# cf-managed-network-endpoint

cf-managed-network-endpoint is a self-hosted network services app. TLS endpoint for Cloudflare Zero Trust "Managed Networks". It is open source and self-hosted, installable on Unraid.

Canonical page: https://ourlocalhost.com/app/6835/cf-managed-network-endpoint

## Description

TLS endpoint for Cloudflare Zero Trust "Managed Networks". Serves a self-signed certificate on port 6443; the Cloudflare WARP client compares its SHA-256 fingerprint to tell whether a device is on the home network. No application logic. The certificate is created once, on the very first start, and kept in the Config folder (keys/). As long as that folder survives, the fingerprint stays the same across restarts and image updates. NEVER delete it: a new certificate means a new fingerprint, and network detection breaks silently. Include the appdata folder in your backups. The fingerprint is printed in the container log on every start (Unraid: container icon -> Logs). Upgrading from a version before 1.0.0: keep the old /certs path below for the first start, so the existing certificate is taken over. Then remove it. Network: a custom VLAN interface (e.g. br0.10) must exist on the machine;

## Platform availability

Available on 1 of 6 install platforms: Unraid.

## Health score

41/100 (Fair), based on 3 of 4 factors.
- Maintained: 77 (last commit 2 days ago)
- Popular: 0 (0 GitHub stars)
- Easy to install: 20 (1 install platform, Docker image)

## Links

- Unraid: https://ca.unraid.net/apps/cf-managed-network-endpoint-16lfdig0q84zgs?q=cf-managed-network-endpoint
- GitHub: https://github.com/Tom-Joad/cf-managed-network-endpoint

## Common questions

### Which folder should I back up to keep the Cloudflare fingerprint stable?

Back up the persistent config volume, including /config/keys where cert.crt and cert.key are stored. If that folder survives, the fingerprint remains the same across restarts and updates.

### What happens if I delete the certificate folder?

The container will create a new certificate with a new fingerprint, and Cloudflare managed-network detection can break silently. If only one of the two key files exists, it aborts instead of creating a new pair.

### Which port does the endpoint need?

It serves the TLS endpoint on port 6443. With a custom VLAN interface, the container listens on its own IP and no port mapping is needed.

### When does the Cloudflare client recheck for managed networks?

It scans when the OS default route changes, the active Wi-Fi SSID changes, or the DNS servers of the default interface change.

### Do I need a separate endpoint for every home location?

No, Cloudflare says to reuse the same TLS endpoint across multiple locations to minimize performance impact.

---
Source: Our Local Host (https://ourlocalhost.com/app/6835/cf-managed-network-endpoint), the self-hosted and open-source app directory.
