Back to list

Blog

Deep Integration with Cloudflare: Secure Remote Access Made Simple

Cloudflare Tunnel integration brings enterprise-grade remote access to Tactic Remote without port forwarding, dynamic DNS, or VPN configuration.

Published Tags: integration / cloudflare / security / networking
Blog

Follow product and engineering updates from this channel.

Browse category

Remote access is the feature most requested by Tactic Remote users, and the one most fraught with security risks. Today, we're sharing the details of our deep Cloudflare integration — how it works, why we chose Cloudflare, and what it means for developers who need to manage Claude Code sessions from outside their home or office network.

The Problem with Traditional Remote Access

Before Cloudflare integration, remote access to your Mac required one of several unpleasant options:

Port forwarding — Opening a port on your router and hoping your ISP doesn't change your IP address. This exposes your Mac directly to the internet and requires firewall configuration that most developers shouldn't have to think about.

Dynamic DNS — Slightly better than raw port forwarding, but still requires an open port and adds the complexity of keeping a DNS record updated when your IP changes.

VPN — The enterprise solution. Reliable and secure, but overkill for individual developers. Setting up a VPN server requires infrastructure, and using a commercial VPN service routes your development traffic through a third party.

SSH tunneling — Technically sound but operationally complex. Keeping an SSH tunnel alive from your phone, especially when switching between Wi-Fi and cellular, is an exercise in frustration.

None of these options meet our standard of "set it up once and forget it." Tactic Remote's users are developers, not network administrators. The remote access solution needed to be as simple as installing an app.

Why Cloudflare

We evaluated several approaches to solving remote access, including building our own relay infrastructure. We chose Cloudflare Tunnel for several reasons:

Outbound-initiated model. Cloudflare Tunnel works by establishing an outbound connection from your Mac to Cloudflare's edge network. In the standard setup, your Mac is not directly exposed as a public inbound service, which avoids router port forwarding and reduces external attack surface.

Global edge network. Cloudflare operates in over 300 cities worldwide. When your iPhone connects to Tactic Remote through the tunnel, it routes to the nearest Cloudflare edge server, minimizing latency regardless of where you are.

Built-in encryption. All traffic through the tunnel is encrypted with TLS. Combined with our own authentication layer, this provides defense-in-depth without requiring users to manage certificates.

Mature reliability posture. Cloudflare handles a significant percentage of global internet traffic. Their infrastructure is stress-tested at scales difficult for a small team to reproduce independently.

Free tier availability. Cloudflare Tunnel's free tier is generous enough for individual developers and small teams. We didn't want remote access to be a paid feature gated by infrastructure costs.

How It Works

Setting up Cloudflare Tunnel with Tactic Remote takes about 5 minutes:

Step 1: Install cloudflared

brew install cloudflare/cloudflare/cloudflared

Step 2: Authenticate

cloudflared tunnel login

This opens a browser window where you log into your Cloudflare account and authorize the tunnel daemon.

Step 3: Create and Configure the Tunnel

cloudflared tunnel create claude-remote
cloudflared tunnel route dns claude-remote your-subdomain.yourdomain.com

Step 4: Start the Tunnel

The Tactic Remote Mac companion app can manage the tunnel lifecycle automatically. Once configured, it starts cloudflared alongside the companion server and monitors tunnel health.

Step 5: Connect from Anywhere

On your iPhone, enter your-subdomain.yourdomain.com as the endpoint instead of a local IP address. Everything else works identically — authentication, session management, terminal streaming, and approvals all function the same regardless of connection mode.

Performance Characteristics

We transparently share the latency impact of tunneled connections:

MetricLocal NetworkCloudflare Tunnel
Connection setup~50ms~200ms
Terminal update latency60-100ms120-250ms
Approval round-trip~100ms~300ms
Reconnection time1-2s2-4s

The additional latency is noticeable but does not meaningfully impact workflows. Terminal output still feels responsive, and approval interactions remain snappy. Most users report that they forget they're connecting through a tunnel after the first few minutes.

Security Considerations

While Cloudflare Tunnel eliminates many security concerns, we want to be transparent about the trust model:

Traffic passes through Cloudflare's network. Cloudflare can theoretically inspect traffic at their edge servers. Our API-level encryption mitigates this — even if Cloudflare inspected the transport layer, the payload is encrypted with keys only your devices possess.

Cloudflare account security becomes important. Your Cloudflare account controls the tunnel. Use a strong password and enable two-factor authentication on your Cloudflare account.

Tunnel availability depends on Cloudflare. If Cloudflare experiences an outage (rare but possible), tunnel-mode access is disrupted. Local network mode remains functional as a fallback.

For detailed security hardening guidance, see our Security and Network Hardening documentation.

What Users Are Saying

Since launching Cloudflare integration, we've seen remote access usage grow significantly:

  • 34% of active users now use Cloudflare Tunnel mode at least once per week.
  • Most common scenario: Developers commuting on public transit who start tasks before leaving home and monitor them during travel.
  • Longest documented session: 4 hours of continuous remote monitoring from an airport lounge — terminal streaming remained stable throughout.

The feedback consistently emphasizes simplicity: developers expected remote access to be complicated and were surprised by the setup experience.

What's Next

We're working with Cloudflare on several improvements:

  • Zero-config tunnel setup that generates a temporary public URL without requiring a Cloudflare account (for quick demo and testing scenarios).
  • Access policies that leverage Cloudflare Access for team environments where multiple people need tunnel access.
  • Latency optimization through smarter edge routing for known client-server geography pairs.

For setup instructions, see our complete Cloudflare Tunnel guide. If you're already using local network mode and want to add remote access, the migration takes about 5 minutes and doesn't affect your local mode configuration.

Try Tactic Remote

Control your coding Agents from your phone

Connect to Claude Code, Codex, and other Agents on your Mac, Windows, or Linux computer. Check progress and send the next instruction from iPhone or iPad.