Cloudflare Access: An Extra Layer of Protection in Front of Home Assistant

Cloudflare Access: An Extra Layer of Protection in Front of Home Assistant

Module 8 · Lesson 6

If you set up Cloudflare Tunnel back in Module 7, Cloudflare Access adds a second, genuinely independent login layer in front of your Home Assistant login page. This lesson covers exactly what it does, when it's actually worth the extra setup effort, and how to roll it out carefully and safely without locking yourself out.

Tunnel versus Access: hallway versus front door

Cloudflare Tunnel, from Module 7, is the hallway, the outbound-only connection carrying traffic from the internet to your Home Assistant server without opening a port. Cloudflare Access is a locked front door placed at the entrance of that hallway, requiring its own separate authentication, through Cloudflare itself, before a visitor ever reaches your actual Home Assistant login page at all. The two work together but solve genuinely different problems, Tunnel handles the plumbing, Access handles who's allowed to even approach the door in the first place.

What Access is for

Without Access, anyone who knows or guesses your home.yourdomain.com address reaches your Home Assistant login page directly, protected only by your account password and two-factor authentication from Lesson 2 and Lesson 3. With Access enabled, that same visitor first hits a Cloudflare-managed login screen, requiring a separate, pre-approved email address or authentication method before your actual Home Assistant login page ever loads at all, an entirely additional barrier standing in front of the one you already built.

When Access makes sense

Access is worth setting up if your Cloudflare Tunnel address is memorable or guessable, if you'd simply like defense in depth beyond Home Assistant's own login page, or if you're security-conscious enough that an extra layer, even for a small household, genuinely appeals to you. It's a free feature on Cloudflare's free tier for a small number of users, making it a genuinely low-cost addition for anyone who's already invested the initial effort into Module 7's tunnel setup and wants a bit more peace of mind.

When not to complicate things

If you're using Nabu Casa, WireGuard, or Tailscale instead of Cloudflare Tunnel, this lesson simply doesn't apply, Access is specific to the Cloudflare Tunnel setup from Module 7's Lessons 5 and 6. And even among Cloudflare Tunnel users, if Lesson 2's account structure and Lesson 3's password hygiene already feel like plenty of security for your comfort level, skipping Access entirely is a completely reasonable choice, this lesson is genuinely optional additional depth, not a required or mandatory step for anyone to feel obligated to complete.

The risk of locking yourself out

A misconfigured Access policy can lock you out of your own Home Assistant server just as effectively as it blocks anyone else, worth taking seriously before rolling it out. Always keep local network access, connecting directly by local IP address at home, as an untouched fallback, and never enable Access without first carefully confirming your own email address or login method is genuinely included in the exact policy you're about to apply, ideally tested thoroughly before you're actually relying on it day to day.

Access policies

An Access policy defines who's allowed through, typically a list of specific, pre-approved email addresses, each verified through a one-time code sent to that address when they first try to connect. Set this up from within Cloudflare's Zero Trust dashboard, the same general area Module 7's Lesson 6 briefly introduced, creating a new application tied specifically to your home.yourdomain.com hostname and a policy listing every single email address that should genuinely have access.

Access for household members

Add each household member's own individual email address to your Access policy, matching the individual account structure Lesson 2 carefully established, rather than sharing just one single approved email address across everyone in the household. This means each person authenticates through Cloudflare with their own distinct identity before ever reaching the Home Assistant login screen itself, giving you the same kind of genuine per-person visibility Lesson 2's account separation already provides, now extended one full layer earlier in the connection chain.

Access and the mobile app

The Home Assistant mobile app can work through Access, though it requires an initial authentication step through Cloudflare the first time, slightly more involved than the simpler setups in Module 7's earlier lessons. Once authenticated, the app generally continues working smoothly without repeating the process constantly, though exactly how often re-authentication is required depends on your specific Access policy's session duration settings.

Access and webhooks

If you use webhooks, automated triggers from an external service reaching into Home Assistant, Access will block them by default, since a webhook can't complete an interactive email-based login the way a person can. Cloudflare supports service-token-based exceptions for exactly this scenario, worth configuring specifically if you rely on webhooks, and worth testing carefully after enabling Access to confirm nothing you depend on has silently broken.

A 10-step safe rollout procedure

Confirm your local network access still works as a fallback. Take a manual backup. List every email address that genuinely needs access. Create the Access application in Cloudflare's dashboard. Build the policy with those emails. Save it, but don't close the tab yet. Open a private browser window and test your own access immediately. Confirm the mobile app still connects. Confirm any webhooks still function, adding service tokens if needed. And only then consider the rollout complete, documenting it in your notebook as this lesson's exercise describes.

Access versus Nabu Casa or a VPN

Nabu Casa and VPN-based methods from Module 7 don't have a direct Access equivalent, their entire model already restricts who can reach your server, through Nabu Casa's own authentication or a VPN's per-device configuration respectively. Access is specifically a Cloudflare Tunnel feature, filling a gap that only exists because Cloudflare Tunnel's whole appeal is a memorable public address, precisely the thing that also makes it worth adding an extra access layer in front of.

What not to do

Don't enable Access without testing it in a private browser window first, don't set an overly broad policy allowing an entire email domain when a specific list of individual addresses would do, and don't skip the local-network fallback check, the single most common way readers accidentally lock themselves out entirely. And don't treat Access as a replacement for the account and password hygiene Lessons 2 and 3 already built, it's an addition, not a substitute.

Exercise

If you're using Cloudflare Tunnel and genuinely want the extra layer of protection, walk carefully through this lesson's full ten-step rollout procedure, testing thoroughly at each individual stage along the way. If you decide Access simply isn't worth the added complexity for your household right now, that's a completely fine, reasonable outcome too, just note that specific decision clearly in your notebook so future-you knows it was a deliberate, considered choice, not an oversight.

Your Access notebook

If you enable Access, note the policy's approved email addresses, the date you set it up, and confirmation that you tested it from a private browser window before relying on it. If you decide against it, a one-line note explaining why is enough, useful context for revisiting the decision later without redoing this lesson's full reasoning from scratch.

A real story: the policy that locked out the wrong device

A reader in this course's community set up Access on a Sunday afternoon, carefully tested it from their laptop in a private browser window exactly as this lesson recommends, confirmed it worked, and felt satisfied with the rollout. The following week, on a work trip, their phone's Home Assistant app suddenly stopped connecting entirely, the mobile app's authentication token had expired under the new Access policy's session settings, and it hadn't been tested from the phone specifically, only the laptop. Fortunately, local network access remained untouched at home, and a family member was able to check on things directly until the phone's Access authentication could be manually renewed a few days later. The lesson they took away, and the reason this lesson insists on testing every device you actually use, not just the one convenient laptop sitting in front of you during setup, was that "it worked once" and "it works for everyone, everywhere" are genuinely two different, easily conflated claims.

Access session duration and re-authentication

Cloudflare lets you configure how long an Access session lasts before requiring re-authentication, ranging from a few hours to several weeks. A shorter session is more secure but means logging in more often, a longer session is more convenient but means a compromised device stays authenticated longer if it's ever lost, tying directly back to Lesson 3's lost-phone checklist. A reasonable middle ground for most households is somewhere around a week, revisited and shortened if your household's specific risk tolerance calls for something tighter.

Choosing an identity provider

Cloudflare's default one-time-email-code method works well and requires no additional setup, genuinely the simplest choice for most households and the one this lesson has assumed throughout. Cloudflare also supports connecting a third-party identity provider, Google, Microsoft, or GitHub accounts among others, for readers who'd prefer authenticating through a service they already use daily rather than checking email for a fresh code every single time a session expires. Either approach works fine, this is a matter of personal convenience rather than any meaningful difference in the underlying protection Access actually provides.

Access logs and an audit trail

Cloudflare's Zero Trust dashboard keeps a log of every Access authentication attempt, successful and failed alike, similar in spirit to the login history Lesson 2 and Lesson 3 covered for Home Assistant's own accounts, but one full layer earlier in the connection. Glancing at this occasionally, particularly after enabling Access for the first time, helps confirm the policy is behaving exactly as intended and gives you an extra, independent vantage point for spotting anything unusual well before it ever reaches your actual Home Assistant login page.

Removing Access if you change your mind

If Access ever feels like more overhead than it's worth for your household, removing it is straightforward, delete the application from Cloudflare's Zero Trust dashboard, and your home.yourdomain.com address immediately returns to going straight to Home Assistant's own login page, exactly as it worked at the end of Module 7 before this lesson. Nothing about Module 7's tunnel setup itself needs to change, Access sits cleanly on top of it and comes off just as cleanly, without disturbing the underlying connection your tunnel already established.

The cost of Cloudflare Access

Cloudflare Access is included free for a small number of users on Cloudflare's free tier, comfortably covering most households described throughout this course. Larger households or anyone wanting additional Zero Trust features beyond basic Access policies may eventually cross into a paid tier, worth checking Cloudflare's current pricing directly if your household's needs genuinely extend that far, though the overwhelming majority of readers following this course will never need to.

Access for a house-sitter or temporary guest

If a house-sitter or extended guest needs temporary remote access while you're away, add their email to your Access policy for the duration of their stay, then remove it the moment that need ends, exactly the same discipline Lesson 2 recommended for temporary Home Assistant accounts. This is arguably where Access shines most for an everyday household, granting genuinely temporary, easily revocable access without ever having to share your own personal login credentials with someone outside your immediate household, closing off precisely the kind of stale-access scenario Lesson 1 flagged as an inside threat worth taking seriously.

Access and multiple self-hosted services

Recall from Module 7 that Cloudflare Tunnel can front more than one self-hosted service under the same domain, home.yourdomain.com for Home Assistant, files.yourdomain.com for a NAS, if you ever expand beyond this course's scope. Access policies apply per application, meaning you can require a stricter policy for one service and a looser one for another, or apply the exact same policy uniformly across everything running through your tunnel, whichever structure best matches how sensitive each individual service genuinely is to you.

Why this lesson is optional but worth reading anyway

Even readers who ultimately decide against enabling Access benefit from understanding what it offers, since the underlying concept, an authentication layer sitting in front of your actual application, shows up in plenty of contexts well beyond just Home Assistant and Cloudflare specifically. Understanding the tradeoff between convenience and defense in depth, covered throughout this lesson, is a genuinely transferable piece of security literacy, not just a Cloudflare-specific configuration exercise limited to this one particular tool.

How Access fits with everything else in this module

Recall the six-locks framing from Lesson 1: accounts, passwords, backups, updates, and, for Cloudflare Tunnel users specifically, this lesson's Access layer, followed by Lesson 7's emergency plan for when something still goes wrong despite all of it. Access is genuinely the most optional of these six, deliberately placed near the end of the module for exactly that reason, but for readers who've already built a Cloudflare Tunnel setup, it's a natural, low-cost extension of work you've already done rather than an entirely new undertaking.

Testing Access from outside your home network

Beyond the private browser window test in this lesson's rollout procedure, it's worth confirming Access behaves correctly from genuinely outside your home network too, mobile data with WiFi off, exactly the test pattern Module 7 established for every remote access method covered in that entire module. Testing only from your home WiFi risks missing a subtle configuration issue that only surfaces once traffic is actually routing through Cloudflare's infrastructure from a genuinely external connection, rather than potentially taking a shortcut your local network might quietly provide without you realizing it.

Explaining Access to non-technical household members

If you add household members to your Access policy, a brief, plain explanation helps: "you'll see a Cloudflare login page before Home Assistant loads now, check your email for a code, it's a normal part of how this works." Without that context, an unfamiliar login screen appearing where a familiar one used to be can feel alarming or broken rather than intentional, undermining the trust and goodwill Lesson 5 already emphasized building around changes like this one.

Revisiting your Access decision over time

Whether you enable Access now or decide to wait, this decision isn't permanent, exactly the same revisitable framing Module 7's Lesson 7 applied to remote access methods generally. A household that starts without Access might add it later once a Cloudflare Tunnel address has been shared more widely than originally intended, or once curiosity about Zero Trust concepts grows alongside the rest of this course's security material. Equally, a household that enables it early might later decide the extra login step isn't worth the friction for their specific daily habits and remove it, following the straightforward removal process this lesson already covered. Either direction is a genuinely legitimate, well-informed choice, not a mistake to be second-guessed later, as long as it's made deliberately and consciously rather than by simply never revisiting the underlying question again at all.

Key takeaways

Access is optional, specific to Cloudflare Tunnel, and adds a second login layer before Home Assistant's own.

Always confirm local network access works before enabling it, that's your fallback.

Test in a private browser window immediately after saving any new policy.

Webhooks need service-token exceptions, they can't complete an interactive login.

Lesson 7 closes out this module with a genuine, practical emergency plan for the day Home Assistant simply won't start at all.

Finished this lesson?