<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cloudflare-Tunnel on Mohammad Jashem — Senior Full-Stack Mobile Engineer</title><link>https://mjashem.com/tags/cloudflare-tunnel/</link><description>Recent content in Cloudflare-Tunnel on Mohammad Jashem — Senior Full-Stack Mobile Engineer</description><generator>Hugo -- gohugo.io</generator><language>en</language><managingEditor>mjashem@hotmail.com (Mohammad Jashem)</managingEditor><webMaster>mjashem@hotmail.com (Mohammad Jashem)</webMaster><lastBuildDate>Sun, 19 Jul 2026 00:00:00 +0600</lastBuildDate><atom:link href="https://mjashem.com/tags/cloudflare-tunnel/index.xml" rel="self" type="application/rss+xml"/><item><title>Self-Hosted Hugo CI/CD: Drone + Cloudflare Tunnel</title><link>https://mjashem.com/insights/hugo-cicd-self-hosted-drone/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0600</pubDate><author>mjashem@hotmail.com (Mohammad Jashem)</author><guid>https://mjashem.com/insights/hugo-cicd-self-hosted-drone/</guid><description>&lt;p&gt;Push to &lt;code&gt;main&lt;/code&gt;. Hugo rebuilds in CI, the built site ships to the server over SCP, the container force-recreates, and the new content is live in well under a minute, in practice. No port ever opens on the server. That last part is the whole point — and once you&amp;rsquo;ve run a static site this way, the idea of exposing a box to the internet to serve HTML feels archaic.&lt;/p&gt;</description></item><item><title>Zero-Trust Homelab: Cloudflare Tunnel, Traefik, No Ports</title><link>https://mjashem.com/insights/self-hosted-zero-trust-homelab/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0600</pubDate><author>mjashem@hotmail.com (Mohammad Jashem)</author><guid>https://mjashem.com/insights/self-hosted-zero-trust-homelab/</guid><description>&lt;p&gt;Most homelab guides tell you to forward ports 80 and 443 on your router and put your home IP in DNS. This one opens zero inbound ports. The whole fleet — photos, passwords, CI, dev environments, this site — sits behind a single outbound tunnel that terminates on the router itself. No port to forward, no public IP to leak.&lt;/p&gt;</description></item></channel></rss>