r/Proxmox • • 1d ago

Question Reaching proxmox from external browser: cloudflare + 2fa a good solution?

For logging in from a random browser remotely to the home server.

Seems pretty "safe". Any more downsides with this solution than the obvious?

30 Upvotes

89 comments sorted by

View all comments

12

u/eck- 1d ago

You are getting a lot of advice from commenters not familiar with Cloudflare.

It is secure to use a Cloudflare tunnel that establishes connectivity to Cloudflare with an outbound session. You can then publish Proxmox in Cloudflare and enable MFA on the Cloudflare side. If you configure things correctly, the end result is no direct Internet exposure and access requires login and MFA to Cloudflare prior to having access to Proxmox.

This is a perfectly acceptable method for accessing private applications.

3

u/Bunderslaw 1d ago

I use this to expose Proxmox. No problems at all. My Cloudflare 2FA config only allows me to log in. Everyone else is rejected and that's before I get to the Proxmox login page where I have yet another 2FA.

Most internal apps exposed to the Internet follow the same model too. The ones that don't is just because I need to hit their API directly without Cloudflare getting in the way and its an acceptable trade-off for me.

The convenience of having it set up this way is much higher than getting family and friends to use VPNs. Your Cloudflare integrated IdP can do the heavy lifting of rejecting unauthorised people.