Files
felhom-controller/controller/internal/infra/templates/cloudflared-compose.yml.tmpl
T

44 lines
1.6 KiB
Cheetah

# Cloudflare Tunnel — external access connector — managed by felhom-controller (base-infra bring-up).
# Routes are configured in the Cloudflare dashboard (Zero Trust > Networks > Tunnels > Public Hostname);
# the tunnel connects Cloudflare's edge to Traefik, which handles TLS + routing internally.
services:
cloudflared:
image: {{.Image}}
container_name: cloudflared
restart: unless-stopped
# R-841: metrics on the container's own loopback at a FIXED port, and a health check that asks cloudflared itself
# whether the tunnel is CONNECTED (`/ready`: 200 with readyConnections > 0, else 503 — measured 2026-10-04: with a
# wrong token the container stays "running" while /ready is 503). The host agent reads the result with
# `docker inspect` (State.Health) and reports the tunnel as running | not_running | unknown.
command: tunnel --metrics localhost:20241 run
healthcheck:
test: ["CMD", "cloudflared", "tunnel", "--metrics", "localhost:20241", "ready"]
interval: 30s
timeout: 10s
retries: 3
start_period: 30s
environment:
- TUNNEL_TOKEN={{.CFTunnelToken}}
dns:
- 1.1.1.1
- 8.8.8.8
security_opt:
- no-new-privileges:true
{{- if .Tunnel}}
# R-753: alone on felhom-tunnel at a fixed address — the one peer traefik believes forwarded headers from.
networks:
{{.TunnelNetwork}}:
ipv4_address: {{.TunnelAddr}}
networks:
{{.TunnelNetwork}}:
external: true
{{- else}}
networks:
- traefik-public
networks:
traefik-public:
external: true
{{- end}}