffic to it (DNS, load balancer, or private network). Full user documentation is available at [Cloudflare Tunnel docs](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/). ## Development - **Requirements**: GNU Make, capnp, Go >= 1.26. Optional: capnpc-go, goimports, golangci-lint, gomocks. - **Build**: `make cloudflared` - **Test**: `make test` - **Lint/format**: `make fmt` and `make lint` - **Mocks**: `make mocks` after interface changes. - **Git hooks**: `make install-hooks` to run fmt-check, lint, and tests before each push. ## Support and Versioning Cloudflare supports versions within one year of the most recent release. Breaking changes (removal of CLI flags, env vars, config keys, or commands) are announced in the [Cloudflare Tunnel changelog](https://developers.cloudflare.com/changelog/product/tunnel/).