cf-managed-network-endpoint
ghcr.io/tom-joad/cf-managed-network-endpoint:latest
https://ghcr.io
br0
sh
false
https://github.com/Tom-Joad/cf-managed-network-endpoint
https://github.com/Tom-Joad/cf-managed-network-endpoint
https://raw.githubusercontent.com/Tom-Joad/cf-managed-network-endpoint/main/unraid/cf-managed-network-endpoint.xml
TLS endpoint for Cloudflare Zero Trust "Managed Networks". Serves a self-signed
certificate on port 6443; the Cloudflare WARP client compares its SHA-256 fingerprint
to tell whether a device is on the home network. No application logic.
The certificate is created once, on the very first start, and kept in the Config
folder (keys/). As long as that folder survives, the fingerprint stays the same across
restarts and image updates. NEVER delete it: a new certificate means a new fingerprint,
and network detection breaks silently. Include the appdata folder in your backups.
The fingerprint is printed in the container log on every start (Unraid: container icon
-> Logs).
Upgrading from a version before 1.0.0: keep the old /certs path below for the first
start, so the existing certificate is taken over. Then remove it.
Network: a custom VLAN interface (e.g. br0.10) must exist on the machine; set a static
IP outside the DHCP pool in this container's "Fixed IP address" setting.
Network:Other Security: