Skip to content
BotServBotServ
CloudflareTunnelRemoteNetworkingSecurityOllama

Cloudflare Tunnel: AI Services Without Public IP

Secure remote access to AI services like Ollama using Cloudflare Tunnel. No port forwarding needed.

S

schutzgeist

8 min read
Cloudflare Tunnel: AI Services Without Public IP

Cloudflare Tunnel: Exposing AI Services Without a Public IP

What you’ll learn in this article

  • What a Cloudflare Tunnel is and why it matters for your setup
  • Why you often don’t need port forwarding for AI services like Ollama
  • How to set up a tunnel to access your services from anywhere
  • Which prerequisites and security considerations apply
  • Common pitfalls and how to avoid them

Introduction

You may already be running Ollama on your Linux server or want to access AI tools remotely. The natural question then becomes: how do you expose your services to the internet without opening up your entire home network? The traditional approach requires port forwarding on your router, a public IP address, and manual TLS certificate management. It’s error-prone and not beginner-friendly.

A Cloudflare Tunnel offers a modern alternative. It creates an outbound connection from your server to Cloudflare. Incoming requests from the internet then flow through the Cloudflare infrastructure and your tunnel, without needing you to expose public ports. This means less attack surface, simpler router configuration, and automatic HTTPS in most cases.

In this article, I’ll walk you through what you need, how to set it up, and what to watch out for. Although I’ll focus on AI services like Ollama, the approach works for nearly any self-hosted service. For broader context on self-hosting, check out the Self-Hosting section. Network security and TLS certificates are covered separately under Network Security and TLS Certificates.

Why use Cloudflare Tunnel?

Cloudflare Tunnel is part of Cloudflare’s Zero Trust offering. The best-known client for it is cloudflared. Think of the tunnel as an encrypted exit route from your server into the Cloudflare network. Instead of visitors connecting directly to your public IP and open ports, they connect to a Cloudflare domain. Cloudflare then forwards traffic through the encrypted tunnel to your server.

This brings several advantages. You don’t need to configure port forwarding on your router. Your public IP stays hidden. Cloudflare can layer on additional services like DDoS protection, access rules, and automatic TLS encryption. For local AI services like Ollama, this is especially useful because you can access Ollama from a laptop, tablet, or phone without exposing your home network directly to the internet.

How Cloudflare Tunnel works

cloudflared is a small program you install on your server. It establishes an outbound connection to Cloudflare and authenticates using a token you generate beforehand. From there, you configure the Cloudflare Zero Trust dashboard to specify which domain routes to which local service.

Here’s an example: Ollama runs on your server on port 11434. You create a public hostname in the tunnel like ollama.example.de and route it to http://localhost:11434. Now Ollama is accessible via that domain. Everything runs over HTTPS as long as your domain is on Cloudflare and has a valid certificate.

Who this article is for

This guide is aimed at beginners who already run a local or rented server and want to expose their AI tools or other self-hosted services over the internet. You should be comfortable with the command line and willing to run a few commands in your Linux terminal. Programming skills aren’t strictly necessary, but familiarity with Docker or systemctl is helpful.

If you’d prefer a solution that doesn’t rely on external services, Tailscale might be more appealing. Cloudflare Tunnel, though, is quick to set up and doesn’t require separate VPN software on client devices.

Key terms

TermMeaning
TunnelAn encrypted connection between your server and an external network, in this case Cloudflare.
cloudflaredThe official Cloudflare Tunnel client that establishes the connection.
OutboundConnections that originate from your network toward the outside world.
Port forwardingA router setting that redirects incoming connections to a local machine.
Reverse proxyA service that forwards external requests to internal services, such as Nginx or Cloudflare itself.
TLSTransport Layer Security, the encrypted connection via HTTPS.
Public hostnameA publicly accessible domain that points to an internal service.
Access ruleA policy that defines who can access a tunnel or service.

Prerequisites for your first Cloudflare Tunnel

Before you start, you’ll need a few things. You need a domain that you manage at Cloudflare. Most top-level domains cost a bit, or you can use a free subdomain managed elsewhere. For getting started, a cheap domain from any registrar that you point to Cloudflare works fine.

Your server should run a Linux distribution like Ubuntu or Debian. You need root access or an account with sudo privileges. Make sure your server has a stable internet connection and allows outbound HTTPS connections. Cloudflare uses ports like 443 for TCP and 7844 for UDP, which work on most home networks and cloud servers.

In the Cloudflare dashboard, create a new tunnel under Zero Trust. You’ll receive a token that you need on your server. Keep it safe, as anyone with this token can authenticate cloudflared to your account.

Installing cloudflared

The easiest approach is installation from the official repository. For Debian and Ubuntu, use these commands in your terminal:

# Add Cloudflare GPG key and repository
sudo mkdir -p --mode=0755 /usr/share/keyrings
curl -fsSL https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-main.gpg

echo "deb [signed-by=/usr/share/keyrings/cloudflare-main.gpg] https://pkg.cloudflare.com/cloudflared $(lsb_release -cs) main" | \
  sudo tee /etc/apt/sources.list.d/cloudflared.list

sudo apt-get update && sudo apt-get install -y cloudflared

Next, authenticate with the token you generated in the dashboard:

sudo cloudflared service install EUREN_TOKEN_HIER

That’s it. The service starts, establishes the tunnel, and appears in your dashboard. Make sure to replace the placeholder EUREN_TOKEN_HIER with your actual token.

Forwarding a Domain to Ollama

Once cloudflared is running, go to your Cloudflare Zero Trust Dashboard, select your tunnel, and create a public hostname. Choose HTTP as the type and enter localhost:11434 as the URL if Ollama is running locally on the same server. If Ollama is in a Docker container, use the container IP or internal Docker name instead, such as http://ollama:11434.

Save the configuration. Within a few seconds, ollama.example.de will be accessible, provided the subdomain already points to Cloudflare via DNS. Cloudflare handles the TLS certificate for you, so you don’t need to manage certificates yourself.

To restrict access, enable Access Rules in the dashboard. This lets you specify which email addresses, IP ranges, or authenticated users can reach the service. For an Ollama instance you use alone, this is highly recommended.

Security and Access Control

While a tunnel doesn’t open inbound ports, it’s not automatically bulletproof. Cloudflare sits between your server and visitors, protecting against many attacks, but you should still take precautions.

Always enable Access Rules so that anyone on the internet can’t stumble upon your Ollama interface. Use strong passwords for your Cloudflare account and enable multi-factor authentication. Configure your local Ollama service to listen only on localhost or internal interfaces. This keeps your home network protected even if a configuration mistake occurs.

Learn more about reverse proxy concepts in Reverse Proxy. To understand encryption better, check out TLS Certificates.

Common Pitfalls

  1. Lost token: Save the token when creating the tunnel somewhere secure. Without it, you’ll need to reinstall the cloudflared service.

  2. Domain not at Cloudflare: The tunnel works most smoothly if your domain is hosted in Cloudflare. External domains require additional steps.

  3. Wrong internal URL: If you enter localhost:11434 but Ollama runs in a container, cloudflared won’t find the service. Use the Docker container name or bridge IP instead.

  4. Cloudflare account limits: The free Zero Trust tier offers many features, but costs kick in with many users or log data. Check before rolling out.

  5. Service won’t start: After cloudflared service install, check with systemctl status cloudflared. Missing permissions or an incorrect token are common culprits.

  6. Ollama blocks external requests: By default, Ollama binds to 127.0.0.1 or 0.0.0.0 depending on configuration. Make sure cloudflared can reach the correct host.

  7. Wrong DNS settings: The public hostname needs a proper DNS zone in Cloudflare. If the CNAME is missing or incorrect, you’ll get DNS errors.

  8. Access without Access Rule: Without an Access Rule, your service is publicly accessible. If that’s unintended, set up at least an email-based rule.

Hardware, Costs, and Security

Cloudflared is very resource-efficient. It runs fine on a Raspberry Pi 4 or small VPS with minimal overhead. When running Ollama simultaneously, you’ll need enough RAM and possibly a GPU depending on the model. For the tunnel alone, any server running Debian or Ubuntu will do.

Costs consist of the domain and optional Cloudflare add-ons. Most basic scenarios fit within the free Zero Trust tier. Locally, you only pay for electricity or hosting. A small VPS often costs just a few euros per month, while a Raspberry Pi in your home network costs only power.

From a security perspective, you significantly reduce your attack surface because no port forwarding is needed. Still, use Cloudflare Access, strong authentication, and clean local Ollama configuration.

Further Reading

FAQ

  1. Is Cloudflare Tunnel free?
    Yes, the free Zero Trust tier covers the core features and many Access Rules.

  2. Do I need a public IP?
    No. Cloudflare initiates the connection outbound. Your public IP remains hidden.

  3. Does this work with Ollama?
    Yes. Simply forward the domain to your local Ollama port. Details are at Ollama Network Access.

  4. Do I need to change anything on my router?
    Usually not. Only outbound connections on ports 443 and 7844 need to be allowed, which is standard.

  5. What’s the difference from a VPN?
    A VPN connects entire networks or devices. A tunnel publishes individual services via a domain.

  6. Is HTTPS included automatically?
    Yes, if your domain is at Cloudflare and set to proxied. Cloudflare handles TLS.

  7. Can I route multiple services through the same tunnel?
    Yes. Simply create multiple public hostnames in the same tunnel.

  8. How secure is this?
    Much safer than port forwarding. With Access Rules, you can restrict access to authorized users only.

  9. Can I run this in Docker?
    Yes. Cloudflared has an official Docker image. Just pass the token volume or environment variable to the container.

  10. What happens if my server goes offline?
    The service becomes unreachable. The tunnel breaks until the client is back online.

  11. Can I tunnel UDP traffic?
    Cloudflare supports UDP, but there are special settings and sometimes limitations.

  12. Do I need to know Linux?
    Basic knowledge is enough. Most steps can be done by copy and paste.

Sources

  • Cloudflare Tunnel Documentation: cloudflare.com/developers
  • cloudflared Repository on GitHub
  • Cloudflare Zero Trust Learning Center
  • Ollama Official Documentation: ollama.com
  • Cloudflare Blog: Zero Trust Network Models
Back to Blog
Share:

Related Posts