cloudflared on the command line, the create command creates the .pemcloudflared login to create a cert.

nginx config is, Tunnel might be able to replace it entirely.X-Forwarded-For?X-Real-IP.nginx


want to know if cache page server from nearest data center to website visitor or not.It's the one they connect to yea
would be great if someone has a workaround or if they make it possible! i can think of many reasons it would be a huge benefit such as less scanners to deal with, no privileged port issues, no proxy setups + more flexibility is always helpful for dx :PrayToTheLordAmen:If your setup is right it shouldn't really matter for security, only Allowlist Cloudflare (https://github.com/Paul-Reed/cloudflare-ufw), verify host header is right (if you're using something like nginx with server_name, it's doing this), and if you're really paranoid set up Auth. Origin Pulls. Cloudflare Tunnels are a great choice as well to just have a lot of the security done for you, and allow you to run mutiple services without something like nginx (even though nginx is really lite, I run it in front of all my web services even if there not sharing with anything)