Cloudflare Tunnel: Your Own Address Without Port Forwarding

Cloudflare Tunnel: Your Own Address Without Port Forwarding

Module 7 · Lesson 5

Cloudflare Tunnel gives Home Assistant its own custom web address, like home.yourdomain.com, without a VPN and without opening a single port on your router. This lesson covers the concept and tradeoffs, Lesson 6 walks through the full setup.

What this lesson doesn't do

This lesson doesn't walk through the actual configuration steps, domain setup, DNS records, the tunnel add-on itself, that's Lesson 6's job in full detail. It doesn't suggest Cloudflare Tunnel replaces the previous three lessons either, it's a genuinely different tool with its own specific strengths. Its job is explaining what Cloudflare Tunnel actually is and helping you decide if the domain-name requirement and setup ahead in Lesson 6 is worth it for your situation.

What Cloudflare Tunnel is

Cloudflare Tunnel is a free service from Cloudflare, a large, well-known infrastructure and security company, that creates an outbound-only connection from your Home Assistant server to Cloudflare's network, exactly the outbound-first pattern Lesson 1 described as the safer default. Once connected, Cloudflare routes traffic from a custom web address you control, home.yourdomain.com, straight through that tunnel to your Home Assistant server, with no inbound port ever opened on your router.

What it solves

Like Nabu Casa and Tailscale, Cloudflare Tunnel works behind CGNAT without issue, since the connection is entirely outbound. Unlike either, it gives you a genuinely custom, memorable web address on a domain you own, rather than a provider-assigned subdomain, and it can additionally front more than one self-hosted service under different addresses on the same domain, home.yourdomain.com for Home Assistant, files.yourdomain.com for a NAS, if you ever expand beyond this course's scope.

What it requires

Unlike every other method in this module, Cloudflare Tunnel requires owning a domain name, a modest annual cost from any domain registrar, and pointing that domain's DNS to Cloudflare, covered step by step in Lesson 6. This is the meaningful barrier to entry compared to Nabu Casa or Tailscale, both of which need nothing beyond an account, and it's worth weighing honestly before committing to this route.

When to choose Cloudflare Tunnel

Choose it if you already own a domain, or want one anyway, and like the idea of a custom, professional-looking address for your Home Assistant server. Choose it too if you plan to self-host other services beyond Home Assistant and want one unified system fronting all of them under the same domain. It's a strong fit for readers who found WireGuard and Tailscale's VPN model appealing but want the specific benefit of exposing just Home Assistant itself under a real domain, rather than putting an entire device on the network.

When not to choose it

If you don't want to buy or manage a domain, skip this route entirely, Nabu Casa or Tailscale get you working remote access without that requirement. If you want your entire home network reachable, not just individual services you deliberately expose, a VPN from Lesson 3 or 4 fits that goal more directly. And if Lesson 6's more involved setup, DNS records, tunnel configuration, public hostnames, sounds like more than you want to take on, that's a completely reasonable reason to stick with a simpler method instead.

Cloudflare Tunnel versus Nabu Casa

Both solve the same fundamental problem, exposing Home Assistant without opening a port, but Nabu Casa is turnkey and paid, while Cloudflare Tunnel is free beyond the domain's small annual cost but requires meaningfully more setup and a working understanding of DNS. Nabu Casa also directly funds Home Assistant's development, a factor Lesson 2 covered, worth weighing against Cloudflare Tunnel's zero-subscription cost if that consideration matters to you.

Cloudflare Tunnel versus a VPN

A VPN gives you your whole network, Cloudflare Tunnel gives you specifically whatever services you deliberately expose through it, nothing more. This narrower exposure is arguably a security advantage, a compromised device on your VPN has broader network access than one only reaching Home Assistant through a tunnel, but it also means a VPN remains the better fit if reaching your NAS, printer, or other home devices remotely genuinely matters to you beyond just Home Assistant.

Security considerations

Cloudflare Tunnel doesn't expose your router at all, but the resulting web address is still a login page reachable by anyone who knows or guesses it, exactly like Nabu Casa's Remote UI. The strong password and two-factor authentication baseline from Lesson 1 remains just as essential here, and Cloudflare additionally offers optional access policies, restricting who can even reach your tunnel's address by email or authentication provider, covered briefly in Lesson 6 for anyone wanting that extra layer.

A public address is still a public address

It's worth being direct about this: home.yourdomain.com, once set up, is reachable by anyone on the internet who knows or guesses that address, exactly as reachable in principle as Nabu Casa's Remote UI address is. Cloudflare's infrastructure provides real protection against a range of automated attacks, but it doesn't replace your own account security, and this course treats it with the same baseline seriousness as any other method exposing a login page to the wider internet.

General configuration overview

At a high level, setup involves pointing your domain's DNS to Cloudflare, installing the Cloudflare Tunnel add-on on HAOS or its container equivalent on Container, authenticating it to your Cloudflare account, and configuring a public hostname mapping home.yourdomain.com to your Home Assistant server's local address. Lesson 6 covers every one of these steps in genuine, careful detail, including a glossary of terms to keep the DNS-specific vocabulary from feeling overwhelming on first encounter.

Reverse proxy, a preview

Cloudflare Tunnel functions as a reverse proxy, a service that receives public traffic and forwards it to the correct internal address, and understanding this term now sets up Lesson 6's configuration section, where it comes up directly while explaining Home Assistant's own reverse-proxy-related settings. You don't need to understand reverse proxies deeply to follow Lesson 6's steps, but recognizing the term will make that lesson feel considerably less like unfamiliar jargon.

A short exercise before moving on

If Cloudflare Tunnel appeals to you, decide now whether you already own a domain you'd like to use, or would need to purchase one, this decision genuinely shapes how quickly Lesson 6 goes. If you don't want a domain at all, that's a perfectly reasonable place to stop, Nabu Casa, WireGuard, and Tailscale already cover the vast majority of readers' actual needs without one.

What it really costs

The Cloudflare Tunnel service itself is genuinely free, no subscription, no usage-based billing for a typical home setup. The only real cost is your domain name's annual registration fee, typically a modest amount per year depending on the registrar and domain extension chosen, a fraction of what a full year of most subscription services would cost, and one you may already be paying if you own a domain for any other reason.

What happens during a Cloudflare outage

Because Cloudflare Tunnel routes through Cloudflare's own infrastructure, a rare outage on their end would temporarily affect your tunnel's availability, exactly the same category of dependency Nabu Casa's Remote UI has on its own infrastructure. Cloudflare's infrastructure is large and generally very reliable, and your local network access at home remains completely unaffected regardless, only the remote path through the tunnel would be briefly interrupted until Cloudflare's own service resumes, typically within minutes given the sheer scale of their global infrastructure.

Choosing between all four methods so far

With four methods now covered, Nabu Casa, WireGuard, Tailscale, and Cloudflare Tunnel, it's worth a brief mental recap before Lesson 6's hands-on setup: want the absolute simplest path and don't mind paying, Nabu Casa. Want free and full network access, and you're not behind CGNAT, WireGuard. Free, full network access, and you are behind CGNAT, Tailscale. Want a custom domain and a system that can grow to front other self-hosted services later, Cloudflare Tunnel. Lesson 7 formalizes this decision process fully with a proper comparison table, but this rough sketch should already point you toward the right next lesson to actually follow through on.

Key takeaways

Cloudflare Tunnel is outbound-only, works behind CGNAT, no port forwarding needed.

It requires owning a domain name, the one real barrier compared to Lessons 2 through 4.

It exposes only what you deliberately configure, not your whole network like a VPN.

The service itself is free, only the domain name carries an annual cost.

Lesson 6 walks through the full setup, step by step, from DNS to your first successful connection, and it's worth reading in one sitting rather than in fragments.

Finished this lesson?