Zero Trust Infrastructure with Cloudflare Tunnel and Home Lab

Zero Trust Infrastructure with Cloudflare Tunnel and Home Lab
234 views(1 unique)
7 min read
📝
Summary: Running production Spring Boot services on a home Ubuntu server via Cloudflare Tunnel — Zero Trust networking, SSL certificates, and the IPv6 Google OAuth fix.

Introduction

Running production workloads on a home server sounds reckless — until you understand Cloudflare Tunnel. The tunnel establishes an outbound-only encrypted connection from your server to Cloudflare's global edge, exposing services publicly without opening any inbound firewall ports. This is Zero Trust networking made accessible to solo developers.

Architecture Overview

The YourOrg platform runs across two environments:

  • AWS EC2 (t3.small) — Angular micro-frontends served by nginx
  • Home Ubuntu server (myserver) — Spring Boot auth server + myapp API, exposed via Cloudflare Tunnel

Cloudflare sits in front of both, providing SSL termination, DDoS protection, and a unified domain (example.com).

Cloudflare Tunnel Setup

Install cloudflared and authenticate:

curl -L https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb -o cloudflared.deb
sudo dpkg -i cloudflared.deb
cloudflared tunnel login
cloudflared tunnel create my-tunnel

Configure ingress rules in config.yml:

tunnel: YOUR-TUNNEL-ID
credentials-file: /etc/cloudflared/tunnel.json

ingress:
  - hostname: auth.example.com
    service: http://localhost:9000
  - hostname: api.example.com
    service: http://localhost:8080
  - service: http_status:404

The IPv6 Token Exchange Problem

A subtle issue: Java's HTTP client resolves oauth2.googleapis.com to an IPv4 address that AT&T silently blocks for outbound port 443. The fix is to pin the IPv6 address in /etc/hosts:

2607:f8b0:XXXX:XXXX::5f oauth2.googleapis.com
2607:f8b0:XXXX:XXXX::5f www.googleapis.com

Now Java's HTTP client resolves to IPv6, which routes through AT&T's IPv6 path without restriction.

SSL Certificate Chain

A Sectigo wildcard certificate (*.example.com) covers both environments. The chain order matters:

  1. STAR_example_com.crt — domain cert
  2. SSL2BUYEMEARSADomainValidationSecureServerCA.crt — intermediate 1
  3. SectigoPublicServerAuthenticationRootR46.crt — intermediate 2

Build the fullchain: cat cert.crt intermediate1.crt intermediate2.crt > fullchain.crt

Cloudflare SSL Mode

With a real cert on the origin server, set Cloudflare SSL to Full (Strict). This validates the origin certificate, preventing man-in-the-middle attacks between Cloudflare and your server. Flexible mode (no origin cert) should only be used during initial setup.

Conclusion

Cloudflare Tunnel + a home server is a legitimate production architecture for personal projects and small SaaS products. The monthly cost is near zero, the security posture is strong, and the operational complexity is lower than managing EC2 instances for every service.

Discussions

No discussions yet. Be the first to start one.

M

Murali Gavarasana

Writer on Ullek

0 articles
0 followers
Writer on the Ullek platform.