Cloudflare Zero Trust Architecture
Cloudflare Tunnel Connector Sizing Calculator: How Many Replicas
Estimate how many cloudflared connector replicas to plan for from your active users and redundancy choice. Review the bandwidth and posture figures alongside the assumptions below; these are planning estimates, not Cloudflare capacity ratings.
Recommended Connectors
2 cloudflared daemons
Planning Bandwidth
1.25 Gbps
at 5 Mbps per active user
Posture Evaluations
3,000 / hour
users x checks per hour
What these numbers assume
- Connectors scale with the redundancy level you pick and add a further set per 1,000 active users. Cloudflare documents that each
cloudflaredinstance already opens four connections to four servers across at least two data centers, so extra replicas buy you host-level redundancy, not edge-level redundancy. - Bandwidth uses a flat 5 Mbps per concurrently active user. That is a planning placeholder, not a measurement. If your traffic is video, backups or large file transfer, raise it; if it is thin internal web apps, lower it.
- Posture evaluations is arithmetic on your own inputs: the user count multiplied by the number of checks per hour implied by the frequency you selected. It counts one enrolled device per user, so if your people carry a laptop and a phone, double it. It is useful for reasoning about log volume and client chatter, not for capacity on Cloudflare's side.
- Not modelled: latency. Round-trip time depends on user location, edge proximity, origin distance and application behaviour, and any single figure printed here would be invented. Measure it from where your users actually are.
Hard limits to check against
Cloudflare publishes per-account Zero Trust limits. These are the ones that constrain a growing deployment:
- Access applications per account: 500
- Rules per application: 1,000
- Domains per application: 50
cloudflaredtunnels per account: 1,000- Routes (CIDR + hostname) per account: 1,000
- Identity providers: 50 · Service tokens: 50
Your 18 ingress routes use 3.6% of the 500-application account limit.
Source: Cloudflare One account limits. Limits change; check the current page before designing around one.
Before you size, get one tunnel working
Capacity planning is the second problem. These guides cover the first one.
- Cloudflare Tunnel setup: your first tunnel step by step — prerequisites, both setup paths, ingress rule ordering and the replica caveats behind the connector count above.
- Cloudflare tunnel not connected: fixing error 1033 — why connectors disappear, and which redundancy actually prevents it.
- Zero Trust access and tunnels instead of VPN ingress — the policy layer that decides who gets through the tunnel you just sized.
- Cloudflare Access vs Tailscale: architecture compared — worth reading before committing to a proxied model at all.