Securing Proxmox VE with Cloudflare Tunnel: A Zero Trust Approach
·501 words·3 mins·
loading
In my previous post, we set up Proxmox VE on a Hetzner dedicated server. While the installation is complete, accessing the Proxmox dashboard usually involves opening port 8006 to the public internet or using a VPN. A more modern and secure approach is to use Cloudflare Tunnels (Cloudflared). This allows you to access your dashboard via a nice hostname (e.g., proxmox.yourdomain.com) without opening any inbound ports on your server.
Why Cloudflare Tunnels? # No Inbound Ports: You can keep your firewall completely closed to the public internet. Identity-Based Access: You can add Cloudflare Access rules (SSO, 2FA) in front of your Proxmox login. Automated SSL: Cloudflare handles the SSL/TLS certificates automatically. 1. Prerequisites # A Proxmox VE server (see the installation guide). A domain managed by Cloudflare. A Cloudflare Zero Trust account (Free tier is fine). 2. Setting Up the Tunnel in Cloudflare Dashboard # Log in to the Cloudflare Dashboard. Navigate to Zero Trust > Networks > Tunnels. Click Create a tunnel and name it (e.g., proxmox-hetzner). Select Cloudflared as the connector. Choose your environment (e.g., Debian 64-bit). 3. Installing Cloudflared on Proxmox # Back in your Proxmox terminal, follow these steps to install the agent: