May 21, 2026
•
16 min read
What `cloudflared` Actually Does
A tunnel-based ingress that opens zero inbound ports is not 'nginx with less work.' It is a different architectural class with different failure modes and different security guarantees. Here is what the daemon is actually doing, operating two of them on a single VPS, and what I learned from the hours where the difference mattered.
cloudflare
quic
networking
infrastructure
security