diff --git a/README.md b/README.md index 28a8a30..8b89f3e 100644 --- a/README.md +++ b/README.md @@ -86,10 +86,10 @@ LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. -[addon-cloudflared]: https://github.com/brenner-tobias/addon-cloudflared/tree/v4.0.14 -[addon-doc-cloudflared]: https://github.com/brenner-tobias/addon-cloudflared/blob/v4.0.14/README.md +[addon-cloudflared]: https://github.com/brenner-tobias/addon-cloudflared/tree/v4.1.0 +[addon-doc-cloudflared]: https://github.com/brenner-tobias/addon-cloudflared/blob/v4.1.0/README.md [cloudflared-issue]: https://github.com/brenner-tobias/addon-cloudflared/issues -[cloudflared-version-shield]: https://img.shields.io/badge/version-v4.0.14-blue.svg +[cloudflared-version-shield]: https://img.shields.io/badge/version-v4.1.0-blue.svg [cloudflared-aarch64-shield]: https://img.shields.io/badge/aarch64-yes-green.svg [cloudflared-amd64-shield]: https://img.shields.io/badge/amd64-yes-green.svg [cloudflared-armhf-shield]: https://img.shields.io/badge/armhf-yes-green.svg diff --git a/cloudflared/CHANGELOG.md b/cloudflared/CHANGELOG.md index d806296..19a2451 100644 --- a/cloudflared/CHANGELOG.md +++ b/cloudflared/CHANGELOG.md @@ -1,4 +1,18 @@ ## What’s changed ## 🚀 Enhancements -- Remove uppercase chars from valid hostnames @brenner-tobias (#346) +- Add option for Post-Quantum Crypto @brenner-tobias (#357) + +## 🧰 Maintenance + +- Configure Renovate, incl. auto-merge @renovate, @elcajon + +## 📚 Documentation + +- Add option in documentation for wildcard DNS record @gerard33 (#353) +- Revise the documentation @elcajon (#362) +- Fix name of Zero Trust dashboard and link in Error Message @brenner-tobias (#368) + +## ⬆️ Dependency updates + +- ⬆️ Update Add-on base image to v13.2.0 @renovate (#367) \ No newline at end of file diff --git a/cloudflared/DOCS.md b/cloudflared/DOCS.md index bff012f..882c60b 100644 --- a/cloudflared/DOCS.md +++ b/cloudflared/DOCS.md @@ -85,12 +85,12 @@ advanced config can be achieved using the remote tunnel setup. Example add-on configuration: ```yaml -external_hostname: "ha.example.com" +external_hostname: ha.example.com additional_hosts: - - hostname: "router.example.com" - service: "http://192.168.1.1" - - hostname: "website.example.com" - service: "http://192.168.1.3:8080" + - hostname: router.example.com + service: http://192.168.1.1 + - hostname: website.example.com + service: http://192.168.1.3:8080 ``` **Note**: _This is just an example, don't copy and paste it! Create your own!_ @@ -106,7 +106,7 @@ services. **Note**: _The tunnel name needs to be unique in your Cloudflare account._ ```yaml -external_hostname: "ha.example.com" +external_hostname: ha.example.com ``` ### Option: `additional_hosts` @@ -127,12 +127,12 @@ Please find below an example entry for three additional hosts: ```yaml additional_hosts: - - hostname: "router.example.com" - service: "http://192.168.1.1" - - hostname: "diskstation.example.com" - service: "https://192.168.1.2:5001" - - hostname: "website.example.com" - service: "http://192.168.1.3:8080" + - hostname: router.example.com + service: http://192.168.1.1 + - hostname: diskstation.example.com + service: https://192.168.1.2:5001 + - hostname: website.example.com + service: http://192.168.1.3:8080 disableChunkedEncoding: true ``` @@ -148,7 +148,21 @@ than the default of `homeassistant`. **Note**: _The tunnel name needs to be unique in your Cloudflare account._ ```yaml -tunnel_name: "myHomeAssistant" +tunnel_name: myHomeAssistant +``` + +### Option: `post_quantum` + +If you want Cloudflared to use post-quantum cryptography for the tunnel, +set this flag. + +**Note**: _When `post_quantum` is set, cloudflared restricts itself to QUIC +transport for the tunnel connection. This might lead to problems for some users. +Also, it will only allow post-quantum hybrid key exchanges and not fall back to +a non post-quantum connection._ + +```yaml +post_quantum: true ``` ### Option: `catch_all_service` @@ -162,7 +176,7 @@ as reverse proxy, you should set the flag `nginx_proxy_manager` ([see below](#option-nginx_proxy_manager)) and not use this option._ ```yaml -catch_all_service: "http://192.168.1.100" +catch_all_service: http://192.168.1.100 ``` **Note**: _This will still route your defined `external_hostname`to Home Assistant @@ -174,6 +188,9 @@ CNAME records in Cloudflare for all of them, pointing to your `external_hostname or directly to the tunnel URL that you can get from the CNAME entry of `external_hostname`. +Alternatively you can add a [wildcard DNS record](https://blog.cloudflare.com/wildcard-proxy-for-everyone/) +in Cloudflare by adding a CNAME record with `*` as name. + ### Option: `nginx_proxy_manager` If you want to use Cloudflare Tunnel with the add-on @@ -196,6 +213,9 @@ CNAME records in Cloudflare for all of them, pointing to your `external_hostname or directly to the tunnel URL that you can get from the CNAME entry of `external_hostname`. +Alternatively you can add a [wildcard DNS record](https://blog.cloudflare.com/wildcard-proxy-for-everyone/) +in Cloudflare by adding a CNAME record with `*` as name. + Finally, you have to set-up your proxy hosts in Nginx Proxy Manager and forward them to wherever you like. diff --git a/cloudflared/config.yaml b/cloudflared/config.yaml index 3d97056..8617237 100644 --- a/cloudflared/config.yaml +++ b/cloudflared/config.yaml @@ -1,5 +1,5 @@ name: Cloudflared -version: 4.0.14 +version: 4.1.0 slug: cloudflared description: Use a Cloudflare Tunnel to remotely connect to Home Assistant without opening any ports @@ -29,6 +29,7 @@ schema: disableChunkedEncoding: bool? tunnel_name: str? tunnel_token: str? + post_quantum: bool? catch_all_service: str? nginx_proxy_manager: bool? log_level: list(trace|debug|info|notice|warning|error|fatal)? diff --git a/cloudflared/translations/en.yaml b/cloudflared/translations/en.yaml index c29d974..f13c109 100644 --- a/cloudflared/translations/en.yaml +++ b/cloudflared/translations/en.yaml @@ -19,6 +19,12 @@ configuration: name: Additional Hosts description: >- Define a list of additional hosts to be routed by the Cloudflare Tunnel. + post_quantum: + name: Use Post-Quantum Cryptography + description: >- + Check to make the tunnel use Post-Quantum Cryptography. Warning: This + will also restricts the tunnel to QUIC, which might lead to problems + for some users. catch_all_service: name: Catch-All Service description: >-