← Back to blog

Giving back: a public service without opening the whole lab

October 3, 2026

Networking is where my engineering journey began, so publishing a homelab service makes me ask two questions: how does traffic reach it, and what can that machine reach afterward?

The Cloudflare tunnel example makes those questions concrete. An outbound connector reaches Cloudflare, and a small web service listens on loopback behind it. This can be useful where inbound port forwarding is unavailable, including some CGNAT situations, provided the connector has the required outbound connectivity.

A tunnel is a traffic path

The example separates tunnel bootstrap from DNS configuration. A helper creates the locally managed tunnel and stores protected credential material outside the checkout. Terraform manages the DNS record using identifiers. That avoids treating a tunnel secret as an ordinary committed input, but Terraform state and metadata still deserve protection.

A tunnel does not automatically isolate a machine from the rest of the LAN. The DMZ needs its own routing and firewall policy. Review IPv4 and IPv6 behavior, administrative access, and permitted egress. Adding a second interface into a trusted network can undo the boundary you intended to create.

Publish only the intended service

The local service should be reachable on the address and port the connector expects. Confirm the actual public hostname reaches that service, then check that unrelated administrative services remain private. Do not infer that a public request is authenticated just because it used a tunnel; authentication and application authorization are separate choices.

Keep the connector's credentials out of Git and job logs. On either a GitHub or GitLab delivery path, the runner executes the change and needs appropriate network access and a narrow identity. The series guide explains those separate paths.

This lab lets readers practice a useful distinction from network engineering: exposure, routing, isolation, and identity are related, but each needs its own evidence. That remains true whether the backend is a simple web page or an AI application.