Credential access
Reads tunnel credentials, Cloudflare tokens, and local tunnel config.
brew / Protected-Tool-Abdeckung / Rang 256
Prüfe Installationswege, Executables, Metadaten und Sicherheitshinweise für cloudflared in AI-Agent-Workflows.
agent safety
cloudflared manages tunnels, DNS-facing connectivity, and Cloudflare access paths.
Reads tunnel credentials, Cloudflare tokens, and local tunnel config.
Can create tunnels, route traffic, and update service exposure.
Can expose local or internal services to the network.
Gate tunnel creation, route changes, token use, and service exposure.
Allow tunnel status checks; require approval before exposing endpoints or changing routes.
Installation
sudo av install brew:cloudflaredbrew install cloudflaredlocal Homebrew formula metadata
sudo port install cloudflaredMacPorts ports tree · net/cloudflared/Portfile · source: api.github.com
sudo apk add cloudflaredAlpine Linux edge package indexes · cloudflared · source: dl-cdn.alpinelinux.org
nix profile install nixpkgs#cloudflarednixpkgs package indexes · pkgs/by-name/cl/cloudflared/package.nix · source: api.github.com
sudo pacman -S cloudflaredArch Linux sync databases · cloudflared · source: geo.mirror.pkgbuild.com
sudo zypper install cloudflaredopenSUSE Tumbleweed package metadata · cloudflared · source: download.opensuse.org
choco install cloudflaredChocolatey community package catalog · cloudflared · source: community.chocolatey.org
scoop install main/cloudflaredScoop official bucket manifest trees · bucket/cloudflared.json · source: api.github.com
winget install --id Cloudflare.cloudflared -eWindows Package Manager source index · Cloudflare.cloudflared · source: cdn.winget.microsoft.com
Überblick
Cloudflare Tunnel client (formerly Argo Tunnel)
https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/
Protected-Tool-Abdeckung
cloudflared stores tunnel certificates and tunnel credential JSON files under its user configuration directory. Those files can authorize a tunnel without another interactive login. Automic Vault detects plaintext certificate private keys and tunnel credential JSON files, but does not migrate them because tunnel state is mutable service/deployment configuration.
orange risk · medium confidence · infrastructure
Lokaler README-Auszug
Detect-only coverage for Cloudflare Tunnel credentials.
cloudflared tunnel state can include certificate private keys and tunnel credential JSON files. These are service credentials, so this protected-tool coverage reports bounded user-level exposures without changing tunnel configuration.
Quelle: local coverage notes
Quellauszug
Executables
| Befehl | Art | Sichtbarkeit | Hinweis |
|---|---|---|---|
cloudflared | cli | global executable |
Aktualität
Diese Signale trennen das Alter der Seitengenerierung, Aktivität des Paketmanagers und Upstream-Release-Vergleich. Versionsrückstand wird nur gemeldet, wenn eine Evidenz-URL und vergleichbare Versionen vorhanden sind.
https://github.com/cloudflare/cloudflared
Installationsmetadaten
| Package key | brew:cloudflared |
|---|---|
| Version | 2026.6.0 |
| Package manager | Homebrew |
| Package manager page | https://formulae.brew.sh/formula/cloudflared |
| Homepage | https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/ |
| Repository | https://github.com/cloudflare/cloudflared |
| Upstream docs | https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel |
| License | Apache-2.0 |
| Source archive | https://github.com/cloudflare/cloudflared/archive/refs/tags/2026.6.0.tar.gz |
| Last updated | 2026-06-09T13:40:23Z |
| Pulse | updated |
| Build dependencies | go |
| Bottle | available (arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux) |
| Homebrew post-install | not defined |
| Service | declared |
registry facts
| Source Database | Homebrew formula API |
|---|---|
| Tap | homebrew/core |
| Full Name | cloudflared |
| Version Scheme | 0 |
| Revision | 0 |
| Head Version | HEAD |
| Bottle Stable Root URL | https://ghcr.io/v2/homebrew/core |
| Deprecated | no |
| Disabled | no |
| Keg Only | no |
| URL Keys |
|
source database matches
Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.
cloudflared
nix profile install nixpkgs#cloudflaredcloudflared 2026.5.0-r0
Cloudflare Tunnel client
https://github.com/cloudflare/cloudflared
sudo apk add cloudflaredcloudflared-doc 2026.5.0-r0
Cloudflare Tunnel client (documentation)
https://github.com/cloudflare/cloudflared
sudo apk add cloudflared-doccloudflared-openrc 2026.5.0-r0
Cloudflare Tunnel client (OpenRC init scripts)
https://github.com/cloudflare/cloudflared
sudo apk add cloudflared-openrccloudflared 2026.5.1-1
Command-line client for Cloudflare Tunnel
https://github.com/cloudflare/cloudflared
sudo pacman -S cloudflaredcloudflared 2026.2.0-1.4
Cloudflare Tunnel client
https://github.com/cloudflare/cloudflared
sudo zypper install cloudflaredcloudflared
sudo port install cloudflaredcloudflared
choco install cloudflaredmain/cloudflared
scoop install main/cloudflaredCloudflare.cloudflared
winget install --id Cloudflare.cloudflared -eQuellspur
Diese Seite wird von av-web aus dem privaten Paket-SQLite-Artefakt bereitgestellt, das scripts/generate-pkg-sqlite.py erstellt.