Cloudflare tunnels config.yml and permissions

What is the name of the domain?

.

What is the issue you’re encountering

I have some questions about tunnel configs and permissions

What steps have you taken to resolve the issue?

Hi everyone,

I have some specific questions regarding the configurations and permissions related to Cloudflare tunnels and I hope someone can help me.

Configurations manageable from config.yml: Could you please indicate what configurations can be managed through the config.yml file generated to handle the tunnels? It’s critical for me to understand what options are available, and I can’t seem to find this information in Cloudflare’s official documentation. Additionally, are there any serious vulnerabilities associated with these parameters?

Permissions of the .json file: Does the .json file used to grant connection permissions to the tunnel provide any additional permissions beyond connecting to the tunnel? For instance, could someone use these secrets to make API calls to Cloudflare, list all tunnels, connect to other tunnels, etc.?

I appreciate any help or guidance you can offer.

Thanks!

Hi @benat.martinez,

Please refer to our Configuration file · Cloudflare Zero Trust docs documentation for information about the configurations that can be managed with the yaml file.

Additionally, you can refer to Useful terms · Cloudflare Zero Trust docs regarding information about the json file.