The Original Cloudflare-First Setup
The Problem Was The Control Plane
Why Tailscale Became The Primary Entry Point
- SSH uses normal OpenSSH keys.
- Internal admin UIs can stay private.
- Kubernetes access can use a private API path.
- Device names can resolve through MagicDNS.
- Services that do not need public URLs never get public URLs.
What Cloudflare Still Does Better
The Split DNS Shape
The Tailscale Serve Lesson
What Stays Private
Tech Stack
- Tailscale for private device-to-device access into the homelab
- MagicDNS for friendly tailnet device names
- Tailscale DNS with split DNS behavior for trusted devices
- Cloudflare Tunnel with cloudflared connectors for selected public web routes
- Cloudflare Access for identity-aware browser access
- Envoy Gateway + Kubernetes HTTPRoutes for local service routing
- Cloudflare DNS for the public mccarn.tech zone