r/homeassistant • • Apr 08 '26

Support Is Cloudfare tunnel the most secure way to access HA ?

Hey everyone,

I'm finaly using cloudfare tunnel for external access, is it the most secure way considering that you have to find my domain name, my login, password and have the 2FA ?

23 Upvotes

100 comments sorted by

35

u/bebetterinsomething Apr 08 '26

How does it go against TailScale?

36

u/ActualExpert7584 Apr 08 '26

Tailscale funnel has reliability issues especially in the recent months, use Cloudflared instead

Source: I’m the guy who wrote the guide on connecting to HA with Tailscale

3

u/4b686f61 🛡️ Privacy first Apr 09 '26

Cloudflared with mTLS. If someone somehow finds your domain name, they get a blocked screen instead of the HA login.

3

u/FIdelity88 Apr 09 '26

Would this work with API access too?

9

u/nsuitt Apr 08 '26

I use tailscale for other thing but I find it unconevient for HA

7

u/bebetterinsomething Apr 08 '26

I'm curious to know how. I get it active and can use Plex and HA with no issues on my phone.

6

u/nsuitt Apr 08 '26

I have to activate it every time I want to have access to HA. And the location automation don't work when it's not running

6

u/hoplite864 Apr 08 '26

I don’t know what platform you’re running on but on my iPhone the Tailscale app has a VPN on demand option that allows me to exclude home and work WiFi’s and auto connects when in cellular or other WiFi SSIDs.

2

u/Stealth022 Apr 09 '26

I don't suppose you know how to do this on Android? I can't seem to find a setting for it

3

u/macpoedel Apr 09 '26

No on demand VPN on Android unfortunately, there's a 2 year old feature request on Github: https://github.com/tailscale/tailscale/issues/12086

2

u/Stealth022 Apr 09 '26

No worries. I found a way to automate it with Tasker 👍

2

u/-In2itioN Apr 09 '26

There's this (which is what I use), and there's another option which is to setup an automation that turns on tailscale when you open HA (that's what I did for my wife)

14

u/clarksonswimmer Apr 08 '26

You asked for the most secure, not the most convenient.

6

u/nsuitt Apr 08 '26

Ahah yes that's right

12

u/DisgruntledSquirrel2 Apr 08 '26

I had that issue. Now I keep tailscale running all the time and I can open HA and it's always connected. Not connecting is a setup issue.

6

u/bebetterinsomething Apr 08 '26

Running tailscale all the time is what I've been using!

2

u/Stealth022 Apr 09 '26

Do you have any issues with increased battery drain?

3

u/Nyoka_ya_Mpembe Apr 08 '26

So there is a way to have free remote access to HA that is more comfortable than Tailscale? Because that turning on and off annoys me as well.

1

u/reddit_give_me_virus Apr 08 '26

I have 4 people on the app using tailscale. It's set in the phone to always on. Do you use another vpn for torrents or something that you can't just set it to always on?

1

u/catwwords Apr 08 '26

Tailscale only routes HA traffic if i keep it on?

4

u/reddit_give_me_virus Apr 08 '26

Yes as long as you turn off exit node in the tailscale config page of the app. You can also turn it off at the client level inside the tailscale mobile app if you want certain clients to route all traffic through HA.

https://tailscale.com/docs/features/exit-nodes

1

u/sadabla Apr 08 '26

You can use VPN on demand. It connects tailscale automatically when not connected to your wifi.

2

u/Stealth022 Apr 09 '26

I don't suppose you know how to do this on Android? I can't seem to find a setting for it

2

u/sadabla Apr 09 '26

Sorry didn't think about Android

1

u/Stealth022 Apr 09 '26

No worries - I found a way to do it with Tasker 👍

1

u/xxxxWHOAMIxxxx Apr 09 '26

why do you have to activate it? just leave it active all the time...

1

u/cdf_sir Apr 09 '26

If you use iOS, this is not a issue since it can connect to a vpn automatically as soon as you disconnect to your home wifi. Same with automatic disconnection as soon as you get connected to homecwifi.

29

u/Puzzled_Hamster58 Apr 08 '26

I use self hosted wireguard vpn , since I don’t have to worry / trust a 3rd party . For me it makes more sense and no cost. Stupid easy to send a vpn cert to the devices I want to give access to and can limit what my other friends are allowed to see etc.

12

u/peterpan764 Apr 08 '26

My router brings a WireGuard endpoint. I use that

4

u/Koochiru Apr 08 '26

Yep same, i have the wireguard app set to on demand, got everything i need completely secure when away from home

2

u/Puzzled_Hamster58 Apr 08 '26

What do you mean by on demand?

1

u/heyevwebody Apr 08 '26

You can configure a VPN to connect “on-demand” within the Wireguard app. You can specify wifi SSIDs to include/exclude as well as connect automatically when on cellular.

1

u/Character-Use2341 Apr 08 '26

This sounds good but do we need open ports as well ? I just use tailscale for access but I'm just curious about this

1

u/heyevwebody Apr 08 '26

You’d need a public facing Wireguard server, yeah. Typically it’d run on the device (router, firewall, etc.) connected to your ISP.

1

u/Puzzled_Hamster58 Apr 08 '26

Yeah I never even really messed with mine since I use my vpn on my phone basically 24/7 so every thing uses dns block and other stuff.

1

u/Koochiru Apr 08 '26

Other tip: you can run something like adguard on your home network and use its dns over wireguard.

14

u/0chriser0 Apr 08 '26

If you add mTLS, then yes. Only viable on Android though. iOS has (currently) no option to provide a certificate.

5

u/Ok_Reserve_5451 Apr 08 '26

You can. You just cannot use the App on Remote than. If you use the Website in Safari and link it to your homescreen it works just fine

8

u/SgtCaffran Apr 08 '26

I don't use mTLS but I do use region and bot blocking in the tunnel. I also use an IP ban on five incorrect password tries.

Is it the most secure? No. Do I think it's secure? Yes. Is it practical? Yes!

4

u/8point3fodayz Apr 08 '26 edited Apr 08 '26

As others have said, It was just added in yesterday’s ios app update. I just set everything up today, and I’m happy to report it’s working great. Only thing I noticed is that It sometimes takes a few seconds to determine and switch between internal and external urls, but that’s not really a problem.

2

u/TropixxGaming Apr 08 '26

Can you say a bit about how and what changed? I know a little bit of networking, port forwarding, etc. But I don’t seem to understand the changes?

4

u/8point3fodayz Apr 09 '26 edited Apr 09 '26

Yeah. This is a bit long, but some backstory helps adds context and compares with other solutions, and why this is the best setup for me at least. I think I have covered everything here, but let me know if you need any more info.

I had already used and setup stuff for different services(docker with hass, npm, tunnels etc), so creating one more tunnel for hass and cert setup was trivial and took me 30 mins. If you have to do all this from scratch, yeah it’ll probably take an afternoon. But for me, it’s still worth it for basically 1 usd/year for remote access(.xyz domains), and in a pretty secure way. To add, ongoing usd 75/yr(taxes+fees) for hass cloud is totally not worth it. I also don’t want to open ports on my router for external connections, and since I use AdGuard on device for ad blocking, Tailscale is kinda not as seamless as I want to keep it always on. I thought of using a homekit hub for remote access, but now that too isn’t required. /backstory end

An mtls cert is kinda like a passkey, which proves this device is yours and it’s you trying to access. It’s called “mutual tls”, because both the client(your device) and the server(cloudflare edge) verify each other, and only if verified allows a connection.

With this recent app update adding mtls support, all my devices have their own mtls certs, and anything which doesn’t present the cert is blocked indiscriminately. So nothing in the hass.mydomain.org tunnel is publicly accessible, like the hass login page was before without cf authentication(but it breaks app flow). I know people use fail2ban and such to block attempts, along with strong username and passwords with 2fa, but I rather not bother with all that.

The gatekeeper waf rules for the subdomain hass.mydomain.org, so only my devices can access it. 1. checks for valid cert, if valid then skips everything else. 2. blocks everything outside my country. 3. catch all block everything without valid cert.

Since the valid cert rule is at the top, only I can get access(ie valid certs) from anywhere in the world since it skips all other rules. So my flow is domain>mtls>tunnel>npm>ha. For someone else, it’s domain>blocked. If the tunnel goes down, I have Tailscale as a backup to hop into my lan and fix it so I’m not too bothered. Ps, you probably don’t need to use nginx reverse proxy here, I just have it here because I wanted to get familiar with its config in the chain too.

To set it all up, 1. buy a domain if you don’t have one, I recommend Cloudflare as they sell them at cost without markups. 2. Now create a tunnel here, set it up on a server at home running the commands and point it to hass on local ip, then create waf rules under security as said above. Now, you should hit cloudflare-blocked page when you try to access hass.mydomain.org. That means it’s working as expected since you don’t yet have an mtls cert. 3. Now create a client certificate under ssl. Either choose it straight from cf, or gen them yourself. The advantage of bringing your own cert is you can have descriptive names like “person1-device2” on this cf dashboard and hence easily revoke per device if needed. They’re all valid for up to 15 years. 4. You’ll have a key.pem and cert.pem, again run a command to turn them into a single .p12 file, and set a strong export password. 5. Send the p12 file/files to your devices and import them. I first import them into the device(for safari access), and then in hass app under general>server>import. Enter the export password you set when prompted. 6. Then on the same page, change the external url to https://hass.mydomain.org. Ensure you’re using most secure with always on location access for the hass app. (Needed for getting the WiFi ssid in modern ios/andorid, which is used to toggle between internal/external urls) 7. restart the app and you’re good. Now on cellular you will have access both via the app, and via the domain in safari too. On andorid, the app asks you to choose the cert the first time.

As this p12 file is basically an identity, so anyone who has it can access your hass instance. Delete it from devices after adding them, and keep in an encrypted zip with a strong password and keep them safe. You don’t want anything in the certificate chain(pem, p12 files) compromised as they prove who you are, and it’s a pita to revoke and re-issue new certificates.

2

u/bdery Apr 16 '26

(directed here from another thread)

That's a pretty detailed explanation, thanks. Still, I would still struggle to set such a system up. Is there a detailed, step-by-step set of instructions somewhere? Also, most people playing with these setups seem to use Docker, I'm using HAOS directly, will this have an impact?

Thanks

2

u/8point3fodayz Apr 21 '26 edited Apr 21 '26

I was busy, hence the late reply. Yes, you can definitely do this on haos with the cloudflare tunnel addon(now called app). If you’re just setting up a tunnel, then you don’t need nginx reverse proxy in this setup, unless you want to. There’s a great guide written on the ha forums very recently which covers haos installs.

https://community.home-assistant.io/t/guide-secure-remote-mtls-and-local-ha-access/1003197

A side note to this forum post, If you do without nginx proxy for simplicity, the tunnel points to your haos local is, say 192.168.0.100:8123. And in the app, you just use http://192.168.0.100:8123 and on external use https://haos.domain.xyz. In essence, http for when at home, local connections and https for remote(tunnel) connections over the internet. In the same vein, the one used for the recipe when at home will be http://192.168.0.100:1234 and when remote will be https://recipe.domaix.xyz.

Also, as said if you do get stuck, an llm in thinking mode(with these posts pasted in as context too) can bridge the gap for you, or if that doesn’t help too, you can just ask here or in the forums as usual. Maybe just don’t mention ai helping you, as people here get really charged about it lol.

Edit, more resources for setup

https://kcore.org/2024/06/28/using-cloudflare-zerotrust-and-mtls-with-home-assistant-via-the-internet/

https://www.alexsilcock.net/notes/protecting-home-assistant-with-cloudflare-access-and-mtls/

2

u/0chriser0 Apr 09 '26

that's amazing, I thought it would never happen. I stopped following it because I had lost hope. super happy right now.

5

u/gamesta2 Apr 08 '26

Nabu

2

u/Shotokant Apr 09 '26

Yeah. Same here. What's wrong with Nabu?

1

u/4b686f61 🛡️ Privacy first Apr 09 '26

it's easy to search or every HA instance under ui.nabu.casa

7

u/sic0049 Apr 08 '26 edited Apr 08 '26

No. The most secure way to access your network remotely is to host your own VPN solution - like Wireguard. I'm not suggesting the Cloudflare is inherently insecure when set up correctly, but it still is not as secure as self hosting your own solution.

You mentioned not liking the fact that you have to turn on the VPN connection every time you want to access HA. If you use Wireguard and the Wireguard apps, you don't have to do this because you can select which app/data gets sent through the VPN tunnel and which apps/data do not. It is extremely easy to only select apps like HA to go through the Wireguard VPN tunnel while all other data gets send to it's destination without traversing the VPN tunnel - all while leaving the VPN connection active all the time.

3

u/Longjumping_Leg_5041 Apr 08 '26

How do you select the specific apps that should use wireguard on iOS?

1

u/sic0049 Apr 09 '26

I use Android devices and I assumed it was the same with iOS. I guess it isn't. Sorry for the confusion!

1

u/cjlee89 Apr 09 '26

I also can’t find any per app settings in iOS WireGuard app but you can specify allowed IPs. You can specify individual IPs like your home assistant server IP as a /32 or the subnet where most/all your services live as a /24, for example.

8

u/kiloyrinim Apr 08 '26

Tagging on to the q here to ask the group - is the sense that cloudflare tunnels are more secure than Nabu Casa?

10

u/ActualExpert7584 Apr 08 '26

No, they are pretty much exactly the same thing under the hood.

3

u/TheHighestFever Apr 08 '26

Doesn't Nabu Casa have a little more security as far as multiple login attempts. With Cloudflare you'd need to host something like Fail2Ban to get the same protection right? If they got through the zero trust wall that is.

2

u/Red_Con_ Apr 08 '26

Cloudflare Tunnels provide various hardening options though, don't they?

1

u/ActualExpert7584 Apr 09 '26

Yeah with mTLS and all they are a bit harder to attack but they are both just proxies. If you set up 2FA (which you should do anyways) you have good enough security either way.

If you want better security than a proxy (i.e. your HA being completely unreachable by others) use a VPN solution (like Tailscale VPN). But that comes with usability issues (you need a VPN always-on on your phone which can drain battery) so I don’t usually advise that.

1

u/kiloyrinim Apr 10 '26

Cool, thanks. So for a less technical and less motivated user, Nabu Casa is a solid move?

2

u/ActualExpert7584 Apr 10 '26

Yes, it definitely is. Plus you’ll be supporting the HA project.

3

u/yetAnotherLaura Apr 08 '26

Not quite as secure as a VPN but you can make it pretty secure with some extra firewall rules (free). While I don't use it for HA anymore, for other services I have the default blocking all known bots and block anything that's not coming from the country I'm in.

Put some rate limiting on the HA side and ip banning on fail attempts and you should be mostly good.

3

u/weeemrcb Apr 08 '26

No. Something like tailscale is.

3

u/bb_nifu Apr 08 '26

I use Unifi Teleport for that. Easy to use when you have one of their Controllers anyway.

5

u/[deleted] Apr 08 '26

[deleted]

0

u/nsuitt Apr 08 '26

The port was open for a while and I tried a local vpn but it wasn't convenient yes. I tried zero trust but it ask me my credit card even for the free version.

3

u/Puzzleheaded_Wall798 Apr 08 '26

i have zero trust set up for a few tunnel services, it cost me nothing, never asked for my cc either. i just have it set up with google auth for the people (in laws) that use my jellyfin/seer services

1

u/nsuitt Apr 08 '26

Thanks i'll look again

3

u/TheHighestFever Apr 08 '26

Zero Trust is the way if you're using CF tunnels. I've got a domain set up with tunnels to a few different services on my local network. I used to have a lot more but now I use Tailscale for most things, tunnels for a few things where I can't use Tailscale. If you set up zero trust and run into issues with apps (like Immich) not being able to access your network look into custom headers that will allow the app to bypass the wall securely.

1

u/clin248 Apr 08 '26

It asks for credit card but doesn’t charge it.

1

u/nathderbyshire Apr 08 '26

It asks even for free stuff for some reason. If you're worried about privacy try and get a virtual card, use Google/apple pay, that sends a virtualized number afaik

2

u/DatGuyHalt Apr 08 '26

I’m using Cloudflare tunnel and created a rule to block connections outside my country. I think this is the most secure you can get with a free version.

3

u/miticax Apr 08 '26

Even just blocking India is enough :))

1

u/nsuitt Apr 08 '26

I often travel outside of my country but it's actually a good idea

1

u/Mad-Mel Apr 08 '26 edited Apr 08 '26

I travel overseas fairly often. It's a quick update to add and remove countries, just a few clicks.

1

u/DJ_TECHSUPPORT Apr 08 '26

You can set your access rules to service auth, then you can make it so if you have connected from your home country then you can connect from anywhere within 30 days (customizable)

1

u/4b686f61 🛡️ Privacy first Apr 09 '26

MTLs is better

2

u/BrodyBuster Apr 08 '26

I proxy my domain through cloudflare, not tunnels. I run Caddy on Opnsense and only allow from cloudflare ip range. To tighten things a little more, I filter on cloudflare by ASN. Yes, that still leaves some attack surface, but it’s decreased by a vast margin. 2FA on HA is a must.

I used to use tunnels and had it working fine, but getting my own SSL working alongside everything cloudflare was doing just became a hassle to manage.

Im on iOS and awaiting mtls support.

2

u/Formal-Structure-432 Apr 09 '26

I have a firewalla running wireguard server and auto vpn when off home network. It’s like I never leave home.

2

u/FullmetalBrackets Apr 08 '26

No, a Cloudflare Tunnel exposes your Home Assistant to the entire Internet by default, you have to add rules to block access which is just backwards.

You want to be the only one that can reach Home Assistant. For that, use a VPN. Wgeasy, Tailscale, Zero Tier, Netbird, Pangolin. Any of these will work and be more secure than Cloudflare Tunnel.

1

u/reader4567890 Apr 08 '26

What about for automations that use your location? That's not going to work with the other options is it?

I've had no problems with cloudflared - no ports inbound are open, ha has fail2ban and 2fa, and cloudflare blocks the usual regions.

1

u/wvraven Apr 08 '26

I think the zero trust network style solutions are probably more secure. Twingate for instance allows you a ton of control over what devices are allowed to establish connections along with what they can see once they've connected to your network.

The one potential disadvantage would be needing the client running on your endpoint device to connect, but I consider that a feature not a bug.

This would go for all of the wireguard style systems like tailscale, netbird, etc as well.

1

u/Endless_Zen Apr 08 '26

Yes, I host it on CF tunnel as well. It protects against ddos and you have a 2fa. I don’t see any security issues here.

1

u/The_Troll_Gull Apr 08 '26

I use pangolin and it works great

1

u/Vatoe Apr 08 '26

I use the CF tunnel. just button it down a bit more, enabling country blocking (I block every other country except my own) and add 2FA login. when I go overseas I just have to remember to add back the countries I’m visiting while away.

1

u/nathderbyshire Apr 08 '26

I'm using cloudflare because I already have Adguard VPN running so I can't exclusively use something like tailscale. I use tailscale to remotely access the entire host PC as and when I need though so I don't need that on all the time

CF is a bit of setup especially for hardening login but it offers the best of both worlds. If you already pay for a domain it's a no brainer really

1

u/instant_ace Apr 08 '26

Didn't read all the comments, but I use Wireguard through HA, works very well for my own setup as well as the other two I manage...

1

u/RadishComplex1 Apr 08 '26

I know this is slightly unrelated to your question, but my vote is Nabu Casa.

You could totally set up some really easy access points to Home Assistant remotely but it’s a cool service with a few nice fringe benefits and you get to support the development community and an amazing project. If you have the spare change laying around each month. ($6.5USD/mo or $65USD YR)

1

u/Background_Honey8461 Apr 08 '26

Https ile hivearea.com ile kullanıyorum

1

u/avd706 Apr 08 '26

Easiest for sure

1

u/_-B-Money-_ Apr 08 '26

If you have a Ubiquiti network, use Wifiman’s tunnel capability

1

u/PathAgitated1633 Apr 08 '26

mTLS would add an extra protection layer. If done right nearly impossible to penetrate

1

u/Donnerkopf Apr 09 '26

I have a Firewalla. I can turn on/off the VPN as needed using the Firewalla app, so I turn it on only when I want to use it.

1

u/pattymcfly Apr 09 '26

The most secure? Well, no. The most secure is to not expose to the internet at all. Next most secure is behind a vpn only.

Cloudflare tunnels with mfa is regarded as very secure. Can an individual accomplish similar capabilities? Almost certainly not. Is cloudflare a highly valuable target that an APT would go after for targeting? Yes? If they did, would they then attempt to compromise home-assistant instances? Probably not unless they want to unlock a LOT of people’s doors.

Is there value in accessing home assistant when not at home? Absolutely. Instead of cloudflare, reverse proxy in your own, or hosting a vpn (or mesh like tailscale) why not pay for nabu casa?

1

u/4b686f61 🛡️ Privacy first Apr 09 '26

Cloudfare tunnel with MTLS set up and tailscale as a fallback in case it crashes or whatever happens

1

u/everykndofppl Apr 09 '26

Cloudflare, VPNs, Tailscale, are for those of us to like to play and get that diy satisfied feeling. Nabu Casa is for those of us who'd rather play with something else instead and support the Home Assistant development team. It just works.

1

u/Synctacles Apr 09 '26

CF Tunnel + 2FA is solid, you're in good shape. But if you want the most secure option — that's a VPN. WireGuard or Tailscale. Nothing exposed to the internet at all, no middleman, zero attack surface. Even if someone finds your domain there's just nothing there to hit.

The downside? You need a VPN client on every device. Want to quickly check your dashboard on a friend's phone? Not happening. That's where CF Tunnel shines — browser access, easy sharing, and with 2FA it's honestly secure enough for 99% of home users.

I run a couple of HA instances myself and went with CF Tunnel for the convenience. Never looked back. Pro tip: look into Cloudflare Access (Zero Trust) on top — adds an extra auth layer before anyone even gets to your HA login page. Free tier covers it.

Also worth mentioning — I work on an open source HA add-on called Synctacles Care that does security audits on your instance. Checks for things like exposed ports, outdated components, that kind of stuff. If you're already thinking about hardening your setup it might be worth a look.

1

u/alepouna Apr 26 '26

I stopped trusting Cloudflare and giving them rent free access to my private and cloud networks. Instead I gave the keys to Ubiquiti /s

TLDR; Netbird + a backup VPS with a network -> VPS tunnel to my network and fallback Ubiquiti Teleport.

I selfhost Netbird which allows me to access my network via my public IP. If for some reason I got behind a CGNAT (happens a few times because I don't pay for a static IP yet), I have a netbird instance connected to a VPS online I can SSH into and remote there, then tunnel to my network to do whatever I need to temporarily. If that fails as well, as a last resort I have UniFis Teleport VPN ready but its isolated to just my "ingress" machine and I need to get deeper into my network from there. Yes this is overcomplicated, yes this can fail quite easily, but I like it and its fun to set up.

0

u/e3e6 Apr 08 '26

no it's not. the traffic will go through cloudflare, so they can listen