Tunnel & Networking
Publish an app on your domain through a Cloudflare tunnel with no open ports, and privately connect apps to each other by a stable name.
What Tunnel & Networking does
Open a server and select the Tunnel & Networking tab. A tunnel serves traffic through an outbound connection — no inbound ports opened and no firewall changes. It covers two jobs:
- Serve an app on your domain — point app.example.com at a container without publishing its port
- Let your apps reach each other — connect an app to a database by a stable private name, then close the public port
Private connections work without Cloudflare. Public hostnames need a Cloudflare account.
Install a tunnel and connect Cloudflare
A server with no tunnel shows No tunnel on this server yet ("A tunnel serves traffic through an outbound connection — no inbound ports opened and no firewall changes").
- Click Install tunnel
- Click Connect Cloudflare account (later Update Cloudflare account) to enable public hostnames
- The Tunnel card then shows the Cloudflare account, Tunnel, and Connector, with badges such as Adopted, Observation only, or Update available
Tunnel actions include Re-check, Convert to managed, Update connector, and Repair.
Public hostnames
In the Public hostnames section, click Add hostname to map a hostname to an app. The table columns are Hostname, App, Private name, Server IP access, and Status. Set Server IP access to Closed (recommended) so the app stops answering on the raw server IP once the hostname is live. Routes report as Live, Removing…, Cleanup paused, or Setup paused.
Private connections between apps
In the Private connections section, click Connect apps to let one app reach another by a stable private name. The table shows From, Reaches, Address used, Public port, and Status (Connected / Failed). Because private connections work without Cloudflare, you can connect an app to its database privately and then close the database's public port.
Frequently Asked Questions
Do I have to open ports on my server?
No. The connector is outbound-only, so no inbound server ports are required and no firewall changes are needed.
Do private app-to-app connections need Cloudflare?
No — private connections work without Cloudflare. Only public hostnames need a connected Cloudflare account.
Ready to try Server Compass?
Download the app and deploy your first application in under 5 minutes.
Download Server Compass