
Cloudflare Tunnel — Outbound-only tunnel that exposes local services through Cloudflare without open ports
What it is
Cloudflare Tunnel (cloudflared) connects a server out to Cloudflare's edge, so services on a home or private network can be published under your domain without port forwarding or a public IP. Typical use is exposing self-hosted apps with Cloudflare access rules in front of them. All traffic routes through Cloudflare, so availability and latency depend on that dependency, and the daemon needs to stay running and updated.
Editor's review
Long-form introduction by the BetterPicker editors · checked against the official site · Oct 9, 2026
Cloudflare Tunnel is the right tool when you want a self-hosted service reachable from the internet without exposing a single open port. The cloudflared daemon makes only outbound connections, so home networks and office firewalls stay closed to inbound traffic while your app gets a proper hostname and Cloudflare's protections in front of it. The software is free, but it ties your ingress to Cloudflare's platform, and that dependency deserves a deliberate yes before you lean on it for anything important.
What it does well
No open ports, by design. The daemon dials out to Cloudflare and keeps that connection alive; inbound requests ride back down it. Your router stays closed, ISP port blocks stop mattering, and the attack surface shrinks to one authenticated outbound path that is easy to audit.
Access control and web protections come along. Because traffic enters through Cloudflare, you can put Zero Trust policies in front of SSH or RDP, require identity checks, and get DDoS shielding for published apps. A beginner tutorial with approx 1.1 million views exists largely because this combination is hard to assemble any other way.
The moving part is one binary. cloudflared runs on Linux, Windows, and macOS as well as in containers, configured from the dashboard or a local YAML file. Releases move briskly, with 2026.10.0 shipped in October 2026 under an Apache 2.0 license, and the component itself costs nothing.
Who it's for
Self-hosters publishing a few services, small teams without a static IP, and anyone who wants remote SSH or RDP behind identity checks. It also suits developers who want a preview URL for a service running on a laptop behind carrier-grade NAT. It fits homes and small offices best. Organizations with strict data-residency rules, or people who want a device-level VPN for everything, should look at other shapes entirely.
Where it falls short
Cloudflare becomes a mandatory middleman. Your DNS has to live on Cloudflare, every request terminates at their edge, and an outage or a policy decision on their side takes your services with it. A popular critical video with approx 460,000 views argues against certain uses, and the dependency question it raises is fair. Read it before you commit, not after.
It publishes services; it is not a VPN. Ingress is defined per hostname and per service, so using it as a general pipe for desktop traffic or constant heavy transfers pushes the product past its design. Treat such uses as off-label and expect friction.
Debugging happens in someone else's network. When a request fails between the visitor and your origin, the visibility you get is the dashboard plus local daemon logs. Latency also gains a hop through the nearest edge, which is usually acceptable and occasionally is not.
Specs at a glance
Facts from the official site · not editorial opinion
| Component | cloudflared daemon (single binary) |
|---|---|
| Latest release | 2026.10.0 (October 2026) |
| License | Apache 2.0 |
| Cost | Free with a Cloudflare account; domain DNS must be on Cloudflare |
| Traffic direction | Outbound-only connections; no open inbound ports |
| Works with | HTTP/HTTPS, SSH, RDP, and arbitrary TCP through WARP routing |
| Managed from | Cloudflare Zero Trust dashboard or a local config file |
Frequently asked questions
▸What is Cloudflare Tunnel?
Cloudflare Tunnel publishes services running on your own hardware to the internet through an outbound connection from the cloudflared daemon to Cloudflare's edge. Visitors reach a normal hostname on your domain while your router keeps every inbound port closed. It is part of Cloudflare's Zero Trust platform.
▸Is it free?
Yes, tunnels are free; you need a Cloudflare account and your domain's DNS on Cloudflare. Access policies and other Zero Trust features are split across free and paid plans, so check which controls you need before committing a production service.
▸Do I still need port forwarding?
No. The daemon makes outbound connections only, so port forwarding rules are removed rather than replaced. This is the main reason people switch from manual router configuration, and it also sidesteps blocked ports and changing home IP addresses.
▸Cloudflare Tunnel or a traditional VPN?
They solve different problems. The tunnel publishes specific services to specific audiences, while a VPN connects a device to a whole network. For exposing a handful of web apps and remote access safely, the tunnel is usually less work; for full-network access, a VPN remains the right shape.
Reviews on YouTube
4 review videos aggregated · praise and criticism included alike · click through to the original video
Channels that covered it
Channels are aggregated as sources only — we don’t rate creators
Related tools
Where to go next
External links open in a new tab; external content is independent of this site.
Link down? Every object page is re-checked monthly.




