Skip to content

Latest commit

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Erisa's Cloudflared Docker Image

This repository contains a simple Dockerfile to build cloudflared, the client for Cloudflare Tunnel, from source.

Note

This Docker image is not an official Cloudflare product.

The aim is to support multiple architectures.
The public image currently supports:

Docker targetAlso known asNotes
linux/amd64x86_64Majority of modern PCs and servers.
linux/386x8632-bit Intel/AMD CPUs. Typically really old computer hardware. These images are untested.
linux/arm64aarch6464-bit ARM hardware. For example Apple Silicon or Raspberry Pi 2/3/4 running a 64-bit OS.
linux/arm/v7armhf32-bit ARM hardware. For example most Raspberry Pi models running Raspberry Pi OS.
linux/arm/v6armelOlder 32-bit ARM hardware. Mostly Raspberry Pi 1/0/0W but there may be others.
linux/s390xIBM ZLinux on IBM Z for IBM mainframes, most notably IBM Cloud.
linux/ppc64leppc64elTested on IBM Cloud Power Systems Virtual Server
linux/riscv64riscv64CPUs from the future. Tested on Scaleway Labs RV1.

The public image corresponding to this Dockerfile is erisamoe/cloudflared and should work in mostly the same way as the official image.

Note

If you have any problems or questions with this image, either open a GitHub Issue or join the Cloudflare Developers Discord Server and ping @Erisa in #general-help, #general-discussions or #off-topic with your question.

Cloudflare Tunnel

Dashboard setup (Recommended)

A docker-compose example with a Zero Trust dashboard setup would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stoppedcommand: tunnel runenvironment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}depends_on:
- mycontainer

Where an .env file in the same directory contains TUNNEL_TOKEN= set to the token given by the Zero Trust dashboard. For more information see the Cloudflare Blog

Note A previous version of this README recommended using --token ${CLOUDFLARED_TOKEN}, which is a less secure way of handing off the token. Setting the TUNNEL_TOKEN variable seems to be a better way of approaching this.

Config file setup (Named tunnel)

An example for a setup with a local config would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stopped # or 'always' to survive container stopsvolumes:
- ./cloudflared:/etc/cloudflaredcommand: tunnel run mytunneldepends_on:
- mycontainer

Where ./cloudflared is a folder containing the .json or .pem credentials and config.yml for a tunnel.

An example config.yml might look like:

tunnel: uuid-for-tunnel#Optional#credentials-file: /etc/cloudflared/uuid-for-tunnel.jsoningress:
- hostname: mywebsite.comservice: http://nginx:80
- service: http_status:404

For more information, refer to the Cloudflare Documentation

To acquire a certificate, you'll need to use the login command.
This will spit out /.cloudflared/cert.pem, rather than /etc/cloudflared.

As such, usage would be something like:

docker run -v $PWD/cloudflared:/.cloudflared erisamoe/cloudflared login

to create a folder called cloudflared in your current dir and deposit a cert.pem into it.

To create a tunnel, you can then do:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared tunnel create mytunnel

Which gives you a UUID for the new tunnel and and a .json credentials file corresponding to it.

And now you can either use the above compose example or for testing simply just:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared --hostname test.example.com --name mytunnel --hello-world

Which will start up a "Hello world" test tunnel on https://test.example.com.

DNS-over-HTTPS

While not the original intent behind the image, you can also use this to host a DNS resolver that speaks to a DNS-over-HTTPS backend.
For example:

docker run -d -p 53:53/udp --name my-dns-forwarder erisamoe/cloudflared proxy-dns --address 0.0.0.0

Would create a container called my-dns-forwarder that responds to DNS requests on your host.
Keep in mind when using this on a public server (e.g. VPS) it will by default listen on all interfaces, making you a public DNS resolver on the internet.
You can sidestep this by changing the -p to instead be -p 127.0.0.01:53:53/udp to listen on localhost instead.

You can also add upstreams with --upstream https://dns.example.com for example. By default, Cloudflare DNS is used.

About

Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures.

Topics

Resources

Stars

203 stars

Watchers

5 watching

Forks

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
GitHub - Erisa/cloudflared-docker: Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures. · GitHub
Skip to content

Latest commit

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Erisa's Cloudflared Docker Image

This repository contains a simple Dockerfile to build cloudflared, the client for Cloudflare Tunnel, from source.

Note

This Docker image is not an official Cloudflare product.

The aim is to support multiple architectures.
The public image currently supports:

Docker targetAlso known asNotes
linux/amd64x86_64Majority of modern PCs and servers.
linux/386x8632-bit Intel/AMD CPUs. Typically really old computer hardware. These images are untested.
linux/arm64aarch6464-bit ARM hardware. For example Apple Silicon or Raspberry Pi 2/3/4 running a 64-bit OS.
linux/arm/v7armhf32-bit ARM hardware. For example most Raspberry Pi models running Raspberry Pi OS.
linux/arm/v6armelOlder 32-bit ARM hardware. Mostly Raspberry Pi 1/0/0W but there may be others.
linux/s390xIBM ZLinux on IBM Z for IBM mainframes, most notably IBM Cloud.
linux/ppc64leppc64elTested on IBM Cloud Power Systems Virtual Server
linux/riscv64riscv64CPUs from the future. Tested on Scaleway Labs RV1.

The public image corresponding to this Dockerfile is erisamoe/cloudflared and should work in mostly the same way as the official image.

Note

If you have any problems or questions with this image, either open a GitHub Issue or join the Cloudflare Developers Discord Server and ping @Erisa in #general-help, #general-discussions or #off-topic with your question.

Cloudflare Tunnel

Dashboard setup (Recommended)

A docker-compose example with a Zero Trust dashboard setup would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stoppedcommand: tunnel runenvironment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}depends_on:
- mycontainer

Where an .env file in the same directory contains TUNNEL_TOKEN= set to the token given by the Zero Trust dashboard. For more information see the Cloudflare Blog

Note A previous version of this README recommended using --token ${CLOUDFLARED_TOKEN}, which is a less secure way of handing off the token. Setting the TUNNEL_TOKEN variable seems to be a better way of approaching this.

Config file setup (Named tunnel)

An example for a setup with a local config would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stopped # or 'always' to survive container stopsvolumes:
- ./cloudflared:/etc/cloudflaredcommand: tunnel run mytunneldepends_on:
- mycontainer

Where ./cloudflared is a folder containing the .json or .pem credentials and config.yml for a tunnel.

An example config.yml might look like:

tunnel: uuid-for-tunnel#Optional#credentials-file: /etc/cloudflared/uuid-for-tunnel.jsoningress:
- hostname: mywebsite.comservice: http://nginx:80
- service: http_status:404

For more information, refer to the Cloudflare Documentation

To acquire a certificate, you'll need to use the login command.
This will spit out /.cloudflared/cert.pem, rather than /etc/cloudflared.

As such, usage would be something like:

docker run -v $PWD/cloudflared:/.cloudflared erisamoe/cloudflared login

to create a folder called cloudflared in your current dir and deposit a cert.pem into it.

To create a tunnel, you can then do:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared tunnel create mytunnel

Which gives you a UUID for the new tunnel and and a .json credentials file corresponding to it.

And now you can either use the above compose example or for testing simply just:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared --hostname test.example.com --name mytunnel --hello-world

Which will start up a "Hello world" test tunnel on https://test.example.com.

DNS-over-HTTPS

While not the original intent behind the image, you can also use this to host a DNS resolver that speaks to a DNS-over-HTTPS backend.
For example:

docker run -d -p 53:53/udp --name my-dns-forwarder erisamoe/cloudflared proxy-dns --address 0.0.0.0

Would create a container called my-dns-forwarder that responds to DNS requests on your host.
Keep in mind when using this on a public server (e.g. VPS) it will by default listen on all interfaces, making you a public DNS resolver on the internet.
You can sidestep this by changing the -p to instead be -p 127.0.0.01:53:53/udp to listen on localhost instead.

You can also add upstreams with --upstream https://dns.example.com for example. By default, Cloudflare DNS is used.

About

Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures.

Topics

Resources

Stars

203 stars

Watchers

5 watching

Forks

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Erisa/cloudflared-docker: Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures. · GitHub
Skip to content

Latest commit

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Erisa's Cloudflared Docker Image

This repository contains a simple Dockerfile to build cloudflared, the client for Cloudflare Tunnel, from source.

Note

This Docker image is not an official Cloudflare product.

The aim is to support multiple architectures.
The public image currently supports:

Docker targetAlso known asNotes
linux/amd64x86_64Majority of modern PCs and servers.
linux/386x8632-bit Intel/AMD CPUs. Typically really old computer hardware. These images are untested.
linux/arm64aarch6464-bit ARM hardware. For example Apple Silicon or Raspberry Pi 2/3/4 running a 64-bit OS.
linux/arm/v7armhf32-bit ARM hardware. For example most Raspberry Pi models running Raspberry Pi OS.
linux/arm/v6armelOlder 32-bit ARM hardware. Mostly Raspberry Pi 1/0/0W but there may be others.
linux/s390xIBM ZLinux on IBM Z for IBM mainframes, most notably IBM Cloud.
linux/ppc64leppc64elTested on IBM Cloud Power Systems Virtual Server
linux/riscv64riscv64CPUs from the future. Tested on Scaleway Labs RV1.

The public image corresponding to this Dockerfile is erisamoe/cloudflared and should work in mostly the same way as the official image.

Note

If you have any problems or questions with this image, either open a GitHub Issue or join the Cloudflare Developers Discord Server and ping @Erisa in #general-help, #general-discussions or #off-topic with your question.

Cloudflare Tunnel

Dashboard setup (Recommended)

A docker-compose example with a Zero Trust dashboard setup would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stoppedcommand: tunnel runenvironment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}depends_on:
- mycontainer

Where an .env file in the same directory contains TUNNEL_TOKEN= set to the token given by the Zero Trust dashboard. For more information see the Cloudflare Blog

Note A previous version of this README recommended using --token ${CLOUDFLARED_TOKEN}, which is a less secure way of handing off the token. Setting the TUNNEL_TOKEN variable seems to be a better way of approaching this.

Config file setup (Named tunnel)

An example for a setup with a local config would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stopped # or 'always' to survive container stopsvolumes:
- ./cloudflared:/etc/cloudflaredcommand: tunnel run mytunneldepends_on:
- mycontainer

Where ./cloudflared is a folder containing the .json or .pem credentials and config.yml for a tunnel.

An example config.yml might look like:

tunnel: uuid-for-tunnel#Optional#credentials-file: /etc/cloudflared/uuid-for-tunnel.jsoningress:
- hostname: mywebsite.comservice: http://nginx:80
- service: http_status:404

For more information, refer to the Cloudflare Documentation

To acquire a certificate, you'll need to use the login command.
This will spit out /.cloudflared/cert.pem, rather than /etc/cloudflared.

As such, usage would be something like:

docker run -v $PWD/cloudflared:/.cloudflared erisamoe/cloudflared login

to create a folder called cloudflared in your current dir and deposit a cert.pem into it.

To create a tunnel, you can then do:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared tunnel create mytunnel

Which gives you a UUID for the new tunnel and and a .json credentials file corresponding to it.

And now you can either use the above compose example or for testing simply just:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared --hostname test.example.com --name mytunnel --hello-world

Which will start up a "Hello world" test tunnel on https://test.example.com.

DNS-over-HTTPS

While not the original intent behind the image, you can also use this to host a DNS resolver that speaks to a DNS-over-HTTPS backend.
For example:

docker run -d -p 53:53/udp --name my-dns-forwarder erisamoe/cloudflared proxy-dns --address 0.0.0.0

Would create a container called my-dns-forwarder that responds to DNS requests on your host.
Keep in mind when using this on a public server (e.g. VPS) it will by default listen on all interfaces, making you a public DNS resolver on the internet.
You can sidestep this by changing the -p to instead be -p 127.0.0.01:53:53/udp to listen on localhost instead.

You can also add upstreams with --upstream https://dns.example.com for example. By default, Cloudflare DNS is used.

About

Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures.

Topics

Resources

Stars

203 stars

Watchers

5 watching

Forks

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Erisa/cloudflared-docker: Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures. · GitHub
Skip to content

Latest commit

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Erisa's Cloudflared Docker Image

This repository contains a simple Dockerfile to build cloudflared, the client for Cloudflare Tunnel, from source.

Note

This Docker image is not an official Cloudflare product.

The aim is to support multiple architectures.
The public image currently supports:

Docker targetAlso known asNotes
linux/amd64x86_64Majority of modern PCs and servers.
linux/386x8632-bit Intel/AMD CPUs. Typically really old computer hardware. These images are untested.
linux/arm64aarch6464-bit ARM hardware. For example Apple Silicon or Raspberry Pi 2/3/4 running a 64-bit OS.
linux/arm/v7armhf32-bit ARM hardware. For example most Raspberry Pi models running Raspberry Pi OS.
linux/arm/v6armelOlder 32-bit ARM hardware. Mostly Raspberry Pi 1/0/0W but there may be others.
linux/s390xIBM ZLinux on IBM Z for IBM mainframes, most notably IBM Cloud.
linux/ppc64leppc64elTested on IBM Cloud Power Systems Virtual Server
linux/riscv64riscv64CPUs from the future. Tested on Scaleway Labs RV1.

The public image corresponding to this Dockerfile is erisamoe/cloudflared and should work in mostly the same way as the official image.

Note

If you have any problems or questions with this image, either open a GitHub Issue or join the Cloudflare Developers Discord Server and ping @Erisa in #general-help, #general-discussions or #off-topic with your question.

Cloudflare Tunnel

Dashboard setup (Recommended)

A docker-compose example with a Zero Trust dashboard setup would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stoppedcommand: tunnel runenvironment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}depends_on:
- mycontainer

Where an .env file in the same directory contains TUNNEL_TOKEN= set to the token given by the Zero Trust dashboard. For more information see the Cloudflare Blog

Note A previous version of this README recommended using --token ${CLOUDFLARED_TOKEN}, which is a less secure way of handing off the token. Setting the TUNNEL_TOKEN variable seems to be a better way of approaching this.

Config file setup (Named tunnel)

An example for a setup with a local config would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stopped # or 'always' to survive container stopsvolumes:
- ./cloudflared:/etc/cloudflaredcommand: tunnel run mytunneldepends_on:
- mycontainer

Where ./cloudflared is a folder containing the .json or .pem credentials and config.yml for a tunnel.

An example config.yml might look like:

tunnel: uuid-for-tunnel#Optional#credentials-file: /etc/cloudflared/uuid-for-tunnel.jsoningress:
- hostname: mywebsite.comservice: http://nginx:80
- service: http_status:404

For more information, refer to the Cloudflare Documentation

To acquire a certificate, you'll need to use the login command.
This will spit out /.cloudflared/cert.pem, rather than /etc/cloudflared.

As such, usage would be something like:

docker run -v $PWD/cloudflared:/.cloudflared erisamoe/cloudflared login

to create a folder called cloudflared in your current dir and deposit a cert.pem into it.

To create a tunnel, you can then do:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared tunnel create mytunnel

Which gives you a UUID for the new tunnel and and a .json credentials file corresponding to it.

And now you can either use the above compose example or for testing simply just:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared --hostname test.example.com --name mytunnel --hello-world

Which will start up a "Hello world" test tunnel on https://test.example.com.

DNS-over-HTTPS

While not the original intent behind the image, you can also use this to host a DNS resolver that speaks to a DNS-over-HTTPS backend.
For example:

docker run -d -p 53:53/udp --name my-dns-forwarder erisamoe/cloudflared proxy-dns --address 0.0.0.0

Would create a container called my-dns-forwarder that responds to DNS requests on your host.
Keep in mind when using this on a public server (e.g. VPS) it will by default listen on all interfaces, making you a public DNS resolver on the internet.
You can sidestep this by changing the -p to instead be -p 127.0.0.01:53:53/udp to listen on localhost instead.

You can also add upstreams with --upstream https://dns.example.com for example. By default, Cloudflare DNS is used.

About

Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures.

Topics

Resources

Stars

203 stars

Watchers

5 watching

Forks

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' GitHub - Erisa/cloudflared-docker: Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures. · GitHub
Skip to content

Latest commit

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Erisa's Cloudflared Docker Image

This repository contains a simple Dockerfile to build cloudflared, the client for Cloudflare Tunnel, from source.

Note

This Docker image is not an official Cloudflare product.

The aim is to support multiple architectures.
The public image currently supports:

Docker targetAlso known asNotes
linux/amd64x86_64Majority of modern PCs and servers.
linux/386x8632-bit Intel/AMD CPUs. Typically really old computer hardware. These images are untested.
linux/arm64aarch6464-bit ARM hardware. For example Apple Silicon or Raspberry Pi 2/3/4 running a 64-bit OS.
linux/arm/v7armhf32-bit ARM hardware. For example most Raspberry Pi models running Raspberry Pi OS.
linux/arm/v6armelOlder 32-bit ARM hardware. Mostly Raspberry Pi 1/0/0W but there may be others.
linux/s390xIBM ZLinux on IBM Z for IBM mainframes, most notably IBM Cloud.
linux/ppc64leppc64elTested on IBM Cloud Power Systems Virtual Server
linux/riscv64riscv64CPUs from the future. Tested on Scaleway Labs RV1.

The public image corresponding to this Dockerfile is erisamoe/cloudflared and should work in mostly the same way as the official image.

Note

If you have any problems or questions with this image, either open a GitHub Issue or join the Cloudflare Developers Discord Server and ping @Erisa in #general-help, #general-discussions or #off-topic with your question.

Cloudflare Tunnel

Dashboard setup (Recommended)

A docker-compose example with a Zero Trust dashboard setup would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stoppedcommand: tunnel runenvironment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}depends_on:
- mycontainer

Where an .env file in the same directory contains TUNNEL_TOKEN= set to the token given by the Zero Trust dashboard. For more information see the Cloudflare Blog

Note A previous version of this README recommended using --token ${CLOUDFLARED_TOKEN}, which is a less secure way of handing off the token. Setting the TUNNEL_TOKEN variable seems to be a better way of approaching this.

Config file setup (Named tunnel)

An example for a setup with a local config would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stopped # or 'always' to survive container stopsvolumes:
- ./cloudflared:/etc/cloudflaredcommand: tunnel run mytunneldepends_on:
- mycontainer

Where ./cloudflared is a folder containing the .json or .pem credentials and config.yml for a tunnel.

An example config.yml might look like:

tunnel: uuid-for-tunnel#Optional#credentials-file: /etc/cloudflared/uuid-for-tunnel.jsoningress:
- hostname: mywebsite.comservice: http://nginx:80
- service: http_status:404

For more information, refer to the Cloudflare Documentation

To acquire a certificate, you'll need to use the login command.
This will spit out /.cloudflared/cert.pem, rather than /etc/cloudflared.

As such, usage would be something like:

docker run -v $PWD/cloudflared:/.cloudflared erisamoe/cloudflared login

to create a folder called cloudflared in your current dir and deposit a cert.pem into it.

To create a tunnel, you can then do:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared tunnel create mytunnel

Which gives you a UUID for the new tunnel and and a .json credentials file corresponding to it.

And now you can either use the above compose example or for testing simply just:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared --hostname test.example.com --name mytunnel --hello-world

Which will start up a "Hello world" test tunnel on https://test.example.com.

DNS-over-HTTPS

While not the original intent behind the image, you can also use this to host a DNS resolver that speaks to a DNS-over-HTTPS backend.
For example:

docker run -d -p 53:53/udp --name my-dns-forwarder erisamoe/cloudflared proxy-dns --address 0.0.0.0

Would create a container called my-dns-forwarder that responds to DNS requests on your host.
Keep in mind when using this on a public server (e.g. VPS) it will by default listen on all interfaces, making you a public DNS resolver on the internet.
You can sidestep this by changing the -p to instead be -p 127.0.0.01:53:53/udp to listen on localhost instead.

You can also add upstreams with --upstream https://dns.example.com for example. By default, Cloudflare DNS is used.

About

Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures.

Topics

Resources

Stars

203 stars

Watchers

5 watching

Forks

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Erisa/cloudflared-docker: Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures. · GitHub
Skip to content

Latest commit

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Erisa's Cloudflared Docker Image

This repository contains a simple Dockerfile to build cloudflared, the client for Cloudflare Tunnel, from source.

Note

This Docker image is not an official Cloudflare product.

The aim is to support multiple architectures.
The public image currently supports:

Docker targetAlso known asNotes
linux/amd64x86_64Majority of modern PCs and servers.
linux/386x8632-bit Intel/AMD CPUs. Typically really old computer hardware. These images are untested.
linux/arm64aarch6464-bit ARM hardware. For example Apple Silicon or Raspberry Pi 2/3/4 running a 64-bit OS.
linux/arm/v7armhf32-bit ARM hardware. For example most Raspberry Pi models running Raspberry Pi OS.
linux/arm/v6armelOlder 32-bit ARM hardware. Mostly Raspberry Pi 1/0/0W but there may be others.
linux/s390xIBM ZLinux on IBM Z for IBM mainframes, most notably IBM Cloud.
linux/ppc64leppc64elTested on IBM Cloud Power Systems Virtual Server
linux/riscv64riscv64CPUs from the future. Tested on Scaleway Labs RV1.

The public image corresponding to this Dockerfile is erisamoe/cloudflared and should work in mostly the same way as the official image.

Note

If you have any problems or questions with this image, either open a GitHub Issue or join the Cloudflare Developers Discord Server and ping @Erisa in #general-help, #general-discussions or #off-topic with your question.

Cloudflare Tunnel

Dashboard setup (Recommended)

A docker-compose example with a Zero Trust dashboard setup would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stoppedcommand: tunnel runenvironment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}depends_on:
- mycontainer

Where an .env file in the same directory contains TUNNEL_TOKEN= set to the token given by the Zero Trust dashboard. For more information see the Cloudflare Blog

Note A previous version of this README recommended using --token ${CLOUDFLARED_TOKEN}, which is a less secure way of handing off the token. Setting the TUNNEL_TOKEN variable seems to be a better way of approaching this.

Config file setup (Named tunnel)

An example for a setup with a local config would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stopped # or 'always' to survive container stopsvolumes:
- ./cloudflared:/etc/cloudflaredcommand: tunnel run mytunneldepends_on:
- mycontainer

Where ./cloudflared is a folder containing the .json or .pem credentials and config.yml for a tunnel.

An example config.yml might look like:

tunnel: uuid-for-tunnel#Optional#credentials-file: /etc/cloudflared/uuid-for-tunnel.jsoningress:
- hostname: mywebsite.comservice: http://nginx:80
- service: http_status:404

For more information, refer to the Cloudflare Documentation

To acquire a certificate, you'll need to use the login command.
This will spit out /.cloudflared/cert.pem, rather than /etc/cloudflared.

As such, usage would be something like:

docker run -v $PWD/cloudflared:/.cloudflared erisamoe/cloudflared login

to create a folder called cloudflared in your current dir and deposit a cert.pem into it.

To create a tunnel, you can then do:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared tunnel create mytunnel

Which gives you a UUID for the new tunnel and and a .json credentials file corresponding to it.

And now you can either use the above compose example or for testing simply just:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared --hostname test.example.com --name mytunnel --hello-world

Which will start up a "Hello world" test tunnel on https://test.example.com.

DNS-over-HTTPS

While not the original intent behind the image, you can also use this to host a DNS resolver that speaks to a DNS-over-HTTPS backend.
For example:

docker run -d -p 53:53/udp --name my-dns-forwarder erisamoe/cloudflared proxy-dns --address 0.0.0.0

Would create a container called my-dns-forwarder that responds to DNS requests on your host.
Keep in mind when using this on a public server (e.g. VPS) it will by default listen on all interfaces, making you a public DNS resolver on the internet.
You can sidestep this by changing the -p to instead be -p 127.0.0.01:53:53/udp to listen on localhost instead.

You can also add upstreams with --upstream https://dns.example.com for example. By default, Cloudflare DNS is used.

About

Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures.

Topics

Resources

Stars

203 stars

Watchers

5 watching

Forks

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' GitHub - Erisa/cloudflared-docker: Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures. · GitHub
Skip to content

Latest commit

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Erisa's Cloudflared Docker Image

This repository contains a simple Dockerfile to build cloudflared, the client for Cloudflare Tunnel, from source.

Note

This Docker image is not an official Cloudflare product.

The aim is to support multiple architectures.
The public image currently supports:

Docker targetAlso known asNotes
linux/amd64x86_64Majority of modern PCs and servers.
linux/386x8632-bit Intel/AMD CPUs. Typically really old computer hardware. These images are untested.
linux/arm64aarch6464-bit ARM hardware. For example Apple Silicon or Raspberry Pi 2/3/4 running a 64-bit OS.
linux/arm/v7armhf32-bit ARM hardware. For example most Raspberry Pi models running Raspberry Pi OS.
linux/arm/v6armelOlder 32-bit ARM hardware. Mostly Raspberry Pi 1/0/0W but there may be others.
linux/s390xIBM ZLinux on IBM Z for IBM mainframes, most notably IBM Cloud.
linux/ppc64leppc64elTested on IBM Cloud Power Systems Virtual Server
linux/riscv64riscv64CPUs from the future. Tested on Scaleway Labs RV1.

The public image corresponding to this Dockerfile is erisamoe/cloudflared and should work in mostly the same way as the official image.

Note

If you have any problems or questions with this image, either open a GitHub Issue or join the Cloudflare Developers Discord Server and ping @Erisa in #general-help, #general-discussions or #off-topic with your question.

Cloudflare Tunnel

Dashboard setup (Recommended)

A docker-compose example with a Zero Trust dashboard setup would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stoppedcommand: tunnel runenvironment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}depends_on:
- mycontainer

Where an .env file in the same directory contains TUNNEL_TOKEN= set to the token given by the Zero Trust dashboard. For more information see the Cloudflare Blog

Note A previous version of this README recommended using --token ${CLOUDFLARED_TOKEN}, which is a less secure way of handing off the token. Setting the TUNNEL_TOKEN variable seems to be a better way of approaching this.

Config file setup (Named tunnel)

An example for a setup with a local config would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stopped # or 'always' to survive container stopsvolumes:
- ./cloudflared:/etc/cloudflaredcommand: tunnel run mytunneldepends_on:
- mycontainer

Where ./cloudflared is a folder containing the .json or .pem credentials and config.yml for a tunnel.

An example config.yml might look like:

tunnel: uuid-for-tunnel#Optional#credentials-file: /etc/cloudflared/uuid-for-tunnel.jsoningress:
- hostname: mywebsite.comservice: http://nginx:80
- service: http_status:404

For more information, refer to the Cloudflare Documentation

To acquire a certificate, you'll need to use the login command.
This will spit out /.cloudflared/cert.pem, rather than /etc/cloudflared.

As such, usage would be something like:

docker run -v $PWD/cloudflared:/.cloudflared erisamoe/cloudflared login

to create a folder called cloudflared in your current dir and deposit a cert.pem into it.

To create a tunnel, you can then do:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared tunnel create mytunnel

Which gives you a UUID for the new tunnel and and a .json credentials file corresponding to it.

And now you can either use the above compose example or for testing simply just:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared --hostname test.example.com --name mytunnel --hello-world

Which will start up a "Hello world" test tunnel on https://test.example.com.

DNS-over-HTTPS

While not the original intent behind the image, you can also use this to host a DNS resolver that speaks to a DNS-over-HTTPS backend.
For example:

docker run -d -p 53:53/udp --name my-dns-forwarder erisamoe/cloudflared proxy-dns --address 0.0.0.0

Would create a container called my-dns-forwarder that responds to DNS requests on your host.
Keep in mind when using this on a public server (e.g. VPS) it will by default listen on all interfaces, making you a public DNS resolver on the internet.
You can sidestep this by changing the -p to instead be -p 127.0.0.01:53:53/udp to listen on localhost instead.

You can also add upstreams with --upstream https://dns.example.com for example. By default, Cloudflare DNS is used.

About

Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures.

Topics

Resources

Stars

203 stars

Watchers

5 watching

Forks

Sponsor this project

Packages

Used by

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); GitHub - Erisa/cloudflared-docker: Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures. · GitHub
Skip to content

Latest commit

History

275 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Erisa's Cloudflared Docker Image

This repository contains a simple Dockerfile to build cloudflared, the client for Cloudflare Tunnel, from source.

Note

This Docker image is not an official Cloudflare product.

The aim is to support multiple architectures.
The public image currently supports:

Docker targetAlso known asNotes
linux/amd64x86_64Majority of modern PCs and servers.
linux/386x8632-bit Intel/AMD CPUs. Typically really old computer hardware. These images are untested.
linux/arm64aarch6464-bit ARM hardware. For example Apple Silicon or Raspberry Pi 2/3/4 running a 64-bit OS.
linux/arm/v7armhf32-bit ARM hardware. For example most Raspberry Pi models running Raspberry Pi OS.
linux/arm/v6armelOlder 32-bit ARM hardware. Mostly Raspberry Pi 1/0/0W but there may be others.
linux/s390xIBM ZLinux on IBM Z for IBM mainframes, most notably IBM Cloud.
linux/ppc64leppc64elTested on IBM Cloud Power Systems Virtual Server
linux/riscv64riscv64CPUs from the future. Tested on Scaleway Labs RV1.

The public image corresponding to this Dockerfile is erisamoe/cloudflared and should work in mostly the same way as the official image.

Note

If you have any problems or questions with this image, either open a GitHub Issue or join the Cloudflare Developers Discord Server and ping @Erisa in #general-help, #general-discussions or #off-topic with your question.

Cloudflare Tunnel

Dashboard setup (Recommended)

A docker-compose example with a Zero Trust dashboard setup would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stoppedcommand: tunnel runenvironment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}depends_on:
- mycontainer

Where an .env file in the same directory contains TUNNEL_TOKEN= set to the token given by the Zero Trust dashboard. For more information see the Cloudflare Blog

Note A previous version of this README recommended using --token ${CLOUDFLARED_TOKEN}, which is a less secure way of handing off the token. Setting the TUNNEL_TOKEN variable seems to be a better way of approaching this.

Config file setup (Named tunnel)

An example for a setup with a local config would be:

services:
cloudflared:
image: erisamoe/cloudflaredrestart: unless-stopped # or 'always' to survive container stopsvolumes:
- ./cloudflared:/etc/cloudflaredcommand: tunnel run mytunneldepends_on:
- mycontainer

Where ./cloudflared is a folder containing the .json or .pem credentials and config.yml for a tunnel.

An example config.yml might look like:

tunnel: uuid-for-tunnel#Optional#credentials-file: /etc/cloudflared/uuid-for-tunnel.jsoningress:
- hostname: mywebsite.comservice: http://nginx:80
- service: http_status:404

For more information, refer to the Cloudflare Documentation

To acquire a certificate, you'll need to use the login command.
This will spit out /.cloudflared/cert.pem, rather than /etc/cloudflared.

As such, usage would be something like:

docker run -v $PWD/cloudflared:/.cloudflared erisamoe/cloudflared login

to create a folder called cloudflared in your current dir and deposit a cert.pem into it.

To create a tunnel, you can then do:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared tunnel create mytunnel

Which gives you a UUID for the new tunnel and and a .json credentials file corresponding to it.

And now you can either use the above compose example or for testing simply just:

docker run -v $PWD/cloudflared:/etc/cloudflared erisamoe/cloudflared --hostname test.example.com --name mytunnel --hello-world

Which will start up a "Hello world" test tunnel on https://test.example.com.

DNS-over-HTTPS

While not the original intent behind the image, you can also use this to host a DNS resolver that speaks to a DNS-over-HTTPS backend.
For example:

docker run -d -p 53:53/udp --name my-dns-forwarder erisamoe/cloudflared proxy-dns --address 0.0.0.0

Would create a container called my-dns-forwarder that responds to DNS requests on your host.
Keep in mind when using this on a public server (e.g. VPS) it will by default listen on all interfaces, making you a public DNS resolver on the internet.
You can sidestep this by changing the -p to instead be -p 127.0.0.01:53:53/udp to listen on localhost instead.

You can also add upstreams with --upstream https://dns.example.com for example. By default, Cloudflare DNS is used.

About

Simple Alpine-built scratch-runtime Dockerfile for cloudflared, with support for multiple architectures.

Topics

Resources

Stars

203 stars

Watchers

5 watching

Forks

Sponsor this project

Packages

Used by

Contributors

Languages