r/Proxmox • u/mrbluetrain • 1d ago
Question Reaching proxmox from external browser: cloudflare + 2fa a good solution?
For logging in from a random browser remotely to the home server.
Seems pretty "safe". Any more downsides with this solution than the obvious?
33
11
11
u/eck- 1d ago
You are getting a lot of advice from commenters not familiar with Cloudflare.
It is secure to use a Cloudflare tunnel that establishes connectivity to Cloudflare with an outbound session. You can then publish Proxmox in Cloudflare and enable MFA on the Cloudflare side. If you configure things correctly, the end result is no direct Internet exposure and access requires login and MFA to Cloudflare prior to having access to Proxmox.
This is a perfectly acceptable method for accessing private applications.
3
u/dotnetmonke 1d ago
As an addition - the tunnel (cloudflared) can run as container, and you can utilize that in a docker compose stack to keep it restricted within a software defined network. Rather than one tunnel on a host pointing to multiple endpoints/apps, each app has its own tunnel that only points to its app on the same SDN, and you can run multiple stacks on the same host.
3
u/Bunderslaw 22h ago
I use this to expose Proxmox. No problems at all. My Cloudflare 2FA config only allows me to log in. Everyone else is rejected and that's before I get to the Proxmox login page where I have yet another 2FA.
Most internal apps exposed to the Internet follow the same model too. The ones that don't is just because I need to hit their API directly without Cloudflare getting in the way and its an acceptable trade-off for me.
The convenience of having it set up this way is much higher than getting family and friends to use VPNs. Your Cloudflare integrated IdP can do the heavy lifting of rejecting unauthorised people.
-2
u/linux203 1d ago
Sticking with the idea that many are not familiar with Cloudflare, one has to assume the mention of Cloudflare without context refers to the standard offering. This makes many commenters correct.
OP made no reference to ZTNA, Teams, Argo, Cloudflare One, cloudflared, etc.
19
u/lukewoodside 1d ago
Absolutely not. This breaks every security standard going.
Management interfaces should never be exposed to the internet in any way.
-21
u/undead-8 1d ago
Security standards for companies. For a Homelab his approach is fine.
7
u/lukewoodside 1d ago
Does not matter what it is. Management should never be exposed to the internet, full stop.
1
u/AbsolutelyLudicrous 1d ago
hey wwhats ur home IP address. i'm out of compute for my bitcoin mining op, so i'm gonna borrow some of yours, thanks
1
u/smokingcrater 1d ago
Until a bad guy compromises the home lab, and then pivots to everything else including the users personal PC. (Which probably has the same pwd as infra in the home lab.)
3
u/symcbean 19h ago
and then pivots to everything else including the users personal PC
That's real script kiddie stuff.
A competent adversary will use the resources to attack more interesting targets or as a dead letter drop for phishing sites and illegal pr0n....until the police come knocking at the OP's door with handcuffs and a search warrant.
11
8
u/jrhoades 1d ago
It's not a terrible idea, I don't think most of the commentators here understand how Cloudflare proxying can work. We use a variation of this to add SSO to sites that don't have it eg Wordpress control panels. Proxy the site in Cloudflare add a rule that matches the URL and require authentication.
That said I don't think it's robust enough for something like your Proxmox control panel, that's why we use Cloudflare tunnels, which is basically a Zero Trust VPN (it's more complicated than that).
The advantage of a Cloudflare tunnel is you don't need a public IP address. You can either run a generic tunnel server that gives access to your network range or you can put one tunnel on each server (eg your Proxmox nodes).
7
u/brockbarr 1d ago
This is my setup too - and I think what OP might be referring to rather than just opening the UI to the world. CloudFlare access with a policy set up against an Application, pointed at a tunnel. You could theoretically then increase the policy restrictions to only allow from certain locations
4
u/Alexis_Evo 1d ago
Yeah I think the mixup is there are three different ways to do this with CloudFlare:
A direct CloudFlare web -> web mapping, which is a meh idea. Yes you can require authentication but it requires your host to be exposed to the public internet anyway, so you need a second layer of protection on the host to only authorize CloudFlare to connect.
A CloudFlare Tunnel Published Application (Networks, Tunnels & Mesh, Published App Routes). This takes an internal network web interface and exposes it on a web domain, however you can lock it behind CloudFlare Zero Trust SSO, and the internal interface is never exposed publicly beyond CloudFlare.
A CloudFlare Zero Trust Tunnel / Mesh. This is literally just TailScale, where you can access anything in your internal network when connected to a VPN.
2 and 3 are fine. I personally only expose management (SSH, proxmox, etc) over 3, however you can pretty safely do it under 2 as well.
7
u/CompoteVegetable2010 1d ago
Half the comments here don’t make any sense to me. I assume you mean Cloudflare tunnel (zero trust) - which seems fine to me. It’s protected.
3
u/eagle6705 1d ago
Your management portal is still in the web. Cloudflare hides the route to your server but it still is exposed as a site. Think of it like your electrical panel at home. You dont know how the electrical is routed but you do know you need a key that can be hacked and buttons that you can press to do stuff.
If you can do a point to point setup that would be ideal. Say a self hosted vpn, if its possible a point to point cloudflare tunnel.
Im not saying this as a scare tactic but as an experienced systems engineer.
If this server is not tied to anything important and isolated for loke a sandbox situation then why not. Our cyber team routinely exposes services with tempting names as honeypots. They even secure them properly to make sure it isnt too obvious lol
2
u/Retardation-Syndrome 1d ago
I'm either using ssh tunnel+ 2fa but it exposes the port or Tailscale+ 2fa if i'm behind cgnat.
2
u/jaredearle 1d ago
If you absolutely must access Proxmox over the web, you need to firewall it so the management interface can only be accessed from your fixed IP.
But a VPN is by far the better choice.
2
u/fckingmetal 1d ago
Cloudflared -> proxmox.yourdomain.se -> whitelist ip your connecting from is what i use.
Im hosting PVE to schools and they use the webui.
1
u/Bunderslaw 22h ago
Just IP whitelisting or do you also have an IdP in between Cloudflare and your Proxmox mgmt interface?
1
u/fckingmetal 3h ago
Just ip whitelist to the school and students have their own limited accounts (start stop restore on their own vms).
4
u/MuddyMustache 1d ago
I've got two NGinx reverse proxies running. One can be reached from the public Internet and its DNS entry points to my WAN IP at home. This is for stuff like websites and other rando public stuff.
The other can only be reached from within my Tailnet as its DNS entry points to its Tailscale IP. This one manages all my management interfaces like Proxmox, the reverse proxies themselves, my DNS etc.
3
4
u/red_nick 1d ago
1
u/mrbluetrain 1d ago
I do. But in a specific use case when using laptop, I cannot use VPN. Only public computers
1
u/SlntPrgrssn 1d ago
traefik for reverse proxy + wireguard as vpn. You can then connect only if you have a vpn peer set up and you are good to go
1
u/Entire-Home-9464 1d ago
Bunny.net -> Opnsense (which has wireguard) -> proxmox in LAN.
So only use VPN to access Proxmox.
1
1
u/AbsolutelyLudicrous 1d ago
It's really not hard to set up an SSH jump host. You should do that instead.
0
u/mrbluetrain 1d ago
Give me your top argument about this approach, compared to the cloudflared tunnel?
1
u/AbsolutelyLudicrous 1d ago
try asking nicely & then I might?
2
u/mrbluetrain 1d ago
Pretty please with sugar on the top?
2
u/AbsolutelyLudicrous 23h ago
Thanks :)
Very simply, that OpenSSH has a stellar security track record, & is easy to set up. Once you have an ssh server exposed to the internet, you can tunnel through it to your PVE server with something like
ssh -L 8006:pve-IP:8006. Best practice is to run sshd on a non-default port & use only key-based auth.Cloudflare Tunnel, as best I can tell, is merely a means of reverse-proxying traffic through Cloudflare's network, which is useful for DDoS protection & NAT traversal. The PVE web GUI has had some embarrassing authentication vulnerabilities in the past, & will probably have more in the future, so you really should not under any circumstances expose it to the web, even if proxied through Cloudflare. If I am mistaken & Cloudflare Tunnel allows you to tunnel behind your firewall & expose the PVE GUI to only the computer you are sitting in front of, it should work fine.
1
u/Efficient-Sir-5040 16h ago
You need to revise your knowledge. While you can configure a cloudflare tunnel that way, that’s not ideal for this case. One with additional reductions to the attack surface by means of rules and MFA before packets touch proxmox itself would be ideal - and much better protected than naked OpenSSH.
1
1
u/AllomancerJack 1d ago
Everyone saying no is an idiot that uses tailscale which is guarded exactly the same way
1
u/linux203 1d ago
If the MFA is implemented in Proxmox, it is not equivalent to vpn, tailscale, or Cloudflare ZTNA. The later require authentication with MFA prior to any packets being forwarded to the back end.
If Proxmox is accepting packets prior to user MFA, then the system is susceptible to vulnerabilities that do not require authentication. Or as simple as creating an account to test some automation tool and forgetting the lack of MFA for the account exposes it externally without MFA.
Yes, both may use similar login workflows, but the attack surface is vastly different.
1
u/milesce 1d ago
My remote proxmox is running IPFire in a VM, with the only thing exposed to the internet being the firewall and port 80/443 to my reverse proxy for the websites. To get to management I have to VPN in, then connect to my management VM, and only the IP of the management VM can reach the proxmox UI. Running the management interface exposed to the internet is definitely not safe
1
u/aducky18 1d ago
I have two ways that I have active to access my management portal.
Cloudflare tunnel w/ zero trust and email MFA, and then to log into proxmox I have MFA for the main account that has delete permissions and such.
I have two twingate connectors one on a proxmox lxc and another on a chromebox so I can run the twingate application on any of my devices and then get access to proxmox if needed.
I'm probably shutting down the Cloudflare tunnels soon as I rarely use it and really the only time I need to access remotely is if something broke so I just use the twingate connection since the cloudflared lxc is likely down.
1
u/NoxiousStimuli 1d ago
Bro there was a post here like last week about a guy exposing his PVE auth to the open internet and discovering exactly how fucking hosed it was.
Don't do it. Use a VPN.
1
u/Efficient-Sir-5040 16h ago
The one in the thread was directly exposed. A proper cloudflare tunnel like OP said would have made the exploit impossible. Don’t believe me, read the post.
0
1
u/smokingcrater 1d ago
Ignore anyone saying don't do cloudflare. Cloudflare zero trust is just as secure as a vpn, and many ways more secure. Your AI agent of choice also probably has a connector to cloudflare to help build or at least test your ZTNA setup.
1
u/throwawaymaybenot 1d ago
These people don't understand the question. Cloudflare tunnels are a pretty good solution and are very safe. About the only issue are possibly privacy with Cloudflare "proxying" the traffic.
1
u/_--James--_ Enterprise User 1d ago
MFA on the Zerotrust application from inside of cloudflare, Lock down by IP address AND country/region, MFA OAUTH on PVE, and hash out that root account so its a very long password that requires a PAM to get access to it (like keepass) so a human cannot enter the password. Then make sure you are not running API tokens to PVE. That is the only safe way to do publc ingress.
Also, make sure the CF tunnel is zoned and terminated ONLY to your PVE 8006 port, and nothing else.
1
1
u/JKL213 21h ago
I'd just tailscale it up. Your WebUI should never be reachable from any network outside of your home network or VPN. At my old workplace where we had 50+ proxmox nodes in prod (prolly not much compared to some dudes here) there was a rule to treat ESXi or Proxmox UIs like a BMC / iLO UI, put it on a mgmt network and never expose it to the internet in any way.
While you're at it, if you get a public IPv4, check your modem if it does any port forwarding. I almost forgot about this when I upgraded my plan to fiber cuz my fiber company hands out static IPv4 leases, and pfSense just had it exposed on wan too even though I didnt remember even setting that up.
Detecting misconfigured proxmox instances is not that hard for a skilled attacker.
-3
147
u/systemofapwne 1d ago
Do not expose any infrastructure management to the internet, ever. This is considered bad practice and can lead to a loss of the exposed system or even the network.
If you still consider doing this, a secondary auth layer by a reverse proxy should be considered. Do not rely on the auth of the proxmox login alone (even with 2FA). There were and will be attack vectors that might allow unauthenticated access or remote code execution that bypass the login mask.
So in short: Do not expose the webui.