Reverse tunnels
Expose a local port on any host as an HTTPS URL without opening a firewall port. Orizon provisions a Cloudflare Tunnel and a subdomain on our tunnel zone; you run cloudflared on the target host and traffic flows through.
How it works
Creating a tunnel provisions a named Cloudflare Tunnel on Orizon's account and publishes a CNAME on our tunnel zone that points at it. You get back a hostname (e.g. abc123.tun.link) and a cloudflared token. Run cloudflared on the host you want to expose using that token — the tunnel forwards every request that reaches the hostname to the port you chose.
The token is shown ONCEThe cloudflared token is returned exactly once, at creation time. We cannot re-issue it — if you lose it, delete the tunnel and create a new one. This mirrors the show-once contract used for managed-database passwords.
CLI
Requires the Orizon CLI logged in with a platform API key.
# Create a tunnel that forwards traffic to :3000 on the host that runs cloudflared.
orizon tunnel create --name dev --port 3000
# → tun_XXXX https://abc123.tun.link → :3000
# cloudflared token: eyJhIjoi… (save this — it is shown ONCE)
# Start cloudflared on the target host, using the saved token.
orizon tunnel run --token eyJhIjoi…
# Change the local port the tunnel forwards to. cloudflared picks up the
# change on its next config poll (seconds); no reconnect needed.
orizon tunnel update-port tun_XXXX 8080
# Tear the tunnel down (removes the CF resource + DNS record).
orizon tunnel delete tun_XXXXHTTP API
The same operations are available on the public API. See Public API for auth details.
# Create
curl -X POST https://api.orizon.ng/api/v1/tunnels \
-H "Authorization: Bearer orz_pk_your_key_here" \
-H "Content-Type: application/json" \
-d '{"name":"dev","port":3000}'
# List
curl https://api.orizon.ng/api/v1/tunnels \
-H "Authorization: Bearer orz_pk_your_key_here"
# Change the forwarded port
curl -X POST https://api.orizon.ng/api/v1/tunnels/tun_XXXX/port \
-H "Authorization: Bearer orz_pk_your_key_here" \
-H "Content-Type: application/json" \
-d '{"port":8080}'
# Delete
curl -X DELETE https://api.orizon.ng/api/v1/tunnels/tun_XXXX \
-H "Authorization: Bearer orz_pk_your_key_here"Notes
- Tunnels run on Orizon's tunnel zone, not your serving domains. The subdomain is not customer-configurable beyond the optional
slug(3–32 chars, DNS-safe). - You need
cloudflaredon the host that terminates the tunnel. Install it from developers.cloudflare.com/cloudflared/downloads — Orizon does not manage that binary for you. - Feature availability depends on deployment configuration. If the endpoint returns
tunnels_disabled(HTTP 501), tunnels are not enabled on this Orizon instance.