SSH certficates for multiple servesr

This is the situation I have:

  • Servers A ( , B ( , and C ( are on a private network
  • Server A is running cloudlfared with CIDR
  • I can access all 3 servers by their private IPs just fine from client devices running WARP.

Now I want to use SSH short-lived certificates. From what I’ve read, each server needs to be running cloudflared, which will be used initially to generate the server keys. Is this correct? I’m ok with each server generating its own keys, but I have no need for them to be running cloudflared full-time.

As an example, in this situation, does Server C needing to running cloudflared with its own tunnel to support SSH short-lived certificates?

