Allow tunnel to ssh ports - #178
Closed
lalyos wants to merge 1 commit into
Closed
Conversation
Author
|
In case somebody want to test it, I've pushed my image to dockerhub. Where |
Owner
|
Closing in favor of a fresh implementation: the idea is right (non-HTTP protocols like ssh/tcp must not carry a path in the tunnel rule), but this branch predates large changes to transform.go and only handles ssh. We are landing a generalized version that omits Path for all non-http(s) backend protocols, with tests — credit to this PR for identifying the issue. Thanks @lalyos! |
STRRL
added a commit
that referenced
this pull request
Jul 19, 2026
Path based routing only exists for http(s) in cloudflare tunnel ingress rules. For backend protocols like ssh, rdp or tcp the Ingress spec still requires a dummy http path entry, which previously leaked into the tunnel rule and broke the tunnel for those protocols. Supersedes #178, credit to @lalyos for identifying the issue.
STRRL
added a commit
that referenced
this pull request
Jul 19, 2026
* fix: omit tunnel rule path for non http backend protocols Path based routing only exists for http(s) in cloudflare tunnel ingress rules. For backend protocols like ssh, rdp or tcp the Ingress spec still requires a dummy http path entry, which previously leaked into the tunnel rule and broke the tunnel for those protocols. Supersedes #178, credit to @lalyos for identifying the issue. * test: add e2e coverage for tcp exposure through the tunnel Deploys redis, exposes it with the backend-protocol tcp annotation and performs a real PING round trip from the test runner through cloudflared access tcp, the Cloudflare edge and the tunnel. Before the path fix the tcp rule carried a path and this data path did not work.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I wondered if its possible to expose both http and ssh ports of a pod.
In my case I deployed gitea which has both.
After making the tunnel work by manually changing the tunnel configuration, I figgured what was missing:
pathmake sensetcp) type it shouldn't be setWith a simple check I made the controller successfully expose my gitea ssh service via a cloudflare tunnel.
Example
Here is an ingress with all details:
I was using the official helm chart to deploy gitea, and first the svc had a couple of issue:
The final relevant chart values to fix the service:
The content of
values-gitea.yaml