Help Needed with Cloudflare Zero Trust, Pages, and Workers for ReactFlux + MiniFlux Setup

Help Needed with Cloudflare Zero Trust, Pages, and Workers for ReactFlux + MiniFlux Setup

Hi everyone,

I'm new to #Cloudflare and have been trying to set up a #SelfHosted project on my #RaspberryPi 500. I'm mostly self-taught, so I apologize if I misunderstand anything or miss important details. Here's my situation:

Current Setup

  • I'm running the self-hosted #RSS feed reader #MiniFlux on my Raspberry Pi 500 (#ArchLinuxARM, installed via Pacman).

  • The setup uses #Caddy as a reverse proxy, a #CloudflareZeroTrust tunnel, and Cloudflare Access for SSO.

  • My #CloudflareAccess application is configured to allow all origins, methods, and headers. It has a policy that allows specific emails or login methods (e.g., GitHub).

What I'm Trying to Do

  • I want to deploy ReactFlux, an alternative frontend for MiniFlux, on #CloudflarePages.

  • Before setting it up fully, I tested the ReactFlux demo with my MiniFlux instance at https://rss.laniecarmelo.tech. However, ReactFlux couldn't log in.

Suspected Issue

I believe the issue is caused by Cloudflare Access protection blocking ReactFlux from accessing the MiniFlux API (https://rss.laniecarmelo.tech/v1/*).

What I've Tried So Far

  1. I added another hostname (rss.laniecarmelo.tech/v1/*) to my tunnel configuration and created a new Cloudflare Access application with a policy set to "Bypass" for everyone. However, this didn't work—when testing the API endpoint in a private browser window, I'm still asked to sign into Cloudflare.

  2. I also tried setting up the hostname with "Protect with Access" turned off but got the same results.

  3. Next, I attempted to use a #CloudflareWorker written in JavaScript to bypass authentication for /v1/*, but it doesn't seem to be doing anything (or isn't being triggered).

What I Need Help With

  • How can I properly configure Cloudflare so ReactFlux can access the MiniFlux API (/v1/*) while keeping the rest of my MiniFlux instance protected by Cloudflare Access?

  • I've been stuck on this for a couple of days and would really appreciate any guidance or suggestions!

Thanks in advance for your help!

#SelfHosting #ArchLinux #Linux #RSSReader #tech #technology #RaspberryPi #RPi #RPi500 #RaspberryPi500
@selfhosting @selfhost @selfhosted

1 points · 2 comments · view on lemmy.world

2 Comments

athos@bolha.one · 1 pts · 1y (1 reply)
[ removed ]
RareBird15@allovertheplace.ca · 1 pts · 1y

@athos @selfhosting @selfhost @selfhosted I wasn't aware of this before, but I just tried it and still had no luck. I added both paths to my MiniFlux Cloudflare Access application with the /v1/* path first, then added two policies, one for API access, set to bypass for everyone, and one for MiniFlux in general, set to allow for certain emails or login methods. I made sure the API access policy was on top. After that, rss.laniecarmelo.tech would always give me a 403 forbidden error. If I set the API access policy to allow for everyone, it always asked to sign into Cloudflare.

sm@sauna.social · 1 pts · 1y

@RareBird15 @selfhosting @selfhost @selfhosted

Some questions:

  1. Have you checked the browser console and/or browser’s network tab when it won’t let you log in?
  2. Have you checked the logs from the cf workers event log if you have it deployed to your own worker?