← Back to all guides

Your address with Cloudflare Tunnel

MarkdownOpen in ClaudeOpen in ChatGPT

You already have a temporary address; this makes it permanent.

At the end, the runner has an address like https://runner.yourcompany.com that your team can open from anywhere.

Set this up with your agent

Copy this to a coding agent on your laptop. It runs the commands and checks each step with you; what you sign in to, press or paste stays yours.

This is for a coding agent that can run commands on my laptop (Claude Code, Codex, Cursor), not a chat website.
Walk me through Loopgate's guide "Your address with Cloudflare Tunnel": https://loopgate.dev/runner/guides/address-cloudflare.md. The guides it links to are beside it, each ending in .md.
Run its commands yourself, on my laptop or on my box over SSH as the guide says, one step at a time, and check each "You should see" line before the next step.
These are mine: tell me when it is my turn, wait for me, and never ask me to type them into this chat. Signing in to anything (the portal, a cloud console, Slack, GitHub), pressing Add a runner, every token and password, my AI subscription's device code, and making the Slack app.
If I paste you the portal's install line, run it on the box: its token works once, for an hour.

At a glance

Time: 15 minutes, plus a few minutes for a new domain to settle.

What you need:

  • The runner, started in Any Linux computer with Docker
  • A free Cloudflare account
  • A domain you own, added to that account (or buy one in Cloudflare under Domain Registration → Register Domains; it is added for you)

Steps:

  1. Make the tunnel
  2. Start the connector
  3. Point a name at it
  4. Open the runner

Your box dials out to Cloudflare and Cloudflare sends your team down that line, so the box opens no door to the internet (what a tunnel is). Run the box commands in the loopgate folder (cd ~/loopgate).

Steps

Make the tunnel

  1. In the Cloudflare dashboard, open Zero Trust from the left menu. The first time, choose a team name and the Free plan.

    Cloudflare may ask for a card even for the free plan.

  2. Go to Networks → Tunnels and press Create a tunnel.

  3. Choose Cloudflared, name it loopgate-runner and save.

  4. Choose Docker and copy only the token. Cloudflare shows a command that ends with --token and a long string starting eyJ; copy that string. Do not run the command; Loopgate's file runs the connector for you.

Start the connector on your box

  1. Make the tunnel's settings file and paste the token after TUNNEL_TOKEN=, then save and leave (Ctrl+O, Enter, Ctrl+X).

    curl -fsSLO https://loopgate.dev/runner/tunnel.env.example && cp tunnel.env.example tunnel.env
    nano tunnel.env

    This token connects anything to your tunnel. Treat it like a password.

  2. Start the tunnel, now and on every start from now on.

    echo "COMPOSE_PROFILES=tunnel" >> .env && docker compose up -d

    You should see: Container loopgate-runner-tunnel-1 Started, and in Cloudflare the tunnel's status turns Healthy within a minute.

Point a name at the runner

  1. In Cloudflare, press Next (or open the tunnel's Public Hostname tab, called Published application routes in some accounts) and add one, leaving the other settings as they are:

    • Subdomain: runner
    • Domain: your domain
    • Service type: HTTP
    • URL: runner:4311
  2. Give the runner its new address, with no slash at the end, and restart it.

    cd ~/loopgate && echo "LOOPGATE_RUNNER_URL=https://runner.yourcompany.com" >> runner.env
    docker compose up -d runner

    You should see: the portal's Devices row shows the new address, no longer marked temporary.

  3. In the Loopgate portal, open Devices and press Open on the runner's row.

    You should see: the workbench, on your new address.

    A browser stays signed in there for thirty days from its last use. A teammate on a link with no sign-in gets Sign in, which goes through the portal.

Check

The runner names your address, and Settings → General no longer says temporary:

docker compose logs runner

You should see: Runner ready at https://runner.yourcompany.com.

Next

Connect Slack, if you have not yet. Links it posts from now on survive a restart.

If something is off

  • "Not a current member of this org." An owner or admin adds the person in the portal; they can get in within about two minutes, and someone removed is out as fast. The runner turns everyone else away, which is why a public address is safe (more).
  • The tunnel is not Healthy. Check the token in tunnel.env, then docker compose up -d.

Doing it by hand

By hand has every line of runner.env and tunnel.env.