Help Needed with Cloudflare Zero Trust, Pages, and Workers for ReactFlux + MiniFlux Setup
Hi everyone,
I'm new to #Cloudflare and have been trying to set up a #SelfHosted project on my #RaspberryPi 500. I'm mostly self-taught, so I apologize if I misunderstand anything or miss important details. Here's my situation:
Current Setup
-
I'm running the self-hosted #RSS feed reader #MiniFlux on my Raspberry Pi 500 (#ArchLinuxARM, installed via Pacman).
-
The setup uses #Caddy as a reverse proxy, a #CloudflareZeroTrust tunnel, and Cloudflare Access for SSO.
-
My #CloudflareAccess application is configured to allow all origins, methods, and headers. It has a policy that allows specific emails or login methods (e.g., GitHub).
What I'm Trying to Do
-
I want to deploy ReactFlux, an alternative frontend for MiniFlux, on #CloudflarePages.
-
Before setting it up fully, I tested the ReactFlux demo with my MiniFlux instance at
https://rss.laniecarmelo.tech. However, ReactFlux couldn't log in.
Suspected Issue
I believe the issue is caused by Cloudflare Access protection blocking ReactFlux from accessing the MiniFlux API (https://rss.laniecarmelo.tech/v1/*).
What I've Tried So Far
-
I added another hostname (
rss.laniecarmelo.tech/v1/*) to my tunnel configuration and created a new Cloudflare Access application with a policy set to "Bypass" for everyone. However, this didn't work—when testing the API endpoint in a private browser window, I'm still asked to sign into Cloudflare. -
I also tried setting up the hostname with "Protect with Access" turned off but got the same results.
-
Next, I attempted to use a #CloudflareWorker written in JavaScript to bypass authentication for
/v1/*, but it doesn't seem to be doing anything (or isn't being triggered).
What I Need Help With
-
How can I properly configure Cloudflare so ReactFlux can access the MiniFlux API (
/v1/*) while keeping the rest of my MiniFlux instance protected by Cloudflare Access? -
I've been stuck on this for a couple of days and would really appreciate any guidance or suggestions!
Thanks in advance for your help!
#SelfHosting #ArchLinux #Linux #RSSReader #tech #technology #RaspberryPi #RPi #RPi500 #RaspberryPi500
@selfhosting @selfhost @selfhosted
2 Comments
athos@bolha.one · 1 pts · 1y
RareBird15@allovertheplace.ca · 1 pts · 1y
@athos @selfhosting @selfhost @selfhosted I wasn't aware of this before, but I just tried it and still had no luck. I added both paths to my MiniFlux Cloudflare Access application with the /v1/* path first, then added two policies, one for API access, set to bypass for everyone, and one for MiniFlux in general, set to allow for certain emails or login methods. I made sure the API access policy was on top. After that, rss.laniecarmelo.tech would always give me a 403 forbidden error. If I set the API access policy to allow for everyone, it always asked to sign into Cloudflare.
sm@sauna.social · 1 pts · 1y
@RareBird15 @selfhosting @selfhost @selfhosted
Some questions: