No description
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-09-26 18:27:35 +00:00
defaults agent updates 2026-09-26 18:27:35 +00:00
meta add galaxy metadata 2026-04-05 20:59:10 +00:00
tasks agent updates 2026-09-26 18:27:35 +00:00
.gitignore update common format, update default values, modernize role 2025-10-06 22:06:24 +00:00
README.md agent updates 2026-09-26 18:27:35 +00:00

cloudflared

Deploy a Cloudflare Tunnel connector as a rootless Podman container.

This role uses the shared deployment role and creates a single container named cloudflared by default. It is designed for remotely managed tunnels using a TUNNEL_TOKEN.

Example

cloudflared_user: srv

# Store in vault.
cloudflared_token: "{{ vault_cloudflared_token }}"

Because this repository includes cloudflared as a shared role in deploy.yml, the role defaults cloudflared_enabled to membership in the inventory group named by cloudflared_inventory_group, which defaults to cloudflared.

Override this when using the role directly outside that shared-services flow:

cloudflared_enabled: true

Network Selection

The role defaults cloudflared_network to host, so outbound tunnel connections use the host network namespace and routing table. Podman should not be translating tunnel egress in this default configuration.

Cloudflare's cloudflared defaults edge-ip-version to IPv4. This role sets cloudflared_edge_ip_version: auto so dual-stack hosts can select IPv6 and fallback according to the host and DNS result ordering.

Force IPv6:

cloudflared_edge_ip_version: "6"

Bind to a specific source address:

cloudflared_edge_bind_address: "2001:db8::10"

The IP version of cloudflared_edge_bind_address overrides cloudflared_edge_ip_version.

Transport

The role exposes Cloudflare's main tunnel transport knobs:

cloudflared_protocol: auto
cloudflared_loglevel: info
cloudflared_retries: 5
# cloudflared_metrics: 127.0.0.1:49312
# cloudflared_post_quantum: true
# cloudflared_region: us
# cloudflared_dns_resolver_addrs:
#   - 2606:4700:4700::1111:53
#   - 2606:4700:4700::1001:53

Additional environment values can be supplied with cloudflared_deploy_env.

References: