๐Ÿ›ก๏ธStalecollected in 81m

Route public traffic to private applications with Cloudflare

Route public traffic to private applications with Cloudflare
PostLinkedIn
๐Ÿ›ก๏ธRead original on Cloudflare Blog
#networking#security#cloud-infrastructureapplication-services-for-private-originscloudflare

๐Ÿ’กSecurely expose your private AI model endpoints to the public without complex network configuration or public IPs.

โšก 30-Second TL;DR

What Changed

Enables routing of public hostnames to private IP origins.

Why It Matters

This simplifies secure access to private AI model endpoints or internal data services by leveraging existing infrastructure. It reduces the attack surface for developers hosting private AI backends.

What To Do Next

Sign up for the closed beta if you need to expose internal AI inference servers to public traffic without managing complex VPN or public IP infrastructure.

Who should care:Developers & AI Engineers

Key Points

  • โ€ขEnables routing of public hostnames to private IP origins.
  • โ€ขSupports existing IPsec, GRE, CNI, or Cloudflare Mesh network paths.
  • โ€ขEliminates the need for public IP addresses or extra connector software.

๐Ÿง  Deep Insight

Web-grounded analysis with 11 cited sources.

๐Ÿ”‘ Enhanced Key Takeaways

  • โ€ขCloudflare's full suite of security, performance, and programmability services, including WAF, bot management, rate limiting, caching, rewrites, and Workers, can now protect applications running on private networks without requiring public IP exposure or inbound firewall rules.
  • โ€ขThe service extends beyond HTTP/HTTPS, supporting any TCP/UDP service running on a private IP, such as databases or logging endpoints, allowing them to remain private.
  • โ€ขThe feature is currently in closed beta for eligible Enterprise customers, with General Availability (GA) targeted for Q4 2026.
  • โ€ขIt integrates by extending Cloudflare's private networking layer into the application services stack, enabling the proxy infrastructure to treat private IPs as valid origin targets for public hostnames via DNS record configuration.
๐Ÿ“Š Competitor Analysisโ–ธ Show
Feature/AspectCloudflare (Application Services for Private Origins / Cloudflare One)Zscaler (ZPA)Palo Alto Networks (Prisma Access)Google (BeyondCorp Enterprise)AWS (Verified Access)PomeriumTailscale
Core OfferingZTNA at the edge, integrates application services (WAF, CDN, Workers) with private network routing for public hostnames to private origins. Supports HTTP/HTTPS, TCP/UDP.Market leader in ZTNA/SASE, secure access to internal applications without exposing them to the internet. Comprehensive SASE platform.Comprehensive SASE and Zero Trust solution, advanced threat protection, secure remote access, cloud-delivered security infrastructure.Chrome-centric Zero Trust, built on Chrome Enterprise, Identity-Aware Proxy (IAP), and Google's global network. Deeply integrated with GCP.ZTNA specifically for applications hosted on AWS, integrates with AWS networking primitives and identity services.Identity-aware proxy, self-hostable, context-aware access, VPN-free experience. Claims faster performance when self-hosted.Mesh VPN based on WireGuard, zero-configuration, identity-aware, secure private network for devices.
Deployment ModelCloud-native, leverages Cloudflare's global edge network. Uses existing network paths (IPsec, GRE, CNI, Cloudflare Mesh).Cloud-delivered security infrastructure.Cloud-delivered security infrastructure.Cloud-native, integrated with Google's global network and Chrome Enterprise.Cloud-native, integrated with AWS infrastructure.Can be self-hosted at the edge or cloud-based.Software clients on devices, forms a mesh network.
Key DifferentiatorUnifies public-facing application security (WAF, CDN) with private origin access, eliminating separate stacks. Free for 50 users for ZTNA.Purpose-built ZTNA/SASE architecture, strong enterprise adoption (45%+ Fortune 500).Advanced threat protection and comprehensive SASE for large enterprises.Deep integration with Google ecosystem, architectural purity, Chrome as endpoint.Native integration and optimized for AWS-hosted applications.Self-hostable, context-aware access, potentially faster for edge deployments.Simplifies secure point-to-point connections with WireGuard and identity.
PricingVaries by enterprise plan; ZTNA free for up to 50 users.Enterprise-focused, custom pricing.Enterprise-focused, custom pricing.Enterprise-focused, custom pricing; zero incremental cost for existing Entra ID users.Usage-based, integrated with AWS billing.Varies by plan, RBAC and SSO integrations at higher tiers.Varies by plan, open-source available.
BenchmarksOptimized, intelligence-driven routing across Anycast network. Zero cold starts for Workers.Focus on threat protection (500B+ daily transactions).Not publicly disclosed for direct comparison.Not publicly disclosed for direct comparison.Not publicly disclosed for direct comparison.Claims faster than Cloudflare Zero Trust Access when self-hosted.Not publicly disclosed for direct comparison.

๐Ÿ› ๏ธ Technical Deep Dive

  • The service extends Cloudflare's private networking layer directly into the application services stack, allowing security and performance proxy infrastructure to treat private IPs as valid origin targets for public hostnames.
  • It requires existing Cloudflare One connectivity, such as IPsec, GRE, Cloudflare Network Interconnect (CNI), or Cloudflare Mesh network paths.
  • A return route for Cloudflare's source IP range (100.64.0.0/12) must be configured in the private network to ensure proper traffic flow.
  • For HTTP/HTTPS applications, configuration involves creating or editing a DNS A or AAAA record, enabling proxy status (orange cloud), and turning on the 'Use private network routing' toggle.
  • Private IP address ranges (RFC 1918, RFC 6598, RFC 4193) are automatically detected for private network routing, but the toggle can be manually enabled for public IP addresses only reachable through the private network.
  • For TCP/UDP services (Spectrum applications), private origins are initially supported through Cloudflare Tunnel, with plans for additional private network connectivity options in future releases.
  • Workers VPC allows Cloudflare Workers to reach private origins through the same private path using specific bindings.
  • When using Cloudflare WAN (formerly Magic WAN) IPsec, the setup requires configuring two anycast IPsec tunnels for redundancy, adding static routes with different priorities for failover, and setting the Cloudflare Source IP to a private range.

๐Ÿ”ฎ Future ImplicationsAI analysis grounded in cited sources

Cloudflare will further blur the lines between public and private application security.
The announcement explicitly states a move towards a model where the same Cloudflare infrastructure secures traffic regardless of whether the user or origin is public, targeting private-to-private traffic flows beyond General Availability.
Increased adoption of Cloudflare's full SASE (Secure Access Service Edge) platform, Cloudflare One.
This feature integrates core application services (WAF, CDN, etc.) with Cloudflare's private networking, making Cloudflare One a more comprehensive single-vendor SASE solution for securing all types of applications.
Reduced operational complexity and cost for enterprises managing hybrid and multi-cloud environments.
By eliminating the need for public IPs, inbound firewall rules, or separate connector software for private applications, and unifying security and performance services, it simplifies network and security management.

โณ Timeline

2009-07
Cloudflare founded by Matthew Prince, Lee Holloway, and Michelle Zatlyn.
2020-08
Cloudflare Network Interconnect (CNI) introduced for private, dedicated links to Cloudflare's network.
2020-10
Cloudflare One, a comprehensive SASE (Secure Access Service Edge) platform, announced.
2021-06
Cloudflare introduces identity-based, Zero Trust policies for private networks, aiming to replace VPNs.
2023-01
Magic WAN Connector launched to simplify connectivity to Cloudflare's SASE platform.
2026-06
Cloudflare launches Application Services for Private Origins in closed beta.

๐Ÿ“Ž Sources (11)

Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.

  1. cloudflare.com
  2. cloudflare.com
  3. cloudflare.com
  4. cloudflare.com
  5. github.com
  6. strongdm.com
  7. inventivehq.com
  8. pomerium.com
  9. checkthat.ai
  10. controld.com
  11. cloudflare.com
๐Ÿ“ฐ

Weekly AI Recap

Read this week's curated digest of top AI events โ†’

๐Ÿ‘‰Related Updates

AI-curated news aggregator. All content rights belong to original publishers.
Original source: Cloudflare Blog โ†—