cf-managed-network-endpoint

TLS endpoint for Cloudflare Zero Trust "Managed Networks".

  • Network Services
  • Security
TLS endpoint for Cloudflare Zero Trust "Managed Networks". Serves a self-signed certificate on port 6443; the Cloudflare WARP client compares its SHA-256 fingerprint to tell whether a device is on the home network. No application logic. The certificate is created once, on the very first start, and kept in the Config folder (keys/). As long as that folder survives, the fingerprint stays the same across restarts and image updates. NEVER delete it: a new certificate means a new fingerprint, and network detection breaks silently. Include the appdata folder in your backups. The fingerprint is printed in the container log on every start (Unraid: container icon -> Logs). Upgrading from a version before 1.0.0: keep the old /certs path below for the first start, so the existing certificate is taken over. Then remove it. Network: a custom VLAN interface (e.g. br0.10) must exist on the machine;

Platform availability

Available on 1 of 6 install platforms

  • Unraid
  • TrueNAS (not listed)
  • Umbrel (not listed)
  • ZimaOS (not listed)
  • Proxmox (not listed)
  • Helm (not listed)

Also on GitHub

Health score

41/100 Fair

Maintained
77last commit 2 days ago
Popular
00 GitHub stars
Easy to install
201 install platform, Docker image
Light to run
No data

Based on 3 of 4 factors.

How is this calculated?

A 0-100 score computed nightly from four factors: maintained (40%: recent commits and steady activity), popular (25%: GitHub stars, log scale), easy to install (20%: platforms, install notes, setup guides, Docker image) and light to run (15%: minimum RAM, ARM support). Factors without data are left out and the rest are rescaled.

Availability: platform listings confirmed today

GitHub stars
0
Open issues
0
Last commit
2026-10-04
Latest release
v1.0.2
License
MIT
Activity
rising

Checked today - source: GitHub (Tom-Joad/cf-managed-network-endpoint)

Resources & Compatibility

Requirements not published yet.

Checked today - source: Docker Hub image tags and published docs

First-install notes

No first-install notes yet.

Alternatives

No alternatives collected yet.

Common questions

Which folder should I back up to keep the Cloudflare fingerprint stable?

Back up the persistent config volume, including /config/keys where cert.crt and cert.key are stored. If that folder survives, the fingerprint remains the same across restarts and updates.

What happens if I delete the certificate folder?

The container will create a new certificate with a new fingerprint, and Cloudflare managed-network detection can break silently. If only one of the two key files exists, it aborts instead of creating a new pair.

Which port does the endpoint need?

It serves the TLS endpoint on port 6443. With a custom VLAN interface, the container listens on its own IP and no port mapping is needed.

When does the Cloudflare client recheck for managed networks?

It scans when the OS default route changes, the active Wi-Fi SSID changes, or the DNS servers of the default interface change.

Do I need a separate endpoint for every home location?

No, Cloudflare says to reuse the same TLS endpoint across multiple locations to minimize performance impact.

Answers sourced from developers.cloudflare.com, github.com

Community

No community discussions collected yet.