Overview
DockFlare is a self-hosted control plane for Cloudflare Tunnel. It watches your Docker containers and automatically creates the tunnel ingress rules, DNS records, and Cloudflare Access applications needed to publish them — so a container goes from running to a secure public URL without touching the Cloudflare dashboard.
It works by reconciliation: you declare what you want with Docker labels or rules in its web UI, and DockFlare keeps Cloudflare’s configuration in sync, correcting drift over time.
Key Features
- Automatic service discovery from Docker labels
- Tunnel ingress orchestration, including advanced origin options
- DNS management with zone-aware record placement
- Cloudflare Access integration: create Access applications, reusable policies, and groups
- Manual rules for workloads that don’t run in Docker, or a hybrid of both
- Multi-host mode: a master plus lightweight agents on other servers, secured with Zero Trust service tokens
- Optional email suite built on Cloudflare Email Routing and R2, with an installable webmail client
- Encrypted backup and restore of configuration and state
- Web UI in 13 languages
How It Works
- Collects the desired state from container labels, manual rules, and remote agents.
- Compares it with its stored state and with Cloudflare.
- Applies the differences to tunnel ingress, DNS, and Access.
- Keeps the managed
cloudflaredconnector aligned.
Getting Started
You need Docker and Docker Compose, a Cloudflare account, your account and zone IDs, and an API token with Tunnel, DNS, and Access permissions. The installer script walks you through setup interactively; you can also use the Docker Compose stack described in the project’s documentation.
Then expose a service by adding labels to it:
services:
internal-tool:
image: nginx:latest
labels:
- "dockflare.enable=true"
- "dockflare.hostname=tool.example.com"
- "dockflare.service=http://internal-tool:80"
- "dockflare.access.policy=authenticate"
- "[email protected]"
DockFlare creates the public hostname, routes it through your tunnel, and puts it behind Cloudflare Access.
Use Cases
- Homelabs publishing self-hosted apps securely without opening router ports
- Small teams running internal tools behind single sign-on
- Multi-server Docker setups that need one place to manage ingress and access