Cloudflare Tunnel w/ Service Token Unresponsive On Web Browser
I've been running immich for a long time now, love it. I have been having been experiencing some weird behavior with cloudflare zero trust though. Wanted to see if anyone else has seen this before I dig in too far myself...
Setup:
Docker compose runs both Immich and Cloudflare tunnel, the tunnel is setup with two policies, one regular allow via either GitHub SSO or Email Auth, the other is a bypass policy setup for the mobile app using a service token. (Not shure what guide I followed to setup the service token awhile back).
Issue: Ever since setting up the service token I can only successfully log-in to Immich web if I am in a private browser window or clear browser data (Consistent across multiple devices). If I attempt to log-in using on a browser that had been logged in sense resetting browser data it appears as though CF does create the tunnel, because I can see the Immich Logo, but it just sits there and spins (screenshot)...
Troubleshooting Steps:
I did try and move some CF policies around thinking that the order of policies was causing issues, that didn't make any difference. The fact that I am getting to the Immich logo makes me think that it's something on the Immich side, not CF?
Any ideas?
Setup:
Docker compose runs both Immich and Cloudflare tunnel, the tunnel is setup with two policies, one regular allow via either GitHub SSO or Email Auth, the other is a bypass policy setup for the mobile app using a service token. (Not shure what guide I followed to setup the service token awhile back).
Issue: Ever since setting up the service token I can only successfully log-in to Immich web if I am in a private browser window or clear browser data (Consistent across multiple devices). If I attempt to log-in using on a browser that had been logged in sense resetting browser data it appears as though CF does create the tunnel, because I can see the Immich Logo, but it just sits there and spins (screenshot)...
Troubleshooting Steps:
I did try and move some CF policies around thinking that the order of policies was causing issues, that didn't make any difference. The fact that I am getting to the Immich logo makes me think that it's something on the Immich side, not CF?
Any ideas?

