09e634de31
gates / gates (push) Successful in 28s
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS
44 lines
1.6 KiB
Cheetah
44 lines
1.6 KiB
Cheetah
# Cloudflare Tunnel — external access connector — managed by felhom-controller (base-infra bring-up).
|
|
# Routes are configured in the Cloudflare dashboard (Zero Trust > Networks > Tunnels > Public Hostname);
|
|
# the tunnel connects Cloudflare's edge to Traefik, which handles TLS + routing internally.
|
|
services:
|
|
cloudflared:
|
|
image: {{.Image}}
|
|
container_name: cloudflared
|
|
restart: unless-stopped
|
|
# R-841: metrics on the container's own loopback at a FIXED port, and a health check that asks cloudflared itself
|
|
# whether the tunnel is CONNECTED (`/ready`: 200 with readyConnections > 0, else 503 — measured 2026-10-04: with a
|
|
# wrong token the container stays "running" while /ready is 503). The host agent reads the result with
|
|
# `docker inspect` (State.Health) and reports the tunnel as running | not_running | unknown.
|
|
command: tunnel --metrics localhost:20241 run
|
|
healthcheck:
|
|
test: ["CMD", "cloudflared", "tunnel", "--metrics", "localhost:20241", "ready"]
|
|
interval: 30s
|
|
timeout: 10s
|
|
retries: 3
|
|
start_period: 30s
|
|
environment:
|
|
- TUNNEL_TOKEN={{.CFTunnelToken}}
|
|
dns:
|
|
- 1.1.1.1
|
|
- 8.8.8.8
|
|
security_opt:
|
|
- no-new-privileges:true
|
|
{{- if .Tunnel}}
|
|
# R-753: alone on felhom-tunnel at a fixed address — the one peer traefik believes forwarded headers from.
|
|
networks:
|
|
{{.TunnelNetwork}}:
|
|
ipv4_address: {{.TunnelAddr}}
|
|
|
|
networks:
|
|
{{.TunnelNetwork}}:
|
|
external: true
|
|
{{- else}}
|
|
networks:
|
|
- traefik-public
|
|
|
|
networks:
|
|
traefik-public:
|
|
external: true
|
|
{{- end}}
|