Wow, just last weekend I finally put my pet projects behind Cloudflare (they are hosted at my house). Really the only thing nagging me now is that the port is still technically open, and will respond to anyone who uses it. Yes, the IP is now hidden thanks to Cloudflare, but security through obscurity and all that.
I was going to try to whitelist Cloudflare IPs, but that seems like a rather large list that can change at any time. This tunnel thing seems perfect. Is it as simple as running some daemon on my home network and then closing the ports?