Cloudflare Tunnel
In cloudflare mode, a Cloudflare Tunnel carries browsers and the CLI to evertap. The machine
running evertap connects out to Cloudflare and takes no incoming connections, so its firewall can
drop them all. You need a domain whose DNS is on Cloudflare.
Setup can create the tunnel for you from a Cloudflare API token you paste once (below), or use a tunnel you run yourself (Run the tunnel yourself).
Let setup create the tunnel
On the machine running evertap, run evertap setup, choose "Cloudflare Tunnel", then "evertap".
-
Setup prints a link, and a QR code, to Cloudflare's page for a new API token with these permissions filled in:
- Account · Cloudflare Tunnel · Edit
- Zone · DNS · Edit
- Zone · Zone · Read
- Zone · Cache Rules · Edit
If one is missing on the page, add it by hand. The page fills in All zones under Zone Resources: change that to the domain for evertap, so the token reaches nothing else.
-
Create the token and paste it. What you paste does not show. If the token reaches more than one domain, choose one.
-
Setup creates, in Cloudflare:
- a tunnel named
evertap, which sendsevertap.<domain>to the UI ands3.<domain>to evertap's public S3 entry,http://127.0.0.1:9900(EVERTAP_PUBLIC_S3_PORT) - a DNS record for each name, proxied, with the comment
evertap - a Cache Rule that keeps Cloudflare from caching
s3.<domain>
- a tunnel named
-
evertap starts cloudflared in Docker (
evertap-cloudflared), and setup waits for it to connect, checks thathttps://evertap.<domain>reaches this evertap, and ends with a one-time sign-in link.
The names sit one level under your domain, as Cloudflare's free certificate covers no deeper.
s3.<domain> serves buckets reached from anywhere (below), and
refuses every request until a bucket is.
evertap does not keep the API token, and you can delete it in Cloudflare once setup is done. What evertap keeps, in its data directory, is the tunnel's id, the token cloudflared runs it with, the domain, and the ids of the DNS records and the Cache Rule.
Without a terminal, give the token in CLOUDFLARE_API_TOKEN:
CLOUDFLARE_API_TOKEN=<token> evertap setup --mode cloudflare --zone example.com--zone is needed only when the token reaches more than one domain.
Setup stops before it creates anything when evertap.<domain> or s3.<domain> already has a DNS
record of yours, even one that leads to a tunnel of your own, or when a tunnel named evertap
already runs in the account, likely for another evertap. It reuses only what an earlier setup
created: a stopped tunnel named evertap, and DNS records with the comment evertap, which it
points at the tunnel again.
What it needs
- Docker on Linux. cloudflared runs with the host's network to reach evertap on
127.0.0.1. When evertap runs in Docker (Run evertap in Docker), run setup inside its container withdocker exec -it evertap evertap setup, and leaveEVERTAP_PUBLIC_URLunset. - Outgoing connections to Cloudflare on TCP 7844. evertap runs cloudflared over HTTP/2, not QUIC, which loses the body of an upload that does not say its length.
127.0.0.1:20241free for cloudflared's metrics, which the Doctor reads. If you ran cloudflared yourself before (below), stop it first.
Running setup again
With a token, setup reuses the tunnel, the DNS records, and the Cache Rule, and makes none of them twice. Choosing another domain moves the names there and removes the old ones. Press Enter instead of pasting a token to keep the tunnel as it is.
The tunnel's state
evertap doctor and the Doctor page show a Tunnel line: connected, with how many links cloudflared
has to Cloudflare, not connected yet, or not running. On the machine running evertap, evertap doctor also says why cloudflared could not start.
Settings → Access shows the same state. Settings cannot change or remove a tunnel setup created, as
that takes a Cloudflare token; run evertap setup on the machine running evertap instead.
Remove the tunnel
Run evertap setup and choose another mode. Once the new mode is in force, evertap stops
cloudflared, and setup asks for a token (from the same link, or CLOUDFLARE_API_TOKEN) to remove the
DNS records, the Cache Rule, and the tunnel from Cloudflare. Press Enter to skip, and setup lists what
to remove in the Cloudflare dashboard.
evertap uninstall removes cloudflared but leaves what setup created in Cloudflare. It lists those
before it asks you to confirm: to remove them with a token, stop there and choose another mode in
setup first.
Run the tunnel yourself
-
In the Cloudflare dashboard, open Networking → Tunnels, choose Create a tunnel, and name it, such as
my-evertap. Do not name itevertap: setup uses that name for the tunnel it creates, and would take over a stopped tunnel of yours with that name, replacing its routes. -
Run cloudflared on the machine running evertap with the command the dashboard shows, such as
sudo cloudflared service install <token>, or with Docker (below). -
In the tunnel's Routes, add a route for a published application: a name such as
evertap.example.com, with the service URLhttp://127.0.0.1:8080.- Write
127.0.0.1, notlocalhost, which can lead to::1, where evertap does not listen. - Keep the name one level under your domain, such as
evertap.example.com. Cloudflare's free certificate covers one level, notevertap.dev.example.com. - If you changed
EVERTAP_PORT, use that port.
- Write
-
On the machine running evertap, run
evertap setup, choose "Cloudflare Tunnel", then "You", and give the address,https://evertap.example.com. Without a terminal:evertap setup --mode cloudflare --url https://evertap.example.com
Setup ends with a one-time sign-in link to that address. If the link does not open evertap, check the tunnel's route.
To have setup create a tunnel instead later, first delete your tunnel's DNS record for
evertap.<domain>, and stop your cloudflared: setup leaves records of yours alone and stops.
cloudflared in Docker
cloudflared in a container reaches evertap on 127.0.0.1 only with the host's network:
docker run -d --name cloudflared --restart unless-stopped --network host \
cloudflare/cloudflared:latest tunnel --no-autoupdate --metrics 127.0.0.1:20241 \
run --token <token>Keep --metrics 127.0.0.1:20241, before run. In a container, cloudflared otherwise serves its
metrics on 0.0.0.0, which with the host's network means every address of the machine, and the
same server shows the tunnel's configuration.
Buckets reached from anywhere
A bucket's signed links work on any device once it is reachable from anywhere
(Signed links that work anywhere). With the tunnel
setup creates, buckets are served at s3.<domain>: turn it on for a bucket, and that is all.
With a tunnel you run yourself, give buckets a hostname of their own on it:
-
In the tunnel's Routes, add another published application, such as
s3.example.com, with the service URLhttp://127.0.0.1:9900. If you setEVERTAP_PUBLIC_S3_PORT, use that port. -
Under Caching → Cache Rules, add a rule that bypasses the cache for that hostname, as setup does for its own tunnel.
-
Give evertap its address, in Settings → Change access, or with setup:
evertap setup --mode cloudflare --url https://evertap.example.com --s3-url https://s3.example.com
Unlike database and bucket connections from evertap connect, these requests travel through
Cloudflare as plain HTTP requests, so more of its rules apply to them:
- Every answer carries
Cloudflare-CDN-Cache-Control: no-store, so Cloudflare keeps no copy, even of an object stored withCache-Control: public. The header does not reach browsers. - An upload through this address is limited to 100 MB on the Free and Pro plans. Larger objects go
up in parts, or through
evertap connect. - Cloudflare changes
Accept-Encodingon its way to evertap. A tool that signs that header, such as rclone or Terraform, fails here; links signed for a browser do not sign it. - A HEAD request for a file Cloudflare would cache, such as a
.jpg, may reach evertap as a GET and fail its signature. The Cache Rule is expected to stop that, but it has not been tested.
Laptops
Laptops pair and connect as with any other mode (Connect from your laptop):
evertap login https://evertap.example.com
evertap connectDatabase and bucket connections travel through the tunnel inside WebSockets, even from a laptop on the same network as evertap.
Cloudflare Access
Access is optional. evertap requires its own sign-in either way. If you put Access in front, cover the UI only: the CLI sends evertap's token and cannot do Access's browser sign-in. In Cloudflare Zero Trust, under Access controls → Applications, add two self-hosted applications:
evertap.example.com, with an Allow policy for the people who use evertap.evertap.example.com/api/client/*, with a Bypass policy that includes Everyone.
The more specific path wins, so Access lets through everything the CLI uses, which is all under
/api/client/, evertap connect included.
Limits
- Cloudflare closes a WebSocket that stays quiet for a while, about 100 seconds by most reports.
evertap and
evertap connectping every 25 seconds, so open connections stay up. - Connections still drop when Cloudflare or cloudflared restarts. Use a connection pool that checks connections (Connection pools).
- Cloudflare waits 125 seconds for an answer. Creating the first database of a version waits up to a minute for the download, then asks you to try again while it goes on.
- Cloudflare limits a request body to 100 MB on the Free and Pro plans. The UI uploads files in parts of up to 16 MiB, so files of any size fit.
- Cloudflare's
terms
let it limit a Free, Pro, or Business plan that serves video or a disproportionate share of
pictures, audio, or other large files without its paid services, through a tunnel too. Database
and bucket traffic passes through Cloudflare inside WebSockets. If you move large amounts of data,
use
networkmode with your own proxy instead. - Bot Fight Mode has not been tested with evertap. It challenges traffic that looks automated, and
on the Free plan no rule can skip it for one path. If
evertap loginorevertap connectfails only through the tunnel, try turning it off.
The evertap name and logo are not licensed with the code (section 6 of the license). You may use them to refer to evertap, but not to name or brand your own product or service, or in a way that suggests evertap made or endorses it, without permission.
evertap is an independent project. It is not affiliated with, endorsed, sponsored, supported, or certified by the owners of the software it runs, and it uses their names only to say which software that is.
- Postgres, PostgreSQL and the Slonik Logo are trademarks or registered trademarks of the PostgreSQL Community Association of Canada, and used with their permission.
- MySQL is a registered trademark of Oracle and/or its affiliates.
- Redis is a registered trademark of Redis Ltd. Any rights therein are reserved to Redis Ltd.
- RustFS is a trademark of RustFS, Inc.
- Other names, including Garage, may be trademarks of their respective owners.