| Filename | Latest commit message | Latest commit date |
|---|---|---|
| defaults | ||
| meta | ||
| tasks | ||
| .gitignore | ||
| README.md | ||
cloudflared
Deploy a Cloudflare Tunnel connector as a rootless Podman container.
This role uses the shared deployment role and creates a single container named
cloudflared by default. It is designed for remotely managed tunnels using a
TUNNEL_TOKEN.
Example
cloudflared_user: srv
# Store in vault.
cloudflared_token: "{{ vault_cloudflared_token }}"
Because this repository includes cloudflared as a shared role in deploy.yml,
the role defaults cloudflared_enabled to membership in the inventory group
named by cloudflared_inventory_group, which defaults to cloudflared.
Override this when using the role directly outside that shared-services flow:
cloudflared_enabled: true
Network Selection
The role defaults cloudflared_network to host, so outbound tunnel
connections use the host network namespace and routing table. Podman should not
be translating tunnel egress in this default configuration.
Cloudflare's cloudflared defaults edge-ip-version to IPv4. This role sets
cloudflared_edge_ip_version: auto so dual-stack hosts can select IPv6 and
fallback according to the host and DNS result ordering.
Force IPv6:
cloudflared_edge_ip_version: "6"
Bind to a specific source address:
cloudflared_edge_bind_address: "2001:db8::10"
The IP version of cloudflared_edge_bind_address overrides
cloudflared_edge_ip_version.
Transport
The role exposes Cloudflare's main tunnel transport knobs:
cloudflared_protocol: auto
cloudflared_loglevel: info
cloudflared_retries: 5
# cloudflared_metrics: 127.0.0.1:49312
# cloudflared_post_quantum: true
# cloudflared_region: us
# cloudflared_dns_resolver_addrs:
# - 2606:4700:4700::1111:53
# - 2606:4700:4700::1001:53
Additional environment values can be supplied with cloudflared_deploy_env.
References: