iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
You can make a Dockerized web app running with WSL2 reachable at a Cloudflare hostname by running cloudflared where it can reach the app, then mapping the hostname to the app’s private HTTP service. The key setup choice is the connector’s location: localhost works only when the app is local to that connector. A public hostname is open to internet visitors unless you separately protect it with Cloudflare Access.
How the pieces fit together
The request path is: visitor → Cloudflare hostname → outbound tunnel connection → cloudflared → your app’s HTTP service. Docker networking determines how the connector reaches the app; WSL2 networking determines how Windows, Linux, and Docker Desktop’s networking boundary interact. Cloudflare Tunnel connects outward from your environment, so the tunnel connection itself does not require an inbound router port or a public origin IP. Cloudflare Tunnel documentation
Docker port publishing and the tunnel solve different problems. A published Docker port exposes a container service to a host or local network address; the tunnel provides a route from Cloudflare to the connector. You may need a published port if cloudflared runs on the Windows/WSL host, but a connector in the app’s Docker network can reach the app directly without relying on a host-published port. Docker Desktop normally publishes ports on all interfaces (0.0.0.0); you can bind to a narrower address such as 127.0.0.1 when that suits the topology. Docker Desktop networking
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Choose where cloudflared runs before choosing the service URL
The service URL in the tunnel route must be reachable from the machine or container running cloudflared. Cloudflare’s examples use URLs such as http://localhost:8000 when the service is local to the connector. Protocols for published applications
#1 Best Overall
- DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
- AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
- CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
- EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
- OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.
Connector runs on Windows or in the same WSL distribution
Use a host address and port that the connector can reach. If the app’s container port is published to the host, a URL such as http://localhost:HOST_PORT may be appropriate, but confirm that the connector’s environment can reach that address. The container’s internal listening port and the host-published port can differ; route to the port reachable from cloudflared, not an assumed value.
Connector runs in a separate Docker container
In this arrangement, localhost means the cloudflared container itself, not the app container. A practical Compose design is to attach both containers to a shared Docker network and configure the tunnel’s service URL with the app’s network service name and its listening port, for example http://app:8000 if those are the actual service name and port. This is Docker-network implementation guidance, not a Cloudflare-prescribed Compose recipe; verify that the app listens on the container interface and that both containers share the network.
Rank #2
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
Connector runs elsewhere
Use an address routable from that connector, such as an appropriately reachable host or network address. Do not copy a localhost URL from an example unless the service really is local to cloudflared. Cloudflare allows published application routes to target HTTP or HTTPS services. If the origin uses HTTPS or redirects to HTTPS, follow Cloudflare’s current origin guidance rather than disabling certificate checks casually. Cloudflare protocol guidance
Free tools Windows power users keep installed
One-click scans. No signup required.
Check WSL2 and Docker Desktop networking
WSL uses NAT by default. Windows can ordinarily reach a Linux service through localhost forwarding, while a Linux process reaching a Windows-hosted service generally uses the Windows host IP. Microsoft documents commands to find the relevant addresses instead of relying on hard-coded examples: from Windows, run wsl.exe --distribution <DistroName> hostname -I to see the WSL guest IP; from Linux, run ip route show | grep -i default | awk '{ print $3}' to find the Windows host IP. These addresses and which one you need depend on where the connector and service run. Microsoft’s WSL networking guide
Rank #3
- NIGHTHAWK WIFI 6 ROUTER FOR YOUR WHOLE HOME: Delivers fast, reliable WiFi across every room of your apartment or small home for streaming, gaming, video calls, and smart home devices, all running at the same time without slowing each other down.
- WORKS WITH YOUR EXISTING INTERNET SERVICE: Pairs with your existing modem or gateway via ethernet. Compatible with most cable, fiber, DSL, and satellite providers. Some gateways and modem router combos may require bridge mode. No coax needed.
- SET UP AND MANAGE YOUR NETWORK WITH THE NIGHTHAWK APP: Download the free Nighthawk app on iOS or Android for guided setup. Manage WiFi, run speed tests, pause devices, and set up guest networks from anywhere. Active internet required.
- READY FOR THE DEVICES YOU ALREADY OWN: Your phones, laptops, and TVs work right out of the box. WiFi 6 delivers speeds up to 1.8 Gbps across 2.4 GHz and 5 GHz bands. Backward compatible with WiFi 5 and earlier.
- COVERAGE IN EVERY ROOM: Covers up to 1,500 sq. ft. for up to 20 connected devices. Walls, floors, and interference can reduce range. Larger or multi-story homes may benefit from a NETGEAR Orbi mesh WiFi system.
On Windows 11 version 22H2 and later, WSL also supports mirrored networking, enabled with networkingMode=mirrored in %USERPROFILE%.wslconfig. It changes host/guest connectivity behavior and can improve VPN compatibility, but it is not an automatic fix for every Docker setup. Microsoft currently documents a Docker Desktop issue in which containers with published ports may fail under mirrored networking with the default networking namespace; consult the current troubleshooting guidance before switching modes or applying a workaround. Microsoft WSL troubleshooting
Docker Desktop runs its Engine in a lightweight Linux VM and routes published ports through its backend. Its WSL2 backend guide currently lists WSL 2.1.5 as the minimum and recommends the latest WSL version; requirements can change, so verify the current guide. Enable the WSL2-based engine and integration for the intended distribution. Docker also advises uninstalling Docker Engine or Docker CLI packages installed directly inside a WSL distribution before setup, since running both can cause conflicts. Docker Desktop WSL2 backend guide
Rank #4
- 𝐅𝐮𝐭𝐮𝐫𝐞-𝐏𝐫𝐨𝐨𝐟 𝐘𝐨𝐮𝐫 𝐇𝐨𝐦𝐞 𝐖𝐢𝐭𝐡 𝐖𝐢-𝐅𝐢 𝟕: Powered by Wi-Fi 7 technology, enjoy faster speeds with Multi-Link Operation, increased reliability with Multi-RUs, and more data capacity with 4K-QAM, delivering enhanced performance for all your devices.
- 𝐁𝐄𝟑𝟔𝟎𝟎 𝐃𝐮𝐚𝐥-𝐁𝐚𝐧𝐝 𝐖𝐢-𝐅𝐢 𝟕 𝐑𝐨𝐮𝐭𝐞𝐫: Delivers up to 2882 Mbps (5 GHz), and 688 Mbps (2.4 GHz) speeds for 4K/8K streaming, AR/VR gaming & more. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance, and obstacles like walls.
- 𝐔𝐧𝐥𝐞𝐚𝐬𝐡 𝐌𝐮𝐥𝐭𝐢-𝐆𝐢𝐠 𝐒𝐩𝐞𝐞𝐝𝐬 𝐰𝐢𝐭𝐡 𝐃𝐮𝐚𝐥 𝟐.𝟓 𝐆𝐛𝐩𝐬 𝐏𝐨𝐫𝐭𝐬 𝐚𝐧𝐝 𝟑×𝟏𝐆𝐛𝐩𝐬 𝐋𝐀𝐍 𝐏𝐨𝐫𝐭𝐬: Maximize Gigabitplus internet with one 2.5G WAN/LAN port, one 2.5 Gbps LAN port, plus three additional 1 Gbps LAN ports. Break the 1G barrier for seamless, high-speed connectivity from the internet to multiple LAN devices for enhanced performance.
- 𝐍𝐞𝐱𝐭-𝐆𝐞𝐧 𝟐.𝟎 𝐆𝐇𝐳 𝐐𝐮𝐚𝐝-𝐂𝐨𝐫𝐞 𝐏𝐫𝐨𝐜𝐞𝐬𝐬𝐨𝐫: Experience power and precision with a state-of-the-art processor that effortlessly manages high throughput. Eliminate lag and enjoy fast connections with minimal latency, even during heavy data transmissions.
- 𝐂𝐨𝐯𝐞𝐫𝐚𝐠𝐞 𝐟𝐨𝐫 𝐄𝐯𝐞𝐫𝐲 𝐂𝐨𝐫𝐧𝐞𝐫 - Covers up to 2,000 sq. ft. for up to 60 devices at a time. 4 internal antennas and beamforming technology focus Wi-Fi signals toward hard-to-reach areas. Seamlessly connect phones, TVs, and gaming consoles.
Publish the hostname and route it to the service
- Prepare the app. Confirm its listening port and that it serves HTTP or HTTPS. If the container must be reached from the host, publish its port using the app’s actual container port; bind it narrowly when broad host or local-network access is unnecessary.
- Install and run cloudflared in the chosen location. Check that the connector can reach the service URL before configuring the public route. For a connector sidecar, use the app’s shared-network service address rather than its own localhost.
- Configure the tunnel’s public hostname route. Map the hostname you control to the service URL reachable from cloudflared. Cloudflare supports multiple applications through one tunnel. Follow the current dashboard or configuration instructions for your tunnel type. Published applications and Tunnel routing
- Confirm the domain setup. A hostname requires a domain and route configuration. In Cloudflare’s documented API setup path, you add the website to Cloudflare and change its nameservers to Cloudflare; dashboard steps and labels may vary. Cloudflare published-application setup
- Test from outside your local network. Open the hostname from a device or connection that is not simply reaching the local service. If it fails, check the connector’s status, the exact origin URL and port, app listening interface, and whether Docker/WSL networking allows cloudflared to reach the service.
Decide whether the hostname should be public or restricted
A published hostname can be viewed by internet users unless you secure it with a separate control such as Cloudflare Access. The tunnel is transport and routing, not application authentication. Cloudflare says a paid Access plan is not needed simply to publish an app, while Access seats are needed for policies such as requiring identity-provider login. Publish a self-hosted application to the Internet
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11If only selected people should use the app, configure and test an Access policy before sharing the hostname. Cloudflare documents token validation as a way to help reject requests that bypass Access because of a network misconfiguration. Cloudflare Access guidance
Quick Recap
Best Value
- Dual band router upgrades to 1200 Mbps high speed internet (300mbps for 2.4GHz plus 900Mbps for 5GHz), reducing buffering and ideal for 4K stream
- Full Gigabit Ports - Gigabit Router with 4 Gigabit LAN ports, ideal for any internet plan and allow you to directly connect your wired devices
- Boosted Coverage - Four external antennas equipped with Beamforming technology extend and concentrate the Wi-Fi signals
- MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
Protect the connector and account for the host’s availability
- Keep the tunnel token secret. Anyone with a remotely managed tunnel token can run the tunnel. Do not commit it to source control or expose it in screenshots, shared shell history, or logs. Follow Cloudflare’s current procedure to rotate it regularly. Tunnel permissions
- Limit local exposure. Do not publish Docker ports more broadly than the chosen topology requires. A port bound to all interfaces is broader than one bound to loopback; choose based on which component needs access.
- Plan for the machine being online. A self-hosted app on one Windows workstation depends on that machine, WSL2, Docker Desktop, and the connector continuing to run. It is not inherently a high-availability deployment.
Troubleshoot by following the request path
- The hostname does not load: verify the public-hostname route and that the tunnel connector is running and connected.
- The tunnel reports an origin connection problem: test the configured service URL from the connector’s own environment. Check host versus container localhost, service name, listening port, protocol, and Docker network membership.
- Windows reaches the app but cloudflared does not: confirm whether the connector is in Windows, WSL, or another container. Each has a different network perspective; use the corresponding reachable address rather than assuming localhost is shared.
- Published ports stop working after enabling mirrored networking: review Microsoft’s current WSL troubleshooting page for the Docker Desktop caveat and supported workarounds before changing other parts of the route.
- Visitors can reach an app intended for a small group: add and validate an Access policy. A tunnel route alone does not restrict the audience.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

