I just set this up with the help of a couple AI's. I am on 5G internet so it seemed like the right way to go. I also created this feature request with chatgpt. Lmk what you think: "It would be great to have Cloudflare Tunnel / cloudflared available as an official SparkBox app. My use case is exposing Jellyfin through a Cloudflare Tunnel without opening ports on my router: Internet ↓ Cloudflare ↓ cloudflared ↓ sb-npm ↓ sb-jellyfin-media For example, I currently have: media.(redacted).com routed through a Cloudflare Tunnel to: http://sb-npm:80 Since cloudflared is currently a manually-created Docker container, it doesn't appear in the SparkBox dashboard or get managed alongside the other apps. Having it as an official app would allow SparkBox to handle: - Installation - Starting/stopping/restarting - Container updates - Logs/status - Cloudflare Tunnel token configuration - Attaching it to the existing sbproxy network - Reboot persistence Ideally, the app could provide a simple setup where the user enters their Cloudflare Tunnel token and configures the hostname and internal service. Cloudflare Tunnel would be especially useful for users who are behind CGNAT or don't want to expose ports 80/443 directly to the Internet. I think cloudflared would be a useful addition to SparkBox because it works very well with the existing NPM/reverse-proxy architecture."
7 replies
Chris wrote:
Update on this one — it shipped today. Cloudflare Tunnel is a first-class SparkBox app as of v1.6.577: run sudo sparkbox update (or tap Update on the dashboard), enable Cloudflare Tunnel under Apps, and paste the tunnel token from your Cloudflare Zero Trust page. Your hostnames keep living in your Cloudflare account exactly like your hand-rolled setup — point them at container names, so http://sb-jellyfin:8096 for your Jellyfin route, or sb-npm:80 if you would rather keep going through the proxy. Once the SparkBox card shows healthy you can just stop your hand-made cloudflared container — same token, so nothing else changes. Short guide with a publish-your-first-app walkthrough: tomsparkbox.com/guides/cloudflared-setup.html — including a note on putting Cloudflare Access in front of anything admin-ish before you publish it. Thanks for the push on this one — everyone stuck behind CGNAT just got a way in.
Chris wrote:
Good idea, xionide — and the cloudflared container you already got running by hand is exactly the shape this would take. Cloudflare Tunnel is the right call on a 5G connection where you can't open ports, so it fits the box really well. I've logged this for Tom as a proper app request: install, updates, logs, and the tunnel token handled in the dashboard like every other app. I can't promise a date, but it's on his list now with your write-up attached. Thanks for laying the setup out so clearly.
xionide wrote:
WOW amazing turnaround. Thanks!
Chris wrote:
Good news — this already exists, so no need to hand-run that container. Cloudflare Tunnel shipped as a first-class SparkBox app. Enable it with: sudo sparkbox enable cloudflared Then in the dashboard's Cloudflare Tunnel card, paste your tunnel token (from Cloudflare's Zero Trust → Networks → Tunnels) and save. Hostnames like media.your-domain.com → http://sb-jellyfin:8096 are set in Cloudflare, not SparkBox. If the card shows unhealthy for a moment, give it ~30 seconds — it's just dialing Cloudflare.
mrga wrote:
I am trying to do it , that from Cloudflare's Zero Trust → Networks → Tunnels) and save doesnt exist ... now there is tunnels & mesh .. and inside we have Tunnel IT and Connector ID ... what do we use ?
Chris wrote:
The current Cloudflare screen has renamed the route. From Cloudflare’s main dashboard choose Networking → Tunnels, then create or open a Cloudflared tunnel. SparkBox needs the long tunnel token (it starts with eyJ), not the Tunnel ID or Connector ID. Paste that token only into Apps → Cloudflare Tunnel on your own SparkBox dashboard—please do not post it here. Once the connector is healthy, add the Jellyfin hostname under that tunnel’s Hostname routes, using HTTP with sb-jellyfin-media:8096 as the service.
Anthony wrote:
Hi xionide — checking whether the revised Cloudflare navigation helped you find the tunnel token. If the connector is not healthy, reply with its non-sensitive status only; please do not post the token, Tunnel ID, or Connector ID. — Anthony, AI Senior Support