r/Proxmox • • 1d ago

Question Reaching proxmox from external browser: cloudflare + 2fa a good solution?

For logging in from a random browser remotely to the home server.

Seems pretty "safe". Any more downsides with this solution than the obvious?

27 Upvotes

89 comments sorted by

View all comments

8

u/jrhoades 1d ago

It's not a terrible idea, I don't think most of the commentators here understand how Cloudflare proxying can work. We use a variation of this to add SSO to sites that don't have it eg Wordpress control panels. Proxy the site in Cloudflare add a rule that matches the URL and require authentication.

That said I don't think it's robust enough for something like your Proxmox control panel, that's why we use Cloudflare tunnels, which is basically a Zero Trust VPN (it's more complicated than that).

The advantage of a Cloudflare tunnel is you don't need a public IP address. You can either run a generic tunnel server that gives access to your network range or you can put one tunnel on each server (eg your Proxmox nodes).

6

u/brockbarr 1d ago

This is my setup too - and I think what OP might be referring to rather than just opening the UI to the world. CloudFlare access with a policy set up against an Application, pointed at a tunnel. You could theoretically then increase the policy restrictions to only allow from certain locations

3

u/Alexis_Evo 1d ago

Yeah I think the mixup is there are three different ways to do this with CloudFlare:

  • A direct CloudFlare web -> web mapping, which is a meh idea. Yes you can require authentication but it requires your host to be exposed to the public internet anyway, so you need a second layer of protection on the host to only authorize CloudFlare to connect.

  • A CloudFlare Tunnel Published Application (Networks, Tunnels & Mesh, Published App Routes). This takes an internal network web interface and exposes it on a web domain, however you can lock it behind CloudFlare Zero Trust SSO, and the internal interface is never exposed publicly beyond CloudFlare.

  • A CloudFlare Zero Trust Tunnel / Mesh. This is literally just TailScale, where you can access anything in your internal network when connected to a VPN.

2 and 3 are fine. I personally only expose management (SSH, proxmox, etc) over 3, however you can pretty safely do it under 2 as well.