ads

Latest Update

recent

Latest Update

random

Cloudflare Tunnel for TrueNAS Access

TrueNAS tutorial · Secure remote access

Cloudflare Tunnel for TrueNAS: Secure Remote Access Without Port Forwarding

A practical TrueNAS tutorial showing how to use Cloudflare Tunnel for remote access without inbound port forwarding, while adding an identity-aware access layer so the administrative interface is not exposed as an ordinary public web service.

Platform TrueNAS SCALE
Remote access Cloudflare Tunnel
Security model Outbound tunnel · Identity-gated access
Environment Personal homelab
Cloudflare Tunnel architecture for TrueNAS remote access
No inbound forwarding The tunnel originates outbound from the homelab
Identity before access Administrative access should be gated by an access policy
One tunnel, many services Additional internal services can be routed deliberately when required
01 · What this guide builds

Remote TrueNAS access without opening an inbound firewall port.

This guide shows how I implemented Cloudflare Tunnel on a TrueNAS SCALE homelab so a selected internal web interface could be reached remotely through a controlled hostname. The tunnel is initiated outbound from the homelab, which means the router does not need a conventional inbound port-forwarding rule for the proxied service.

The tutorial also improves on the common “just publish the NAS dashboard” approach. For an administrative interface, connectivity is only half of the design. The safer pattern is to put Cloudflare Access or another identity-aware control in front of the tunnel so an approved identity is required before traffic reaches TrueNAS.

The example hostnames and internal addresses in this article are sanitized. Do not publish your live TrueNAS management hostname, tunnel credentials, service tokens, or unnecessary internal addressing in a public tutorial.
02 · How the design works

Cloudflare becomes the controlled entry point; TrueNAS remains on the private network.

The original goal was to reach the TrueNAS web interface remotely through a domain name without opening router ports. The revised design adds another requirement: remote access should be restricted by identity before traffic reaches the internal administration service.

Connectivity Use an outbound tunnel from the homelab instead of inbound port forwarding.
DNS Map a controlled hostname to the Cloudflare Tunnel endpoint.
Authorization Require a Cloudflare Access policy or equivalent identity control for administration.
Exposure Keep the TrueNAS management interface private except through the intended access path.
03 · Architecture

The connection starts inside the network.

Remote administrator │ ▼ Cloudflare Access / identity policy │ ▼ Cloudflare edge │ ▼ Cloudflare Tunnel │ outbound connection ▼ TrueNAS homelab │ └── Selected internal administration service

Because `cloudflared` establishes the tunnel outbound, the router does not need a conventional inbound port-forwarding rule for the proxied service. Cloudflare routes approved traffic through the established tunnel to the internal service target.

04 · Before you start

What you need before creating the tunnel.

Domain A domain managed through Cloudflare DNS.
TrueNAS SCALE Running on the local homelab network with the target service reachable internally.
Cloudflare account Used to create the tunnel, DNS route, and access policy.
cloudflared Installed as an application/container or otherwise operated inside the trusted environment.
Identity provider Email OTP, Google, Microsoft, GitHub, or another provider supported by the access policy.
05 · Step-by-step deployment

Create the tunnel, route the hostname, then add identity-aware access.

01
Create the tunnel.

Create a named tunnel in Cloudflare and associate it with the connector running inside the homelab.

02
Install the connector on TrueNAS.

Deploy the Cloudflare Tunnel application/container and provide the tunnel credentials securely.

03
Define the internal service target.

Point the tunnel route to the local TrueNAS administration service or another approved internal application.

04
Create the DNS hostname.

Associate the public hostname with the tunnel route rather than a public IP address.

05
Add an Access policy.

Require an approved identity, group, email domain, or other rule before Cloudflare forwards traffic to the tunnel.

06
Test from outside the LAN.

Verify that unauthorized users are stopped by the access layer and that authorized access reaches the internal service successfully.

06 · Configuration example

The public hostname maps to a private service target.

A locally managed `cloudflared` deployment can use a configuration structure similar to the sanitized example below. Exact paths and management methods vary depending on how the connector is deployed.

tunnel: <tunnel-uuid>
credentials-file: /etc/cloudflared/<tunnel-uuid>.json

ingress:
  - hostname: admin.example.com
    service: https://192.168.x.x:xxxx

  - service: http_status:404
Do not publish the real tunnel UUID, credentials JSON, service token, API token, internal management hostname, or unnecessary internal addressing. Tunnel credentials should be treated as secrets.
07 · Protecting the admin page

Add an authentication layer before exposing the TrueNAS login page.

A tunnel by itself provides connectivity. It does not automatically decide who should be allowed to reach an administrative interface. That authorization decision belongs in Cloudflare Access or another identity-aware control layer.

Allowed identity Restrict access to specific users, groups, or trusted email domains.
MFA Prefer an identity provider and policy that supports multifactor authentication.
Session duration Keep administrative sessions reasonably short rather than issuing very long-lived access.
Default rule Deny users who do not match the explicit allow policy.
08 · Security checklist

No port forwarding does not mean no security work.

Administrative hostname Avoid advertising the live TrueNAS admin hostname publicly.
Origin authentication TrueNAS authentication still matters even when Cloudflare Access sits in front of it.
Cloudflare account Protect the Cloudflare account itself with strong MFA and tightly scoped API tokens.
Tunnel credentials Store connector credentials securely and rotate them if they are exposed.
Origin TLS Prefer HTTPS to the internal service where practical and understand certificate validation behavior.
Least exposure Publish only the specific internal applications that genuinely need remote access.
09 · Testing and next steps

Verify the access controls before using the tunnel for additional services.

After the tunnel is online, test from a network outside your home LAN. An unauthenticated request should be stopped by the access policy, while an approved identity should reach the intended internal service. Also confirm that no direct router port-forwarding rule is exposing the same TrueNAS management service in parallel.

Unauthorized test Confirm an unapproved identity cannot reach the TrueNAS login interface.
Authorized test Confirm an approved user can authenticate through the access layer and reach the service.
Failure test Stop the tunnel connector and verify the public hostname no longer reaches the internal service.
Route review Confirm there is no unnecessary direct WAN port forwarding to the TrueNAS administration interface.

Extending the same pattern

Once the tunnel and identity layer are stable, the same architecture can be reused for selected applications such as Snipe-IT, Immich, or other internal dashboards. Give each service its own hostname and access decision instead of treating every homelab application as equally safe to publish.

No comments:

Please Don't Spam Comment Box !!!!

All Rights Reserved by Bikram Bhujel © 2019 - 2030
Powered By Bikram Bhujel, Designed by Bikram Bhujel
Powered by Blogger.