# Cloudflare Tunnel — external access connector — managed by felhom-controller (base-infra bring-up). # Routes are configured in the Cloudflare dashboard (Zero Trust > Networks > Tunnels > Public Hostname); # the tunnel connects Cloudflare's edge to Traefik, which handles TLS + routing internally. services: cloudflared: image: {{.Image}} container_name: cloudflared restart: unless-stopped # R-841: metrics on the container's own loopback at a FIXED port, and a health check that asks cloudflared itself # whether the tunnel is CONNECTED (`/ready`: 200 with readyConnections > 0, else 503 — measured 2026-10-04: with a # wrong token the container stays "running" while /ready is 503). The host agent reads the result with # `docker inspect` (State.Health) and reports the tunnel as running | not_running | unknown. command: tunnel --metrics localhost:20241 run healthcheck: test: ["CMD", "cloudflared", "tunnel", "--metrics", "localhost:20241", "ready"] interval: 30s timeout: 10s retries: 3 start_period: 30s environment: - TUNNEL_TOKEN={{.CFTunnelToken}} dns: - 1.1.1.1 - 8.8.8.8 security_opt: - no-new-privileges:true {{- if .Tunnel}} # R-753: alone on felhom-tunnel at a fixed address — the one peer traefik believes forwarded headers from. networks: {{.TunnelNetwork}}: ipv4_address: {{.TunnelAddr}} networks: {{.TunnelNetwork}}: external: true {{- else}} networks: - traefik-public networks: traefik-public: external: true {{- end}}