Cloudflare doesn't really seem to care about their tunnel product. "cloudflared service install broken on macOS" since 2021: https://github.com/cloudflare/cloudflared/issues/327
This is a very good solution for HTTP(S) tunneling - which is the most frequently needed tunnel. However if you want to play a game, or use SSH, then Pinggy tunnels are very simple to use. One command:
ssh -p 443 -R0:localhost:443 [email protected]
Disclosure: Co-founder of pinggy.io here.
Is this their version of https://tailscale.com/tailcat ? I can't tell if you need to auth
edit: yeah, it says no account creation, neat!
Are we in an age where no one even bothers to open the product pages they generate? The first subtitle with the font color almost matching the background. Or it's even worse that a human looked at it and said "yep, that's OK"?
I have been considering using my other laptop as a place to run my agents in production since 1. my laptop is more powerful than the vps I can rent for cheap.
then just use Cloudflare tunnels to connect to the laptop.
For small-scale personal or family applications serving just a few users, does it make sense to choose Quick Tunnels over Tailscale or Pangolin?
Tunneling was something that recently fell out of the work I've been doing [1]. I've used Cloudflare Tunnels before but I just have low trust with them recently with how big they are getting. All of these nice things come at the cost of pushing _a lot_ of traffic through their systems.
There's a number of comments already about how this page looks vibe coded, I'd add that I'm actually shocked at how much this looks like the output of a one-shot prompt. It's not so much that an LLM was used, but a callout on just how generic this page is. How much iteration went into this? At surface it looks like nearly no iteration.
For someone looking for an opensource solutions, following is an awesome resource for tunnelling
https://github.com/anderspitman/awesome-tunneling
I have played around with frp, bore and ngrok.
Can anyone elaborate on what's new? This exact product has existed from Cloudflare for years. Is it just that they added a new marketing site for it?
Historically, we’ve found that their tunnels have really high latency variance. For example something that’s normally 30-50ms to ec2 is now 115ms-750ms
This is my docker compose for sharing files with randoms online https://pastebin.com/raw/cYV7ksw9
Don't pass -d, your tunnel URL prints in the console and you can download dirs as tarball.
hi y'all, ngrok creator/founder here.
we removed anonymous usage of our product many years ago because it was far and away the largest source of abuse on our entire platform.
i believe at this point that that anonymous, account-less tunneling services like this are net negative for the security of the internet
happy to answer any questions from the community
Tailscale is one of the most profoundly useful technologies I’ve ever used as small business person. It’s also one I would have never thought to invent despite feeling its lack daily.
I still remember when ngrok came out. The experience was more or less the same.
It’s interesting that 10 (more?) years later the product has not evolved and, apparently, hasn’t found a way to finance itself without removing the pure free tunneling option.
I made my own tunnel system with a $5/mo vps that runs kernel wireguard and accepts my nas' public key. Once connected it DNATs 80/443 traffic down the tunnel to the nas, where its routed to caddy.
The vps runs a custom image that is 2.54 Megabytes. It has a custom kernel with almost everything but networking and wireguard disabled, a fixed-size fs with pre-allocated blocks and inodes to hold the vps wireguard key, and a single pid 1 binary that calls the kernel directly to set up the routing rules, generate a new wireguard key on first boot and save it to the fs, print out the wireguard public key to the console, and loops reap. Updating involves building and uploading a new image, assigning the vps to use it, reboot, wait for the public key in the console then set it on the nas so they can talk.
Don't all these free proxy services always fall prey to blacklists because scammers,etc abuse them until they're useless?
Needs to support tcp and udp
I quite like pinggy for this. You don't need to install anything, since it uses a plain SSH tunnel.
ssh -p 443 -R0:localhost:9051 free.pinggy.io
(Free for 1h each session)
This has existed for a long time and has been abused by quite a few people. I've seen some cc nodes using a random known cloudflare site and spoofing hostname to a temporary cloudflare site. IMO this should require a login at bare minimum.
My AI discovered this days ago when I wanted to deploy a new vibe coded website (it was to keep score while playing whist and rentz)
Thought it was very cool
What's surprised me, just earlier today I let Codex write a minor PR for simple open-source webapp. I needed HTTPS for testing secured context Web API. (Web Bluetooth)
While testing it locally Codex by itself suggests using CF Tunnels but what's more interesting it actually used the Quick Tunnels.
Coming from days where I get warnings of vibe-coded generated code using deprecated code or older APIs, I must say using something so fresh is quite impressive.
Does this make working with agents in cloud more interesting? Maybe now I can see my changes right away without waiting for the build and deploy? By running the dev server and tunneling from the sandbox giving me a direct url access somehow?
Can someone chime in here?
Worst marketing ever. ngrok had a similar slogan:
something like - "We help you put localhost on the Internet."
What could possibly go wrong?
The page is a fine exemplar of marketing deception. Banner says:
> Free, secure tunnel for everything you are building.
> Preview and ship ideas globally in seconds with Quick Tunnels. Deploy your local application to the Internet with a single command.
Clicking through Explore Cloudflare Tunnel leads us to:
> Looking to expose public applications? This documentation covers Cloudflare Tunnel use cases for private networking and Zero Trust, like VPN replacement and private network access. For publishing public web applications, APIs, and services to the Internet through Cloudflare refer to ...
The main use case: cloud harnesses to access your local network; I highly recommend to run the harness in your local network instead, then you own the session, no tunnel needed.
The other use case for webhooks is ok, but is exactly what ngrok already does since forever with a pretty high free quota.
This is cool. I like it! Also Cloudflare design has stepped up so much over the past 2 years.
Does this have a more generous allowance than ngrok? From what I can read no limits are mentioned
It will be nice if it had persistent URLs and and SDK for desktop applications. It could solve a lot of small issues for a project I am currently busy with.
This is obviously vibe written, and I can't wait to see how quickly it will be shut down after someone uses it in combination with Mullvad to host child pornography.
Mullvad themselves already turned off port forwarding because people were using it to host child pornography. This is like Mullvad's port forwarding, but free.
how long until someone's agent sets up a tunnel for the world to see one's most sensitive, private and embarrassing information or insecure work-in-progress app? granted, for the brew install some massive permissions are needed, so hopefully for those running their agent's in a sandbox, you should be safe.. should be..
Quick Tunnels look great for demos and temporary dev environments. I’d still be hesitant to make them part of a long-lived production setup.
Oh I use this for testing and demos between my phone and computer. Ngrok is fine, probably better off using Tailscale, but it's very easy to just run a quick tunnel with "cloudflared tunnel --url localhost:XXXX".
If your a hobbiest or dev just testing your services, it makes more sense to utilize onion services imho.
It does the exact same thing, except supported by a global network of volunteers around the world.
Sure, you get some latency, but this is actually ideal for testing. You should know how your service operates in non optimal lightning fast conditions.
json output is nice, my agents always had to parse the text output before
What's the difference between this and their previous Cloudflare Tunnels solution?
This is handy, but I wonder how much it will cannibalize their services. I have a simple app deployed on cloudflare for a very niche single purpose use, but I wouldn't have bothered if I had this. Serving it from my own machine would have been fine.
I want this with TOTP or passkeys. Just giving me a hostname doesn't cut it these days.
Ah yes. We can't let self hosted app traffic flow across the Internet in a way that escapes the vast Internet surveillance system run by the Americans called Cloudflare.
Hmm, Tailscale is too convenient and that traffic is going dark from Cloudflare's all seeing eye.
So is this basically a ngrok from CF?
Love this, very cool.
I used to use a service called ngrok for this, but it's nice that Cloudflare is offering one now.
The number of vibe coded apps accidentally hosted on dev laptops is about to explode.
Off-topic: That web page looks exactly like my vibe-coded utilities.
It looks like tunnels can do some non https stuff these days? But it's a bit unclear
Seems like the quality of software engineering is now going to zero and just vibe coding unstable alternatives since 2023.
I like Cloudflare Tunnels a lot, but something that annoys me is that officially you're not allowed to use them for streaming video, meaning I can't put it in front of my Jellyfin without breaking TOS.
I think that rule is more of a "we reserve the right to..." rule, but it makes me sad because I'd rather not open up ports on my router to expose my Jellyfin to my parents.
The website looks broken in dark mode on Firefox.
So it is ngrok 10 years later?
My wife and I have a mobile group/shared bot system where we can make mini apps and collab.
Anything from baby stuff, groceries, shopping, planning, wine tracker app, simple/fun/useful data things, etc…
We have Tailscale on our phones and can instantly and privately see without deployment or anything crazy via our secure VPN.
Think shared Claude Artifacts that don’t live @ Anthropic.
Tried to first do this with Cloudflare Tunnels (because I love Cloudflare), but between the broken dashboard side of Zero Trust and nightmare of Warp… it was basically impossible to setup. I guess that’s all super enterprise, which seems to be very anti-Cloudflare philosophically to not be able to self do things.
Will check out Quick Tunnels but I think it’s missing the bigger integration offerings Tailscale has/does still.