# Your address with Cloudflare Tunnel

You already have a temporary address; this makes it permanent.

At the end, the runner has an address like `https://runner.yourcompany.com` that your team can open from anywhere.

## At a glance

**Time:** 15 minutes, plus a few minutes for a new domain to settle.

**What you need:**

- The runner, started in [Any Linux computer with Docker](any-box.md)
- A free Cloudflare account
- A domain you own, added to that account (or buy one in Cloudflare under **Domain Registration → Register Domains**; it is added for you)

**Steps:**

1. Make the tunnel
2. Start the connector
3. Point a name at it
4. Open the runner

Your box dials out to Cloudflare and Cloudflare sends your team down that line, so the box opens no door to the internet ([what a tunnel is](words.md)). Run the box commands in the `loopgate` folder (`cd ~/loopgate`).

## Steps

### Make the tunnel

1. **In the Cloudflare dashboard, open Zero Trust** from the left menu. The first time, choose a team name and the **Free** plan.

   > Cloudflare may ask for a card even for the free plan.

2. **Go to Networks → Tunnels and press Create a tunnel.**

3. **Choose Cloudflared, name it `loopgate-runner` and save.**

4. **Choose Docker and copy only the token.** Cloudflare shows a command that ends with `--token` and a long string starting `eyJ`; copy that string. Do not run the command; Loopgate's file runs the connector for you.

### Start the connector on your box

5. **Make the tunnel's settings file and paste the token after `TUNNEL_TOKEN=`**, then save and leave (Ctrl+O, Enter, Ctrl+X).

   ```sh
   curl -fsSLO https://loopgate.dev/runner/tunnel.env.example && cp tunnel.env.example tunnel.env
   nano tunnel.env
   ```

   > This token connects anything to your tunnel. Treat it like a password.

6. **Start the tunnel, now and on every start from now on.**

   ```sh
   echo "COMPOSE_PROFILES=tunnel" >> .env && docker compose up -d
   ```

   You should see: `Container loopgate-runner-tunnel-1  Started`, and in Cloudflare the tunnel's status turns **Healthy** within a minute.

### Point a name at the runner

7. **In Cloudflare, press Next** (or open the tunnel's **Public Hostname** tab, called **Published application routes** in some accounts) **and add one**, leaving the other settings as they are:
   - **Subdomain:** `runner`
   - **Domain:** your domain
   - **Service type:** `HTTP`
   - **URL:** `runner:4311`

8. **Give the runner its new address**, with no slash at the end, and restart it.

   ```sh
   cd ~/loopgate && echo "LOOPGATE_RUNNER_URL=https://runner.yourcompany.com" >> runner.env
   docker compose up -d runner
   ```

   You should see: the portal's Devices row shows the new address, no longer marked `temporary`.

9. **In the Loopgate portal, open Devices and press Open** on the runner's row.

   You should see: the workbench, on your new address.

   > A browser stays signed in there for thirty days from its last use. A teammate on a link with no sign-in gets **Sign in**, which goes through the portal.

## Check

The runner names your address, and Settings → General no longer says `temporary`:

```sh
docker compose logs runner
```

You should see: `Runner ready at https://runner.yourcompany.com`.

## Next

[Connect Slack](slack.md), if you have not yet. Links it posts from now on survive a restart.

## If something is off

- **"Not a current member of this org."** An owner or admin adds the person in the portal; they can get in within about two minutes, and someone removed is out as fast. The runner turns everyone else away, which is why a public address is safe ([more](words.md)).
- **The tunnel is not Healthy.** Check the token in `tunnel.env`, then `docker compose up -d`.

## Doing it by hand

[By hand](by-hand.md) has every line of `runner.env` and `tunnel.env`.
