
DockFlare
Cloudflare Tunnel ingress controller automated with Docker labels
2.4k stars 107 forks last commit first released
Actively maintained
Last commit 17 Aug 2026.

DockFlare is a self-hosted ingress controller for Cloudflare that automates Cloudflare Tunnel configuration from Docker container labels. It centralizes DNS and Cloudflare Zero Trust Access management, and includes a web UI for manual definitions and policy overrides.
Key Features
- Automatic Cloudflare Tunnel and DNS record management driven by Docker labels
- Web UI for creating services, applying overrides, and managing reusable Access Groups/Policies
- Built-in Identity Provider management for OAuth/OIDC (including generic OIDC)
- Public vs authenticated access modes mapped to Cloudflare Access decisions
- Multi-server “master/agent” architecture for managing workloads across multiple hosts
- Redis-backed coordination for caching and cross-process signaling
- Backup and restore of DockFlare instance data (including encrypted credentials)
Use Cases
- Publish internal services securely without manually configuring Cloudflare dashboards
- Standardize Cloudflare Access policies across many apps using reusable groups
- Orchestrate tunnels and access controls across a homelab or multi-host environment
Limitations and Considerations
- Requires a Cloudflare account and API token permissions to manage tunnels, DNS, and Access resources
- Primarily designed around Docker event/label workflows; non-Docker services may require manual definitions
DockFlare is well-suited for operators who want Cloudflare Tunnel-based ingress with centralized, repeatable policy management. It reduces configuration drift by syncing desired state from labels and UI-managed rules while supporting multi-host environments through agents.
Categories:
Tags:
Tech Stack:
Similar to DockFlare

Pangolin
Identity-aware VPN and reverse proxy for secure remote access
Open-source identity-based remote access platform combining WireGuard VPN and tunneled reverse proxy access with granular zero-trust controls.
OAuth2 Proxy
Reverse proxy and middleware for OAuth2/OIDC authentication
OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.
Calibre-Web Automated
Automated Calibre-Web-based web app for managing eBook libraries
An enhanced Calibre-Web fork that automates eBook ingest, conversion, metadata/cover enforcement, backups, and device sync for a streamlined digital library workflow.
Tinyauth
Lightweight authentication middleware for protecting web apps
Tinyauth is a lightweight auth middleware that adds a login screen, OAuth, or LDAP authentication in front of your apps via common reverse proxies.
Pomerium
Identity- and context-aware access proxy for zero trust access
Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.
GoDoxy
Reverse proxy and container orchestrator for self-hosters
High-performance reverse proxy and container orchestrator with Web UI, automatic Docker/Podman route discovery, idle-sleep, access control, and automated Let's Encrypt support.




