Cloudflare Quick Tunnels
118 points by jcbhmr 3 hours ago | 70 comments

kincl 2 hours ago
Is this their version of https://tailscale.com/tailcat ? I can't tell if you need to auth

edit: yeah, it says no account creation, neat!

reply
Tepix 9 minutes ago
I believe with tailscale you don’t have to trust a 3rd party with your cleartext traffic
reply
hermanradtke 2 hours ago
feels more like an ngrok competitor
reply
israrkhan 26 minutes ago
This is a crowded space with lots of solutions (oss and commercial)

https://github.com/anderspitman/awesome-tunneling

reply
alasano 26 minutes ago
More like their version of Tailscale funnel I think
reply
dangoodmanUT 2 hours ago
Historically, we’ve found that their tunnels have really high latency variance. For example something that’s normally 30-50ms to ec2 is now 115ms-750ms
reply
israrkhan 27 minutes ago
For someone looking for an opensource solutions, following is an awesome resource for tunnelling

https://github.com/anderspitman/awesome-tunneling

I have played around with frp, bore and ngrok.

reply
aliasxneo 2 hours ago
Tunneling was something that recently fell out of the work I've been doing [1]. I've used Cloudflare Tunnels before but I just have low trust with them recently with how big they are getting. All of these nice things come at the cost of pushing _a lot_ of traffic through their systems.

[1]: https://dntls.substack.com/p/the-new-internet

reply
pstoll 13 minutes ago
Reality check - you are not pushing “_a lot_” of traffic relative to any hyperscaler or large scale CDN. They push hundreds of Tbps sustained. You don’t peak at a few Mbps.

They can monitor extreme outliers. It’s not an issue for them.

reply
aliasxneo 58 seconds ago
In hindsight, that was probably a confusing sentence. I was more pointing out how much traffic flows trough their systems which ends up making it an attractive honeypot, especially as a U.S. company.
reply
ijustlovemath 4 minutes ago
I think they're talking about market capture risks
reply
simonw 32 minutes ago
If there's any company in the world that can survive a lot of extra traffic being pushed through their systems it's Cloudflare.

I bet these new tunnels end up being a fraction of a percentage point of their network traffic.

reply
aliasxneo 30 minutes ago
Yeah, I don't doubt their infrastructure at all. In fact, I rate them fairly high in terms of reliability and performance. I've honestly been a fan of them for a very long time - it's just I'm watching all of this centralization happen and it sets my Spidey sense off. Like I'm waiting for the other shoe to drop.
reply
ceejayoz 23 minutes ago
I didn't take it as a capacity concern, but a "how much data do they get to look at" one.
reply
bix6 23 minutes ago
It’s a concentration of power issue.
reply
Tepix 11 minutes ago
They see all the traffic in cleartext. Plus you have to trust them not to maliciously alter your traffic. As a US company, their options may be limited if they are coerced by their government to do so.
reply
insanitybit 9 minutes ago
Just use TLS / mTLS over the tunnel, no?
reply
eli 26 minutes ago
Don’t the free tunnels have explicit limits on bandwidth and streaming?
reply
inopinatus 9 minutes ago
Cloudflare want you to push traffic through their systems. This is yet another traffic generator to drive up Cloudflare’s leverage when negotiating peering with carriers & service providers, in order to drive down the marginal cost of bandwidth for Cloudflare’s actual product viz. the enterprise DDoS protection.

Anyone familiar with The Peering Playbook will recognise what's going on here.

reply
afzalive 42 minutes ago
This is pretty great and I think this will be quite important in the age where everyone has their self-hosted services.
reply
whizzter 2 hours ago
Don't all these free proxy services always fall prey to blacklists because scammers,etc abuse them until they're useless?
reply
axus 52 minutes ago
Wow, exfiltrating data has never been easier!
reply
Imustaskforhelp 59 minutes ago
Yes they actually do, but because its cloudflare which is offering this, blacklisting it might lead to blacklisting can be more negative and cloudflare has a much higher incentive to not make these tunnels useless. They are also more powerful and can fix things which would be harder for smaller companies to handle (atleast within the context of cloudflare tunnels)
reply
himata4113 43 minutes ago
This has existed for a long time and has been abused by quite a few people. I've seen some cc nodes using a random known cloudflare site and spoofing hostname to a temporary cloudflare site. IMO this should require a login at bare minimum.
reply
booi 2 minutes ago
if you think people won't abuse it because you're making them log in with a free email address...
reply
rplnt 31 minutes ago
Are we in an age where no one even bothers to open the product pages they generate? The first subtitle with the font color almost matching the background. Or it's even worse that a human looked at it and said "yep, that's OK"?
reply
lkbm 27 minutes ago
It's fine on light mode. It's just the dark mode that's terrible. Seems likely they only tested the former.
reply
rplnt 20 minutes ago
I see, good point. Some might be confused about my comment then.
reply
reaperducer 29 minutes ago
Are we in an age where no one even bothers to open the product pages they generate?

We live in an age of monkey-see-monkey-do management.

When Microsoft axed its QA team, it gave permission for everyone else to make the same stupid mistake.

reply
singpolyma3 10 minutes ago
It looks like tunnels can do some non https stuff these days? But it's a bit unclear
reply
ggg011012 16 minutes ago
Quick Tunnels look great for demos and temporary dev environments. I’d still be hesitant to make them part of a long-lived production setup.
reply
pstoll 6 minutes ago
You should be more than hesitant - don’t do it. They literally market them for quick demos. And not long lived production.
reply
JV00 2 hours ago
Does this have a more generous allowance than ngrok? From what I can read no limits are mentioned
reply
raahelb 2 minutes ago
These are the limitations mentioned on the docs [1]. Quick Tunnels are subject to a hard limit on the number of concurrent requests that can be proxied at any point in time. Currently, this limit is 200 in-flight requests. If a Quick Tunnel hits this limit, the HTTP response will return a 429 status code. Quick Tunnels do not support Server-Sent Events (SSE).

[1]: https://developers.cloudflare.com/cloudflare-one/networks/co...

reply
daemonologist 58 minutes ago
I don't know if there's an overall limit, but their regular tunnels have a limit of 100 MB per request which breaks stuff like Immich.
reply
kelvinjps10 15 minutes ago
What's the difference between this and their previous Cloudflare Tunnels solution?
reply
Narciss 52 minutes ago
My AI discovered this days ago when I wanted to deploy a new vibe coded website (it was to keep score while playing whist and rentz)

Thought it was very cool

reply
smalltorch 49 minutes ago
If your a hobbiest or dev just testing your services, it makes more sense to utilize onion services imho.

It does the exact same thing, except supported by a global network of volunteers around the world.

Sure, you get some latency, but this is actually ideal for testing. You should know how your service operates in non optimal lightning fast conditions.

reply
thenewnewguy 42 minutes ago
I honestly can't tell if you're trolling or this is an HN out of touch moment.

The obvious difference (and thus massive advantage) of the cloudfare product is that it is accessible over the normal internet without needing to install a tor client.

I'm sure that works for some subset of the population where all potential users are already comfortable using Tor; but imagine trying to share your PoC website with the designer/client and you are asking them to install Tor browser.

reply
smalltorch 29 minutes ago
>hobbiest or dev just testing your services

Is different than sharing your work with a client.

I personally wouldnt make it SOP to utilize a complely free service like this to share my work. I'm not saying it's not convient, it definitely is.

But you shouldn't subject a clients product to terms they probably aren't aware of.

reply
ZeroCool2u 2 hours ago
This is handy, but I wonder how much it will cannibalize their services. I have a simple app deployed on cloudflare for a very niche single purpose use, but I wouldn't have bothered if I had this. Serving it from my own machine would have been fine.
reply
danserfaty 28 minutes ago
Maybe it's a nice way to quickly test a new service or change over the internet without going through the git process, same way one would use ngrok - I could see that being helpful when prototyping / pocs, etc - before deploying changes to your app via the proper channel, especially if you are already using cloudflare for your domains/apps. As other people said, it probably would not be practical or scalable for most people to run an app 24/7 from their laptop using their home or office internet connection.
reply
aniviacat 59 minutes ago
Cloudflare Tunnels has been a free service of Cloudflare for quite a while now. What's new is being able to use them without needing an account.
reply
bakugo 53 minutes ago
It's not new. Maybe this page is new, but being able to set up a quick tunnel on trycloudflare.com without an account has been a thing for years.
reply
roncesvalles 51 minutes ago
Not many people run their local machine 24/7.
reply
berofeev 36 minutes ago
What does reality look like on this nowadays?

My initial thought was desktops generally run 24/7, with laptops running when in use. At least for the customer at the market intersection for this type of product.

reply
JavierFlores09 9 minutes ago
I often tell my dev colleagues to avoid having their PC turned on all the time, be it because of the electricity bill cost, environmental impact or simply to make the longevity of the hardware a little longer. Granted almost everyone just ignores those things even if they're conscious of it, so I'd say you're right
reply
sophacles 11 minutes ago
There are people who turn off their computer?
reply
damsta 25 minutes ago
The website looks broken in dark mode on Firefox.
reply
smalltorch 2 hours ago
It's a nice ability, but I dont like the terms of use.
reply
ZeroCool2u 2 hours ago
Anything specific to watch out for?
reply
whizzter 2 hours ago
On what url were those? Or Cloudflare's TOS in general ?
reply
tombert 31 minutes ago
I like Cloudflare Tunnels a lot, but something that annoys me is that officially you're not allowed to use them for streaming video, meaning I can't put it in front of my Jellyfin without breaking TOS.

I think that rule is more of a "we reserve the right to..." rule, but it makes me sad because I'd rather not open up ports on my router to expose my Jellyfin to my parents.

reply
bityard 10 minutes ago
Bandwidth costs money and streaming video costs several orders of magnitude more than just your random web/dev apps. Asking CF to foot the bill for entertainment streaming is really quite a lot.
reply
tombert 7 minutes ago
I know. I'm not "upset" over it, just that it makes the service less useful for me.
reply
TonyStr 23 minutes ago
I discovered and set this up the other day, added jellyfin, immich and forgejo and was really happy about the result for five minutes, before I discovered that limitation in the TOS. Now I only use it for forgejo. Have you found a different solution to exposing jellyfin?
reply
madeforhnyo 13 minutes ago
For free idk, I personally use a VPS (with unlimited traffic) and Tailscale. Someone has to pay for the public IP and proxy.
reply
tombert 16 minutes ago
I have a proxy set up with the Oracle Always Free VMs they provide. It works well enough.
reply
tamimio 13 minutes ago
Use pangolin (you can self host), been using it for a while and it’s great, under the hood it’s a vpn+reverse proxy which you can do yourself too. In pangolin you can have public or private resources, where private ones you need to authenticate through pangolin first (either pass or others like pin number for your parents so easy to remember). When you link your domain for public ones, I suggest you make a sub domain for it, so your apps will be a sub to your subdomain, that way you keep control of your main domain while having automatic assignment for your apps rather than manually, and if you didn’t issue a certificate, that sub.subdomain is basically invisible on the internet unless you host a service to expose it.
reply
xeornet 33 minutes ago
Looks like they straight up vibe coded the landing page lol.
reply
rozab 27 minutes ago
I find it quite shocking that orgs with some great designers like cloudflare are doing this. Broken layouts, trios of random uppercase words sprinkled around. It's crazy. How does it inspire confidence in a product, knowing that the landing page was created in 10 seconds?
reply
user3939382 2 hours ago
I just spent a week writing a harness around the existing tunnels to make this by hand.
reply
075326899532 30 minutes ago
[ad]
reply
ThrowawayTestr 2 hours ago
No-ip gives out free dynamic DNS with a static URL. I use it for Sunshine desktop streaming when I travel.
reply
cuu508 60 minutes ago
Yeah, but then you are always exposing your public IP.
reply
monster_truck 45 minutes ago
Exposing it to what exactly? The internet? Yes that's how it works
reply
johng 20 minutes ago
This requires no port forwarding, so someone brute force scanning your IP won't find this and your open port. they also might have a harder time figuring out what service has been exposed since the port number itself will be unknown.
reply
cute_boi 34 minutes ago
what a sloppy website, did cloudflare fired bunch of ui/ux designer? Every text is slop lol.
reply
altmanaltman 2 hours ago
Claude worked overtime on this webpage
reply