Back to list

Blog

Cloudflare Tunnel for Remote Development: Complete Setup Guide

Access your Mac development server from anywhere without opening ports, managing DNS, or configuring your router. Here's how Cloudflare Tunnel makes remote development practical.

Published Tags: Getting started / networking / cloudflare / security / seo
Blog

Follow product and engineering updates from this channel.

Browse category

If you want to access your Mac development environment from outside your local network — from a coffee shop, an airport, a different city — you need a secure path through the internet to your machine. The traditional approaches (port forwarding, dynamic DNS, VPN) all have significant drawbacks for developer use cases.

Cloudflare Tunnel offers a better model: your Mac establishes an outbound connection to Cloudflare's network. Remote clients connect to Cloudflare. No ports opened on your router, no DNS to manage, no firewall rules to configure.

This guide covers how to set it up for remote development, specifically for accessing Claude Code via Tactic Remote.

How Cloudflare Tunnel Works

The architecture is straightforward:

Your iPhone          Cloudflare Edge          Your Mac
     │                    │                       │
     │  HTTPS (wss://)    │  Outbound tunnel      │
     │───────────────────►│◄──────────────────────│
     │                    │                       │
     │  Encrypted         │  cloudflared process  │
     │  WebSocket         │  connects outbound    │
     │                    │  to Cloudflare        │
     │                    │                       │

Key points:

  • Your Mac initiates the tunnel connection outbound to Cloudflare. Nothing listens on a public port.
  • Cloudflare assigns a URL (e.g., https://random-words.trycloudflare.com) that routes to your Mac through the tunnel.
  • Traffic is encrypted end-to-end with TLS.
  • Your router doesn't need any configuration — no port forwarding, no UPnP, no DMZ.

This is fundamentally different from exposing a port. With port forwarding, your Mac accepts inbound connections from the entire internet. With Cloudflare Tunnel, only authenticated traffic through Cloudflare reaches your Mac.

Prerequisites

  • macOS 14 (Sonoma) or later (for the Mac app integration)
  • Homebrew installed
  • cloudflared — Cloudflare's tunnel client

Install cloudflared:

brew install cloudflared

Verify the installation:

cloudflared --version
# cloudflared version 2025.x.x

You do not need a Cloudflare account for quick tunnels. The trycloudflare.com domain is free and requires no sign-up.

Setup with Tactic Remote Mac App

The Mac app handles most of the Cloudflare Tunnel configuration automatically.

Step 1: Enable Cloudflare Tunnel

In the Mac app's Settings:

  1. Toggle Cloudflare Tunnel to enabled
  2. The app starts cloudflared with the correct configuration
  3. A tunnel URL appears (e.g., https://bright-river-abc123.trycloudflare.com)

Behind the scenes, the Mac app runs:

cloudflared tunnel --url http://localhost:8765 --protocol h2mux

The --protocol h2mux flag uses HTTP/2 multiplexing for the tunnel connection, which provides better performance for WebSocket traffic.

Step 2: Set an API Key

This is mandatory for Cloudflare connections. When your server is reachable from the internet, you must authenticate connections.

The Mac app generates a 32-character random API key. You can also set your own. This key is required when connecting from your iPhone — it's sent in the WebSocket handshake via the Sec-WebSocket-Protocol header.

Step 3: Configure Your iPhone

In Tactic Remote on your iPhone:

  1. Go to connection settings
  2. Switch to Cloudflare mode
  3. Enter the tunnel URL from the Mac app
  4. Enter the API key

Or scan the QR code from the Mac app, which encodes both the tunnel URL and API key.

Step 4: Test the Connection

  1. Switch your iPhone to cellular (turn off WiFi to confirm you're not accidentally using LAN)
  2. Open Tactic Remote
  3. Verify connection succeeds
  4. Create or open a session
  5. Send a test command

If this works, you're set. The tunnel URL persists as long as cloudflared is running.

How Tactic Remote Uses the Tunnel

When Cloudflare Tunnel is active, the communication path changes:

LAN mode: iPhone → WiFi → Mac (port 8765) — direct WebSocket Cloudflare mode: iPhone → Cellular/WiFi → Cloudflare Edge → Tunnel → Mac (port 8765) — encrypted WebSocket through tunnel

From the iPhone app's perspective, the only difference is the URL:

  • LAN: ws://192.168.1.100:8765
  • Cloudflare: wss://bright-river-abc123.trycloudflare.com

The wss:// prefix indicates WebSocket Secure (encrypted). All data between your phone and Cloudflare, and between Cloudflare and your Mac, is encrypted.

Security Considerations

What the Tunnel Protects

  • No public ports — your Mac's firewall doesn't need any inbound rules
  • TLS encryption — all traffic is encrypted in transit
  • DDoS protection — Cloudflare's edge network absorbs volumetric attacks before they reach your Mac
  • URL obscurity — the trycloudflare.com URL is randomly generated and hard to guess

What You're Responsible For

  • API key strength — use a long random key (the Mac app generates 32 characters). Don't use weak passwords.
  • API key transmission — transfer the key via QR code (in-person) rather than sending it over email or chat
  • Tunnel URL privacy — don't post your tunnel URL publicly. Anyone with the URL and API key can connect.
  • Mac physical security — the server has access to your filesystem through Claude Code. Lock your Mac.
  • Rate limiting — Tactic Remote's server includes rate limiting middleware to slow brute-force attempts, but it's not a substitute for a strong API key

What About Cloudflare Seeing Your Traffic?

Cloudflare terminates TLS at their edge, which means they theoretically can see your traffic. For most development use cases, this is acceptable — you're not sending classified data, and Cloudflare's privacy commitments are well-documented.

If this concerns you, use LAN mode exclusively and only work from your local network.

Troubleshooting

"Tunnel URL not appearing"

  • Check that cloudflared is installed: which cloudflared
  • Check the Mac app logs for cloudflared errors
  • Try running cloudflared manually: cloudflared tunnel --url http://localhost:8765
  • Verify your internet connection is active

"Connection works on LAN but not Cloudflare"

  • Verify you're using wss:// (not ws://) with the tunnel URL
  • Confirm the API key matches between Mac app and iPhone settings
  • Check if your network blocks outbound connections on non-standard ports (rare but possible on corporate networks)

"Intermittent disconnections"

  • Cloudflare quick tunnels may recycle URLs after extended inactivity
  • Check the Mac app — if the tunnel URL changed, update your iPhone settings
  • Consider using a named tunnel with a Cloudflare account for permanent URLs

"High latency"

  • Quick tunnels route through the nearest Cloudflare data center, which is usually fast
  • If latency is consistently high, your ISP might have poor peering with Cloudflare
  • Test with: curl -o /dev/null -w "%{time_total}" https://your-tunnel-url.trycloudflare.com
  • Latency under 200ms is fine for terminal interaction. Over 500ms becomes noticeable.

Quick Tunnel vs Named Tunnel

Tactic Remote uses quick tunnels by default — no Cloudflare account required, URL assigned automatically. This is the fastest path to working remote access.

Quick tunnel limitations:

  • URL is randomly generated and changes if cloudflared restarts
  • No custom domain
  • No Cloudflare Access integration (no SSO, no additional auth layers)

Named tunnels (require a free Cloudflare account) provide:

  • Persistent URL that doesn't change across restarts
  • Custom domain mapping (e.g., dev.yourdomain.com)
  • Cloudflare Access for additional authentication (SSO, email verification)
  • Better for team setups where multiple people need consistent access

For individual developers, quick tunnels work well. If you find yourself frequently updating the tunnel URL on your phone, consider upgrading to a named tunnel.

Alternatives to Cloudflare Tunnel

For completeness, other approaches to remote access:

Port Forwarding

  • Open a port on your router, configure firewall
  • Risk: your Mac is directly exposed to the internet
  • Requires dynamic DNS if your IP changes
  • Not recommended for development environments

Tailscale/WireGuard VPN

  • Creates a private network between your devices
  • Good security model (peer-to-peer encrypted)
  • Requires Tailscale client on both Mac and iPhone
  • Note: Tactic Remote does not currently integrate with Tailscale — you'd need to run it separately and point Tactic Remote at the Tailscale IP

ngrok

  • Similar concept to Cloudflare Tunnel
  • Free tier has limitations (connection count, bandwidth)
  • Mature product with good developer experience
  • Alternative if you prefer ngrok's ecosystem

SSH Tunnel

  • Classic approach using SSH port forwarding
  • Requires SSH server configuration on your Mac
  • Note: Tactic Remote uses WebSocket, not SSH — an SSH tunnel would wrap the WebSocket connection, adding complexity without clear benefit

Cloudflare Tunnel is the recommended option for Tactic Remote because it's free, requires no account for quick tunnels, and is directly integrated into the Mac app.

Try Tactic Remote

Control your coding Agents from your phone

Connect to Claude Code, Codex, and other Agents on your Mac, Windows, or Linux computer. Check progress and send the next instruction from iPhone or iPad.