I just got mine working a few months ago on FreeBSD using cloudflared. I paid for a cloudflare DNS and run cloudflared (in a jail, which is optional). Here is a redacted example of my tunnel.yml file (should work similarly on other OS's)
# cat /root/.cloudflared/fbsd0_tunnel.yml
tunnel: <redacted UUID>
credentials-file: /root/.cloudflared/<different UUID>.json
ingress:
# Example of an HTTP request over a Unix socket:
- hostname: <redacted full cloudflare URL, no port appended>
service: http://localhost:8096 #this is where jellyfin would normally run
# Example of a rule responding to traffic with an HTTP status:
- service: http_status:404