Route public traffic to private applications with Cloudflare

๐กSecurely expose your private AI model endpoints to the public without complex network configuration or public IPs.
โก 30-Second TL;DR
What Changed
Enables routing of public hostnames to private IP origins.
Why It Matters
This simplifies secure access to private AI model endpoints or internal data services by leveraging existing infrastructure. It reduces the attack surface for developers hosting private AI backends.
What To Do Next
Sign up for the closed beta if you need to expose internal AI inference servers to public traffic without managing complex VPN or public IP infrastructure.
Key Points
- โขEnables routing of public hostnames to private IP origins.
- โขSupports existing IPsec, GRE, CNI, or Cloudflare Mesh network paths.
- โขEliminates the need for public IP addresses or extra connector software.
๐ง Deep Insight
Web-grounded analysis with 11 cited sources.
๐ Enhanced Key Takeaways
- โขCloudflare's full suite of security, performance, and programmability services, including WAF, bot management, rate limiting, caching, rewrites, and Workers, can now protect applications running on private networks without requiring public IP exposure or inbound firewall rules.
- โขThe service extends beyond HTTP/HTTPS, supporting any TCP/UDP service running on a private IP, such as databases or logging endpoints, allowing them to remain private.
- โขThe feature is currently in closed beta for eligible Enterprise customers, with General Availability (GA) targeted for Q4 2026.
- โขIt integrates by extending Cloudflare's private networking layer into the application services stack, enabling the proxy infrastructure to treat private IPs as valid origin targets for public hostnames via DNS record configuration.
๐ Competitor Analysisโธ Show
| Feature/Aspect | Cloudflare (Application Services for Private Origins / Cloudflare One) | Zscaler (ZPA) | Palo Alto Networks (Prisma Access) | Google (BeyondCorp Enterprise) | AWS (Verified Access) | Pomerium | Tailscale |
|---|---|---|---|---|---|---|---|
| Core Offering | ZTNA at the edge, integrates application services (WAF, CDN, Workers) with private network routing for public hostnames to private origins. Supports HTTP/HTTPS, TCP/UDP. | Market leader in ZTNA/SASE, secure access to internal applications without exposing them to the internet. Comprehensive SASE platform. | Comprehensive SASE and Zero Trust solution, advanced threat protection, secure remote access, cloud-delivered security infrastructure. | Chrome-centric Zero Trust, built on Chrome Enterprise, Identity-Aware Proxy (IAP), and Google's global network. Deeply integrated with GCP. | ZTNA specifically for applications hosted on AWS, integrates with AWS networking primitives and identity services. | Identity-aware proxy, self-hostable, context-aware access, VPN-free experience. Claims faster performance when self-hosted. | Mesh VPN based on WireGuard, zero-configuration, identity-aware, secure private network for devices. |
| Deployment Model | Cloud-native, leverages Cloudflare's global edge network. Uses existing network paths (IPsec, GRE, CNI, Cloudflare Mesh). | Cloud-delivered security infrastructure. | Cloud-delivered security infrastructure. | Cloud-native, integrated with Google's global network and Chrome Enterprise. | Cloud-native, integrated with AWS infrastructure. | Can be self-hosted at the edge or cloud-based. | Software clients on devices, forms a mesh network. |
| Key Differentiator | Unifies public-facing application security (WAF, CDN) with private origin access, eliminating separate stacks. Free for 50 users for ZTNA. | Purpose-built ZTNA/SASE architecture, strong enterprise adoption (45%+ Fortune 500). | Advanced threat protection and comprehensive SASE for large enterprises. | Deep integration with Google ecosystem, architectural purity, Chrome as endpoint. | Native integration and optimized for AWS-hosted applications. | Self-hostable, context-aware access, potentially faster for edge deployments. | Simplifies secure point-to-point connections with WireGuard and identity. |
| Pricing | Varies by enterprise plan; ZTNA free for up to 50 users. | Enterprise-focused, custom pricing. | Enterprise-focused, custom pricing. | Enterprise-focused, custom pricing; zero incremental cost for existing Entra ID users. | Usage-based, integrated with AWS billing. | Varies by plan, RBAC and SSO integrations at higher tiers. | Varies by plan, open-source available. |
| Benchmarks | Optimized, intelligence-driven routing across Anycast network. Zero cold starts for Workers. | Focus on threat protection (500B+ daily transactions). | Not publicly disclosed for direct comparison. | Not publicly disclosed for direct comparison. | Not publicly disclosed for direct comparison. | Claims faster than Cloudflare Zero Trust Access when self-hosted. | Not publicly disclosed for direct comparison. |
๐ ๏ธ Technical Deep Dive
- The service extends Cloudflare's private networking layer directly into the application services stack, allowing security and performance proxy infrastructure to treat private IPs as valid origin targets for public hostnames.
- It requires existing Cloudflare One connectivity, such as IPsec, GRE, Cloudflare Network Interconnect (CNI), or Cloudflare Mesh network paths.
- A return route for Cloudflare's source IP range (100.64.0.0/12) must be configured in the private network to ensure proper traffic flow.
- For HTTP/HTTPS applications, configuration involves creating or editing a DNS A or AAAA record, enabling proxy status (orange cloud), and turning on the 'Use private network routing' toggle.
- Private IP address ranges (RFC 1918, RFC 6598, RFC 4193) are automatically detected for private network routing, but the toggle can be manually enabled for public IP addresses only reachable through the private network.
- For TCP/UDP services (Spectrum applications), private origins are initially supported through Cloudflare Tunnel, with plans for additional private network connectivity options in future releases.
- Workers VPC allows Cloudflare Workers to reach private origins through the same private path using specific bindings.
- When using Cloudflare WAN (formerly Magic WAN) IPsec, the setup requires configuring two anycast IPsec tunnels for redundancy, adding static routes with different priorities for failover, and setting the Cloudflare Source IP to a private range.
๐ฎ Future ImplicationsAI analysis grounded in cited sources
โณ Timeline
๐ Sources (11)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
Weekly AI Recap
Read this week's curated digest of top AI events โ
๐Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: Cloudflare Blog โ
