Skip to content
DnsLister Forum

Where domain hunters compare notes

How I temporarily deploy a web app from an unused PC with Cloudflare Tunnel (instead of AWS/GCP — no port forward / static IP)

Why I did this

Whenever I needed to show a side web app outside my house, I defaulted to AWS or GCP.

Spin up EC2 / Compute Engine, open security groups / firewall rules, wire DNS, get HTTPS working — that's a lot of steps for “just show this for a bit.” The bill looks small until you forget to turn the instance off.

The goal wasn't to turn a home PC into production. It was to get a temporary public HTTPS URL without opening AWS/GCP first. So I used an unused computer + Cloudflare Tunnel.

What Cloudflare Tunnel does (short)

The old way: open 80/443 on your router and accept inbound traffic to your home IP.

Tunnel flips that: cloudflared on the PC keeps an outbound connection to Cloudflare. When someone hits your hostname, Cloudflare sends the request through the tunnel, and cloudflared proxies to your localhost app.

So you get: – no port forwarding – no static / public IP requirement (works behind CGNAT if the tunnel stays up) – home public IP not parked in DNS – relatively simple HTTPS if the domain is on Cloudflare

What you need

  1. A PC on the internet (disable sleep; wired if you can)
  2. A Cloudflare account + a domain on Cloudflare DNS
  3. A web app that already loads on localhost on that PC
  4. cloudflared

Steps

1) Confirm localhost Run the app. If http://127.0.0.1:PORT opens, continue. It doesn't need to be public yet.

2) Install cloudflared Install for your OS/arch. Check with cloudflared --version.

3) Log in to Cloudflare cloudflared tunnel login Pick the domain you'll use for the tunnel hostname.

4) Create a tunnel cloudflared tunnel create demo-box Note the name, UUID, and credentials JSON path. You can re-check with cloudflared tunnel list / tunnel info.

5) Map hostname → localhost Example ~/.cloudflared/config.yml:

“`yaml tunnel: demo-box credentials-file: /home/you/.cloudflared/<UUID>.json

ingress: – hostname: demo.example.com service: http://127.0.0.1:3000 – service: http_status:404 “`

Notes: – service port must match what the app actually listens on – keep the catch-all http_status:404 or validation often fails – add more hostname lines if you run multiple apps

6) Route DNS to the tunnel cloudflared tunnel route dns demo-box demo.example.com Don't open 80/443 on the router. Don't set a static IP.

7) Run and test from outside cloudflared tunnel run demo-box Hit https://demo.example.com from another network (phone LTE is a good check).

8) Survive reboot / sleep (required if you'll leave it up) – disable sleep / hibernate – auto-start the web app – install cloudflared as a service (cloudflared service install + enable/start — commands vary by OS) – power / UPS as needed

Skip this and the URL dies after the next reboot.

Security lines I kept

  • no inbound SSH / RDP / admin UI on the router
  • manage the box via a private mesh (e.g. Tailscale) if needed
  • treat this box as demo / beta / friends — keep SLA-sensitive traffic on AWS/GCP
  • optional Cloudflare Access login wall
  • don't commit tunnel credentials / tokens to git

When it fits / when it doesn't

Fits: demos, beta, friend QA, “try it publicly before I open a cloud instance” Doesn't: heavy traffic, high availability, flaky home power/network as production

Closing

Not “never use AWS/GCP.” Just a way to stop opening a cloud instance first every time I need a short public demo.

If you've run this longer-term: what monitoring, auto-restart, or backups did you add?

Source: r/selfhosted · by /u/hamshrew

Leave a Reply

Your email address will not be published. Required fields are marked *