Can I use cloudflare to allow location from DDNS?

I was wondering if it is possible that I can block a connection to one of my CF tunnel URLs that I do not have an access policy assigned to, but only allow IPs coming from my brothers house to access ?

Is there a way to accomplish this leveraging his DDNS ? Since his public IP will update all the time ?

My use case, I want to host some back up software that I assigned the domain name to a CF tunnel and only his house IP would be able to hit the URL. The idea is for his backup software to hit the domain URL that comes in through my tunnel.

Open to other ideas, but was curious about this one.