Tunnel via Cloudflare to any TCP service
iq.thc.org
iq.thc.org
With this method, you effectively turn Cloudflare into a transport, which enables you to get around the limitation of Cloudflare. Say what if you want to transport UDP packets now (for your Wireguard for example)? Cloudflare don't really support that currently, but now it's achievable (albeit, not the best way).
The software used, both websocat, and gost is there to convert/proxy (non-Cloudflare specific) WebSocket connections to arbitrary TCP/UDP (supported by gost). You need to install them on both end of your endpoint through, to enable full conversion (App TCP client -> websocat/gost client -> [Cloudflare via Websocket] -> websocat/gost server -> App TCP server).
Also, you can use Tor network to do similar things, just with .onion service. Tor only supports TCP proxying (if I remembered it correctly), now you can do UDP too.
Yes, yes...I know..."ORACLE"!? choking sounds But at this point, they're no worse a company than Amazon. I've been very happy with their free tier for my home use. There's a bit of learning curve...just like AWS, but they give you a ton of free stuff, including training.
Used to be a huge proponent, it was a good 4 years of freebies. But this too shall pass.
05:20:09 up 631 days, 23:10, 1 user, load average: 0.01, 0.02, 0.00
on my "Always Free" instance.Here's the link to their documentation on reclamation of idle resources: https://docs.oracle.com/en-us/iaas/Content/FreeTier/freetier...
> Idle Always Free compute instances may be reclaimed by Oracle. Oracle will deem virtual machine and bare metal compute instances as idle if, during a 7-day period, the following are true:
> * CPU utilization for the 95th percentile is less than 15%
> * Network utilization is less than 15%
> * Memory utilization is less than 15% (applies to A1 shapes only)
And here's the email that I get whenever they reclaim an instance:
> Oracle Cloud Infrastructure (OCI) has reclaimed idle Always Free compute resources from Always Free customers by stopping the compute instance(s). Reclaiming idle resources allows OCI to efficiently provide services to Always Free customers. Your account had one or more idle compute instances that have been stopped. You can restart your compute instance as long as the associated compute shape is available in your region. Your Boot and Block Volumes remain unchanged and available to you. In the future, you can keep idle compute instances from being stopped by converting your account to Pay As You Go (PAYG). With PAYG, you will not be charged as long as your usage for all OCI resources remains within the Always Free limits.
Screenshot of my "Always Free" banner in the Oracle web interface: https://imgur.com/a/hTZfkek
In the 3+ years of running 2 instances on OCI, I'm yet to see this.
ssh -R \*:8080:localhost:80 -N root@example.comI've seen too many cloud provider horror stories.
Until you get hacked or attacked and the bandwidth bill skyrockets. I wouldn't risk it.
Cloudflare is bandwidth "included".
Another great use case is for SSH to a server quite some distance away. I find that the latency when using a cloudflare tunnel to SSH on average better than whatever route my ISP would normally take.
Unless I'm missing something here, there's no way Cloudflare is allowing that much traffic through tunnels for free. Is this just setting up the initial plex connection through the tunnel and then going p2p?
I don't have any actual stats, but there appear to be about 10-20 hours a day of remote streaming, mostly at 3Mbps. So we're only looking at 400-800GB on average per month.
Also, you can use Cloudflare unregistered free tunnels just like the article, but using registered tunnels makes it so you don't have to update the Plex url every time you reconnect. I used unregistered tunnels until Cloudflare made tunnels available on free tier accounts with no bandwidth charges.
I havent had any issues with bandwidth but it depends on how much you push through it. Ive seen stories throughout the years of people pushing 30-50TB before getting a temp ban from using cloudflare services. Of course DNS still works but you just cant use their proxy/cdn/tunnels/etc
What's the limit?
https://developers.cloudflare.com/cloudflare-one/application...
I do SSH forwarding just fine with a CF tunnel. No extra services needed.
You sure?
the audience probably feels more comfortable working with technologies that have a "web" prefix and or can be deployed to a shared webhosting account aka cloud
"gofwd" is a cross-platform TCP port forwarder with Duo 2FA and Geographic IP integration. Its use case is to help protect services when using a VPN is not possible. Before a connection is forwarded, the remote IP address is geographically checked against city, region (state), and/or country. Distance (in miles) can also be used. If this condition is satisfied, a Duo 2FA request can then be sent to a mobile device. The connection is only forwarded after Duo has verified the user.
This is bonkers that people so actively discuss this. That's like using 3rd party service to access your bank account.
So the ISP gets access instead of the VPN? All this does is shift trust, not remove it.
I wrote up a quick guide back in early May - seems relevant to this article as one of the newest users couldn't get Cloudflare to work with TCP how he wanted.
https://inlets.dev/blog/2023/05/04/expose-local-tcp-ports.ht...
For other use cases there’s also the programming libraries (only Rust atm, though I was spiking a TypeScript/Node PoC this week) which might provide more flexibility. Personally I’m excited by the idea of being able to move this kind of secure by design connectivity all the way into the application layer though.
https://github.com/efrecon/sshd-cloudflared
It automatically runs a dockerised sshd to access your directory. The sshd is configured using your github's keys to protect access.
And if you’re asking why anyone would even do that, like why use Tunnel at all, then well, many people are behind all kinds of NAT or, like me, on a public IP with my ISP’s stateful firewall preventing anyone from talking to me. CF Tunnel allows you to hide all that in a nice outgoing TCP connection and if your firewall allows that (which it probably does), you’re golden.