A Cloudflare Tunnel Connector That Keeps Its Token Off The Command Line

cloudflared from Cloudflare's signed repository (a 2025 key rpm on EL 10 accepts), pinned, run as a hardened unit that reads the tunnel token from a root-only file, not from the unit or ps. Never self-updating. The live test greps the unit and the connector's command lines for the token and expects nothing. Original role, live-tested on Rocky Linux 10.

This is the operations reference: version drift, dependants and neighbours. For what the module provisions, its inputs and outputs, and how to buy it, see the catalogue entry.

ansibleCloudflareNetworking & VPCv1.0.0live-tested

Provider drift

This artifact declares no Terraform provider requirements, so there is nothing to drift. Provider freshness applies to Terraform and OpenTofu modules.

What depends on this

No reference architecture names this module, so changing it affects only configurations that reference it directly.

Nearest alternatives

Nothing else in the catalogue covers networking & vpc on Cloudflare. If this module is not the right shape, the closest options are on other clouds.

The same job on other clouds

This module has no cross-cloud peer set in the catalogue, so there is no portability comparison to draw.

Installing it

module "ansible_cloudflared_tunnel" {
  source  = "www.iac-bazaar.com/iac-bazaar/ansible-cloudflared-tunnel/cloudflare"
  version = "1.0.0"
}

A registry token is required for the download itself. Installing through the registry protocol has the two credential steps.