Skip to content

build(deploy): bump the pinned cloudflared to 2026.9.3 - #122

Merged
Fl0p merged 1 commit into
mainfrom
flo-975-cloudflared-bump
Oct 4, 2026
Merged

Fl0p merged 1 commit into
mainfrom
flo-975-cloudflared-bump

Conversation

@Fl0p

@Fl0p Fl0p commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

What changed

CLOUDFLARED_VERSION goes from 2024.11.1 (2024-11-19) to 2026.9.3 (2026-09-24), still an explicit tag rather than latest, so rebuilding an old commit keeps producing the binary it originally shipped. Plus the one mitigation that two years of changelog actually calls for, and docs.

I read the full CHANGES.md for the window. Only four entries touch anything cotel does:

Version Change Effect here
2026.4.0 Breaking: --edge-ip-version default 4 → auto Mitigated, see below
2026.2.0 Breaking: proxy-dns removed Not used
2024.12.1 metrics server binds localhost:20241-20245 when --metrics is absent Container-local, not published, harmless
2025.1.1 post-quantum curves on QUIC Upstream default, edge-side

The one that matters: --edge-ip-version

auto connects over whichever address family the system resolver answers with first, and falls back to the other only after a connection has already failed - and then sticks with the fallback for 10 minutes (region.go, GiveBack: a V6 connectivity error swaps in the secondary set with a primaryTimeout). A container whose resolver answers AAAA first but has no working IPv6 egress therefore burns its first attempts failing. I reproduced exactly that: TUNNEL_EDGE_IP_VERSION=6 on this network yields SUMMARY: Environment has critical failures, while 4 and auto both come up healthy here.

Token mode now defaults TUNNEL_EDGE_IP_VERSION to 4, which is precisely the 2024.11.1 behaviour, and an operator can still set auto/6. Local-config mode is deliberately not touched: I verified that this env var silently outranks an edge-ip-version: in the operator's own config.yml (config said 6, env said 4, it connected over IPv4), and silently ignoring a mounted config file is worse than inheriting upstream's new default. That asymmetry is documented in both tunnel guides.

Pre-checks: left on, deliberately

New since 2024.11.1, cloudflared probes DNS/QUIC/HTTP2/API at startup and logs a ~20-line CONNECTIVITY PRE-CHECKS table. The issue flagged these as running "before the tunnel comes up" - they do not. cmd.go:428 calls go runPrechecks(...), and the source comment is explicit: "Pre-checks are diagnostic only and do not gate tunnel startup." A FAIL row does not stop anything, and the suite is capped at 10s. So --no-prechecks is not needed, and the table is worth keeping: it separates a blocked UDP path from a bad token, which is the diagnosis the deploy health gate structurally cannot make, since it probes cotel's /healthz and not the tunnel.

--token-file: evaluated, not adopted

It exists now ($TUNNEL_TOKEN_FILE; absent in 2024.11.1) and would flip the ps row of the visibility table to "No". That is the only row it changes. Whoever can run ps inside the container can also read /proc/1/environ, so the same person reaches the same value by a path --token-file does not touch - it would cost a tmpfs mount and a secret on disk to close nothing. Reasoning recorded in the doc so it is not re-litigated.

Verified

Built and ran the real image on arm64 (this PR's tree, rebased onto main after #120 landed):

  • docker build . green; baked binary reports cloudflared version 2026.9.3.
  • No-tunnel container: healthy, {"ok":true,"spans":0,...}, matching the CI smoke-test shape.
  • Token-mode container with a synthetic padding-free token:
    • token value in docker logs: 0 hits by full value and by 24-char prefix - the fix(deploy): keep the tunnel token out of the container log #120 fix is not regressed by the bump.
    • Environmental variables map[TUNNEL_EDGE_IP_VERSION:4] and Settings: map[token:*****] - default applied, token still redacted.
    • edge connection over IPv4 (ip=198.41.192.77), SUMMARY: Environment is healthy.
  • Entrypoint logic across all four modes with stubs: token mode → 4; token mode with TUNNEL_EDGE_IP_VERSION=auto → auto; local-config mode → unset; no tunnel → unset, no cloudflared.
  • Independently re-measured the fix(deploy): keep the tunnel token out of the container log #120 finding on 2026.9.3: a token left in the environment is still printed in full by the startup env dump. The bump does not fix the leak, confirming it belonged in a separate PR.
  • docs VitePress build green; sh -n scripts/entrypoint.sh clean.

Not verified, and it cannot be from here

https://otlp.aignite.pl answering after the real deploy. The production token lives only in the CLOUDFLARE_TUNNEL_TOKEN secret and merging is the deploy, so a 2-year jump cannot be smoke-tested against the real tunnel first. The health gate does not cover this: it probes cotel's /healthz, so a healthy cotel behind a dead tunnel passes.

Pre-deploy baseline captured just now, for comparison straight after the merge:

# tunnel alive -> 401 from cotel. A dead tunnel gives a Cloudflare 530/1033 page instead.
curl -s -X POST -H 'Content-Type: application/json' -d '{"resourceSpans":[]}' \
  https://otlp.aignite.pl/v1/traces
# baseline now: HTTP 401 {"error":"unauthorized"}

ssh robmini 'docker exec cotel-cotel-1 /usr/local/bin/cloudflared --version'
# baseline now: 2024.11.1  -> must read 2026.9.3 after the deploy

ssh robmini 'docker logs cotel-cotel-1 2>&1 | grep -o "Environmental variables map\[[^]]*\]"'
# must not contain CLOUDFLARE_TUNNEL_TOKEN (no secret needed to check this)

ssh robmini 'curl -s localhost:8080/healthz'
# newest_span_age_seconds should stay low: live traffic arrives via the public tunnel

Rollback is the previous image, which is still on the host.

2024.11.1 was two years of fixes behind. The pin stays explicit rather
than moving to `latest`, so rebuilding an old commit still produces the
binary it originally shipped.

One change in that window touches cotel: 2026.4.0 flipped the
`--edge-ip-version` default from 4 to auto, which follows whichever
address family the resolver answers with first and falls back to the
other only after a connection has already failed. Token mode now
defaults `TUNNEL_EDGE_IP_VERSION` to 4, holding the behaviour the old
version had; local-config mode is left alone, because that env var
silently outranks an `edge-ip-version` in the operator's own config.yml.

Startup connectivity pre-checks, also new, are kept on: they run
concurrently with startup rather than gating it, and the table they log
separates a blocked UDP path from a bad token — the diagnosis the deploy
health gate cannot make, since it probes cotel's /healthz and not the
tunnel.

`--token-file` is not adopted. It keeps the token out of `ps` inside the
container, but the value stays readable via `docker inspect` and
/proc/1/environ, so it closes no access path in exchange for a tmpfs
mount and a secret on disk.

Co-Authored-By: Wayland <wayland@agents.flopbut.local>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 40 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 170b317d-ddb4-4c4e-b301-8a5210e6d93e
📥 Commits

Reviewing files that changed from the base of the PR and between c6ec581 and b0b43c6.

📒 Files selected for processing (7)
  • CHANGELOG.md
  • Dockerfile
  • README.md
  • docs/decisions/0006-cloudflare-tunnel-and-token-auth.md
  • docs/operations/cloudflare-tunnel-local.md
  • docs/operations/cloudflare-tunnel-remote.md
  • scripts/entrypoint.sh
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Fl0p
Fl0p merged commit fe3d5d6 into main Oct 4, 2026
5 checks passed
@Fl0p
Fl0p deleted the flo-975-cloudflared-bump branch October 4, 2026 18:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant