Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What's the benefit of Cloudflare Tunnel over just using Wireguard?


Same question from me too - I do have a few services on my homelab at home - stuff like a NAS, synology surveillance, homeassistant, few lxc containers hosting random services on Proxmox - and it all works just fine for my needs with standard WireGuard vpn setup on all my devices (macbook/ipad/iphone/android). What would cloudflare tunnel get me?


It's free and simple and handles HTTPS termination and can be set up easily using terraform/pulumi.

Interestingly, in the early hours of this morning I switched from Cloudflare Tunnels to a rathole/traefik based solution (well, currently it's port forwarding and a low grade home-baked dyndns solution until I get paid and can afford a cheap hetzner box because I spent all of my money again).

I switched back because I didn't like the added complexity of having to manage the routes, what I'm using it for is technically against ToS, and I like the self-contained nature of my microk8s cluster.


> handles HTTPS termination

I understand a lot of people run services locally for other reasons, but HTTPS termination defeats any privacy argument.

Cloudflare are essentially the largest MitM data collector in the world. A few people started moving their data out of the cloud and they saw the gap. Now they're plugging that gap "for free".


I use them for different purposes. The wiki I linked there is exposed via `cloudflared`. Its purpose is to be public. I can't see myself using Wireguard for that.


I just add Yggdrasil to all my nodes. Removes the need to deal with nginx also.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: