cf-managed-network-endpoint ghcr.io/tom-joad/cf-managed-network-endpoint:latest https://ghcr.io br0 sh false https://github.com/Tom-Joad/cf-managed-network-endpoint https://github.com/Tom-Joad/cf-managed-network-endpoint https://raw.githubusercontent.com/Tom-Joad/unraid-templates/main/templates/cf-managed-network-endpoint.xml https://raw.githubusercontent.com/Tom-Joad/unraid-templates/main/icons/cf-managed-network-endpoint.png TLS endpoint for Cloudflare Zero Trust "Managed Networks". Serves a self-signed certificate on port 6443; the Cloudflare WARP client compares its SHA-256 fingerprint to tell whether a device is on the home network. No application logic. The certificate is created once, on the very first start, and kept in the Config folder (keys/). As long as that folder survives, the fingerprint stays the same across restarts and image updates. NEVER delete it: a new certificate means a new fingerprint, and network detection breaks silently. Include the appdata folder in your backups. The fingerprint is printed in the container log on every start (Unraid: container icon -> Logs). Upgrading from a version before 1.0.0: keep the old /certs path below for the first start, so the existing certificate is taken over. Then remove it. Network: a custom VLAN interface (e.g. br0.10) must exist on the machine; set a static IP outside the DHCP pool in this container's "Fixed IP address" setting. Network:Other Security: