October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Set Up Cloudflare Tunnel with Docker Compose for Persistent Webhook Debugging

Route webhook traffic through Cloudflare Tunnel to a receiver on a shared Compose network. Learn when to use a Quick Tunnel, how to keep a callback hostname stable, and how to troubleshoot and secure test deliveries.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To give a webhook sender a repeatable URL for a receiver running in Docker Compose, use a named, remotely managed Cloudflare Tunnel with a configured public hostname. Run cloudflared beside your receiver and route the hostname to the receiver’s Compose service name and listening port—for example, http://webhook-receiver:8080. For a one-off test where the URL can change, a Quick Tunnel is simpler, but its hostname is temporary.

How the tunnel reaches a Compose service

The webhook provider sends an HTTPS request to your public hostname. Cloudflare routes that request through the tunnel to the cloudflared connector, which forwards it to the receiver over the containers’ shared Compose network. The connector makes outbound connections to Cloudflare, so this arrangement does not require opening an inbound port on your machine. Cloudflare says each tunnel maintains four long-lived connections to two Cloudflare data centers; that describes the tunnel architecture, not a guarantee that your application or hostname will always be available. Cloudflare Tunnel overview.

Inside the cloudflared container, localhost means that container, not the webhook receiver. Use the receiver’s Compose service name and the port it listens on inside its container. The receiver does not need a published host port solely for cloudflared to reach it when the containers share a network. Cloudflare’s published-application route maps a hostname to a local service URL. Cloudflare’s tunnel setup guide.

Choose a temporary or stable hostname

Option Hostname and setup Limits and best fit
Quick Tunnel Creates a temporary URL without requiring a Cloudflare account or domain. The hostname changes each time. The URL stops working when the process stops; Cloudflare offers no uptime guarantee. Each Quick Tunnel supports up to 200 in-flight requests and does not support SSE. Use it for a disposable test when you can update the provider’s callback URL each time. Cloudflare Quick Tunnels.
Named, remotely managed tunnel Uses a hostname configured for your tunnel. Publishing a hostname requires a Cloudflare account and domain setup. Better suited to saved webhook subscriptions and repeated debugging. Cloudflare recommends remotely managed tunnels for most use cases. A stable hostname still depends on its route and DNS being configured and a connector running; Compose’s restart policy cannot guarantee Cloudflare-side availability. Cloudflare tunnel setup; locally managed tunnel overview.

For a repeatable team workflow, use a named tunnel and its published application route to direct the hostname to a URL such as http://webhook-receiver:8080. Replace the example service name and port with your receiver’s actual Compose service name and container listening port. Quick Tunnels are intended for testing and development, not a persistent callback subscription. Cloudflare Quick Tunnels.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
2 Bay DIY NAS Kit, x86 Home Server, Intel Quad-Core, 16GB RAM,
  • 【Build Your Own NAS & Homelab — Not Just Storage】 More than a traditional NAS, ZimaBlade 7700 is a flexible x86 mini server for building your own homelab, personal cloud, or Docker host. Perfect for DIY NAS, self-hosting, container apps, and even retro systems — not limited like typical ARM-based NAS devices.
  • 【x86 Platform — Broad Compatibility, Real Freedom】 Powered by an Intel quad-core x86 processor, it runs a wide range of operating systems and software with native compatibility. Ideal for Linux, Docker, CasaOS, and more — designed for flexibility and experimentation rather than locked-down appliance use.
  • 【16GB RAM for Smooth Multi-Service Workloads】 Handle file sharing, media streaming, backups, and multiple lightweight services at once. Optimized for low-power, always-on operation — a great fit for home labs and personal servers running 24/7.
  • 【Smooth 4K Media Streaming — Plex Direct Play Ready】 Stream your personal media library smoothly with Plex and similar media servers. Supports 4K playback on compatible devices via direct play, delivering a reliable home media experience without the need for heavy transcoding.
  • 【Complete 2-Bay NAS Kit — Ready to Build】 Includes power supply, 16GB RAM, metal drive cage for 2 HDD/SSD, and dual SATA cables — everything you need to start building your own NAS right out of the box.

Run a named tunnel connector with Docker Compose

The following is an implementation example, not a canonical Cloudflare Compose recipe. Create the named tunnel and configure its public hostname in Cloudflare first; use the tunnel token Cloudflare provides. The token authenticates the connector, so do not commit it in a Compose file or expose it in logs.

services:
  webhook-receiver:
    image: your-webhook-receiver-image
    expose:
      - "8080"
    networks:
      - webhook

  cloudflared:
    image: cloudflare/cloudflared:latest
    command: tunnel --no-autoupdate run --token ${TUNNEL_TOKEN}
    restart: unless-stopped
    networks:
      - webhook

networks:
  webhook:
    driver: bridge

Replace the receiver image, service port, and connector image tag with values appropriate to your application and current official image guidance. For repeatable builds, pin a specific supported cloudflare/cloudflared version rather than relying on latest. Cloudflare documents running the connector in Docker with a tunnel token, but does not prescribe this YAML. Cloudflare’s tunnel setup guide.

Rank #2
Sale
UGREEN NAS DXP2800 2-Bay for Advanced Home Users, Remote Workers & Creators
  • 【Advanced Home Data & Media Hub】For advanced home users who need phone backup, file storage, and centralized data management. Centralize family photos, 4K videos, movies, computer backups, and personal files in one place while running multiple apps for home entertainment and everyday data management. Suitable for households with growing digital libraries and multiple NAS use cases.
  • 【Built for Creators, Media Servers & Advanced Apps】Powered by the Intel N100 Quad-Core CPU, 8GB DDR5 RAM, 2.5GbE networking, and dual M.2 NVMe slots, DXP2800 handles large files and heavier workloads with ease. Run Docker, virtual machines, and media server applications compatible with Plex—ideal for content creators, tech enthusiasts, and advanced home users managing 4K videos, RAW photos, personal media libraries, and multiple NAS apps.
  • 【Up to 80TB for Growing Digital Libraries】 Supports up to 80TB of storage using two HDD bays and two M.2 NVMe SSD slots for family photos, movies, RAW photos, 4K videos, work files, and device backups. AI photo management supports recognition of people, objects, scenes, and locations, album organization, and duplicate photo detection. HDDs and SSDs are not included.
  • 【AI-powered Home Surveillance】Turn DXP2800 into a centralized home surveillance hub by connecting compatible network cameras and storing recordings locally on your NAS. AI-powered features include Face Recognition, People Detection, and Pet Detection, helping advanced home users review important events more efficiently while managing home surveillance and personal data in one place.
  • 【One data Center Across Your Devices】Keep files from desktops, laptops, phones, tablets, and other devices together instead of scattered across cloud accounts and external drives. Access, back up, organize, and share data across Windows, macOS, Android, iOS, web browsers, and compatible smart TVs—ideal for creators and advanced home users working across multiple devices.

Store TUNNEL_TOKEN in a protected environment file excluded from version control, or use a Compose secret and a setup that reads the secret without placing it in committed configuration. Follow the token delivery method supported by your connector invocation. In Cloudflare’s tunnel route, set the service URL to http://webhook-receiver:8080 for this example. The service name must match Compose, and the port must be the receiver’s internal listening port—not a host-published port. Cloudflare’s configuration documentation describes routing hostnames to local services and configuring multiple services or path rewriting. Cloudflare tunnel configuration.

Test and debug a webhook delivery

  1. Check the receiver first. Confirm it starts, listens on the expected port, and can accept requests on the container interface reachable from the Compose network.
  2. Check container routing. Confirm cloudflared and the receiver share a Compose network, and that the tunnel’s service URL uses the receiver’s service name and internal port rather than localhost.
  3. Check the public route. For a named tunnel, verify the hostname is configured for the intended tunnel and published application route. For a Quick Tunnel, use the current URL printed by the running process; an old URL will not follow a restarted Quick Tunnel.
  4. Configure the callback exactly. In the webhook provider, enter the public URL plus the receiver’s required path. Match the expected HTTP method and content type.
  5. Send a test event and inspect both logs. Check application logs for the request and cloudflared logs for forwarding or connection errors. A request that never reaches the receiver points toward hostname, tunnel, network, or origin routing; a receiver response points toward the application’s path, method, status, or validation behavior.
  6. Check signatures and replay carefully. If the integration verifies signatures, validate them against the raw request body as required by that provider. Do not disable signature verification in a real integration just to make a local test pass. Use the provider’s delivery logs and documented replay mechanism; replay behavior and response requirements vary by provider. Cloudflare identifies webhook testing as a tunnel use case, but does not define a universal webhook replay or signature procedure. Cloudflare Workers local development and tunnels; Wrangler tunnel commands.

If delivery fails, use the provider’s recorded status and the two sets of logs to narrow down the fault. A redirect, incorrect path, origin connection failure, unexpected HTTP status, or application-level rejection each requires a different fix; correct the route or receiver behavior, then replay through the provider’s documented process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Protect the exposed development receiver

A public callback URL is reachable by anyone who obtains it unless you add an effective access control. Keep the exposed service narrow: do not route unrelated local services, remove or protect administrative routes, and avoid using live credentials or production data in the development process. Cloudflare warns that a development server exposed by a Quick Tunnel can be accessed by anyone with its URL. Cloudflare Workers local development and tunnels.

Cloudflare’s Quick Tunnel guidance includes email allowlisting, but an interactive browser sign-in is not suitable for a non-interactive webhook sender. For a stable hostname, Cloudflare points to Access as a stronger control; check that the webhook provider can satisfy the policy, or explicitly accommodate its delivery mechanism before enforcing it. Cloudflare Quick Tunnels; Cloudflare Workers local development and tunnels.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.