Files
felhom-controller/controller/internal/infra/templates/cloudflared-compose.yml.tmpl
T
admin 1e8d045815 R-753: the box tells visitors apart — cloudflared at a fixed address, traefik trusts only it, the controller reads the hop traefik saw
- felhom-tunnel network 172.16.253.0/29 (ip-range .4/30): cloudflared alone at .2, traefik at .3; traefik's websecure
  trusts forwarded headers from 172.16.253.2/32 only, and every request passes felhom-forwarded@file, which removes
  the client-writable host/path/address headers (X-Forwarded-Host/-Uri/-Method/-Prefix, Forwarded, True-Client-Ip, …)
  and fixes X-Forwarded-Port to 443 (measured: Cloudflare passes a client's X-Forwarded-Host/-Port).
- EnsureBaseStack reconciles a RUNNING traefik/cloudflared whose rendered files changed (recreate), refuses a rewrite
  that would drop a certificate resolver, and moves cloudflared only once traefik is on the tunnel network.
- clientIP: believed only when the TCP peer is traefik; the rightmost X-Forwarded-For entry (the hop traefik saw);
  the tunnel hop → CF-Connecting-IP (the edge refuses a client-sent one, measured 403). rateKey: IPv6 per /64.
  Dashboard login, claim, share and escrow counters key on it; the setup gate logs it.
- Dashboard login messages: keys, informal voice, both languages.
Red-proofs: RP-A1 (leftmost hop), RP-A2 (shared tunnel key), RP-A3 (no reconcile) — felhom.eu audits/visitors-2026-10-01/A.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
2026-10-01 21:01:42 +02:00

34 lines
947 B
Cheetah

# Cloudflare Tunnel — external access connector — managed by felhom-controller (base-infra bring-up).
# Routes are configured in the Cloudflare dashboard (Zero Trust > Networks > Tunnels > Public Hostname);
# the tunnel connects Cloudflare's edge to Traefik, which handles TLS + routing internally.
services:
cloudflared:
image: {{.Image}}
container_name: cloudflared
restart: unless-stopped
command: tunnel run
environment:
- TUNNEL_TOKEN={{.CFTunnelToken}}
dns:
- 1.1.1.1
- 8.8.8.8
security_opt:
- no-new-privileges:true
{{- if .Tunnel}}
# R-753: alone on felhom-tunnel at a fixed address — the one peer traefik believes forwarded headers from.
networks:
{{.TunnelNetwork}}:
ipv4_address: {{.TunnelAddr}}
networks:
{{.TunnelNetwork}}:
external: true
{{- else}}
networks:
- traefik-public
networks:
traefik-public:
external: true
{{- end}}