The short answer to how to install cloudflared on Ubuntu: add Cloudflare’s signed apt repository, then install the package with apt. It takes three commands. Write the GPG key to /usr/share/keyrings/cloudflare-main.gpg, add a deb line for https://pkg.cloudflare.com/cloudflared any main, and run sudo apt-get update && sudo apt-get install cloudflared. After that, apt delivers updates.
The daemon does nothing until it has a tunnel. This page installs cloudflared, verifies it, runs it under systemd and puts updates under your control. Tunnel creation and Access setup are covered in your first Cloudflare Tunnel, step by step. cloudflared is the tunnel connector, not the WARP client, which WARP compared with a VPN covers.
Which install method should you use on Ubuntu?
Use the apt repository at pkg.cloudflare.com. Packages are verified by a signing key trusted for that repository only. apt upgrades cloudflared with the rest of the system, and nothing restarts on its own. The alternatives (a .deb via dpkg, a standalone GitHub binary or the Docker image) each fit a narrower case.
| Method | Install | Update path | Auto-update | Use it when |
|---|---|---|---|---|
apt repo (pkg.cloudflare.com) | 3 commands | apt-get install --only-upgrade | No | Default for Ubuntu hosts that can reach the repo |
.deb via dpkg -i | Download + dpkg | Re-download + dpkg | No | Offline hosts, or pinning one build |
| Standalone binary (GitHub) | Download, chmod +x, move into PATH | cloudflared update or auto-update | Yes, when run as a service | Minimal images without an extra apt source |
Docker cloudflare/cloudflared | docker run | Pull a new image | Disable with --no-autoupdate | Hosts already running everything in containers |
The auto-update column matters most. Cloudflare’s run parameters reference says built-in updates are “not available on Windows, for package-manager installations, or when cloudflared runs interactively in a terminal.” It also says “the updater does not wait for the replacement process to connect to Cloudflare before shutting down the old process.” --autoupdate-freq defaults to 24h, so a single-connector tunnel risks dropping connections daily, at a time you didn’t pick. Package installs let you schedule updates yourself.
Step 1: add Cloudflare’s apt repository
Cloudflare’s package repository page gives these commands for the any suite:
sudo mkdir -p --mode=0755 /usr/share/keyrings
curl -fsSL https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-main.gpg >/dev/null
echo 'deb [signed-by=/usr/share/keyrings/cloudflare-main.gpg] https://pkg.cloudflare.com/cloudflared any main' | sudo tee /etc/apt/sources.list.d/cloudflared.list
Cloudflare recommends the any suite for any Debian-based distribution. It also publishes release-specific suites: focal (20.04), jammy (22.04) and noble (24.04). Use any unless you need to pin. do-release-upgrade disables third-party sources anyway, and with any you can re-enable the source without editing the codename.
The signed-by= option matters. The Debian wiki’s third-party repository guidance warns against putting a vendor key in the global /etc/apt/trusted.gpg.d store. Doing that “would cause the system to accept signatures from the third-party keyholder on all other repositories configured on the system that don’t have a signed-by option.” Old tutorials using the deprecated apt-key add do exactly that; avoid them.
Keep the nightly suite at next.pkg.cloudflare.com off anything people depend on.
Step 2: install and verify
sudo apt-get update && sudo apt-get install cloudflared
cloudflared --version
apt-cache policy cloudflared
ls -la /usr/local/etc/cloudflared/
cloudflared --version shows the installed build. As of this writing, the newest tag on GitHub releases is 2026.9.3, published 24 September 2026. apt-cache policy confirms the candidate comes from pkg.cloudflare.com, not a forgotten source.
The ls line checks for .installedFromPackageManager. Cloudflare’s update documentation uses that marker to distinguish package installs from standalone binaries. If it’s there, update with apt, never with cloudflared update.
Alternative: install the .deb with dpkg
Use this on hosts that can’t reach pkg.cloudflare.com, or for one exact build. Cloudflare documents the same command for dpkg upgrades:
curl --location --output cloudflared.deb "https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-$(dpkg --print-architecture).deb"
sudo dpkg -i cloudflared.deb
dpkg --print-architecture returns amd64 on x86-64 and arm64 on 64-bit ARM (like a Raspberry Pi 4 or 5 on Ubuntu Server), matching the GitHub asset names. Releases also ship arm, 386 and a FIPS amd64 build. To pin a build, replace latest/download with download/2026.9.3, or any validated tag.
The cost: nothing announces new versions. Cloudflare’s downloads page says it “supports versions of cloudflared that are within one year of the most recent release.” Manual installs mean manual upgrades.
Does cloudflared need any firewall ports open on Ubuntu?
No inbound ports. cloudflared only makes outbound connections, over TCP and UDP 7844, to region1.v2.argotunnel.com and region2.v2.argotunnel.com, per Cloudflare’s firewall requirements. Outbound 443 is optional, for update checks, github.com downloads and Access JWT validation. By default ufw allows all outbound traffic, so a stock Ubuntu host needs no new rule.
With default-deny egress, open only what the connector uses. Your apt mirrors and pkg.cloudflare.com still need 80/443:
sudo ufw allow out 7844/tcp
sudo ufw allow out 7844/udp
sudo ufw allow out 53
Test the path before creating a tunnel:
dig +short A region1.v2.argotunnel.com
dig +short AAAA region1.v2.argotunnel.com
dig +short SRV _v2-origintunneld._tcp.argotunnel.com
nc -vz -w 3 region1.v2.argotunnel.com 7844
mtr -T -P 7844 -c 10 region1.v2.argotunnel.com
nc only proves TCP/7844. UDP is connectionless, so nc -u reports success either way. If a middlebox drops QUIC, the default --protocol auto falls back to HTTP/2, and the logs show it.
Run cloudflared as a systemd service
Service setup depends on who owns the tunnel config.
Remotely-managed (dashboard) tunnels. The dashboard’s install command wraps a token:
sudo cloudflared service install <TOKEN>
systemctl status cloudflared
journalctl -u cloudflared -f
Treat the token as a private key. Cloudflare’s tunnel permissions page states: “Anyone with access to the token will be able to run the tunnel.” Cloudflare’s example unit puts the token on the ExecStart line of /etc/systemd/system/cloudflared.service. Don’t post systemctl cat cloudflared output publicly, and check your shell history. To add flags such as --loglevel, run sudo systemctl edit --full cloudflared.service, then restart.
Locally-managed tunnels. These use config.yml and a credentials file. Cloudflare’s Linux service guide warns of a catch. The service looks for $HOME/.cloudflared/config.yml, and under sudo, $HOME is /root. A config in your own home directory won’t be found. Pass the path explicitly:
sudo cloudflared --config /home/<USER>/.cloudflared/config.yml service install
sudo systemctl start cloudflared
systemctl status cloudflared
Each machine supports only one cloudflared service. A second attempt returns “cloudflared service already installed,” so run sudo cloudflared service uninstall before switching tunnels. One connector is also a single point of failure. Add a replica on a second host before anyone depends on it.
How do you update cloudflared on Ubuntu?
Update through apt, then restart the service. Cloudflare’s documented procedure is two lines, restart included:
sudo apt-get update && sudo apt-get install --only-upgrade cloudflared
sudo systemctl restart cloudflared.service
By default, unattended-upgrades covers Ubuntu’s own security updates, not third-party repositories. Unless you add Cloudflare’s origin to Unattended-Upgrade::Allowed-Origins, cloudflared updates only when you run apt. sudo apt-mark hold cloudflared gives full control, but release the hold on a schedule: a build pinned indefinitely eventually falls outside the one-year support window. With two replicas, restart them one at a time.
Common install errors and fixes
Signature errors after the key rotation. The repository page notes, “We have rolled our public key for package signing.” It names RPM distributions and Debian Trixie as affected, and says the old keys are “DEPRECATED and will be removed on 30 April 2026.” On Ubuntu, re-running the Step 1 key command replaces the keyring with the current key, harmless if already present. If signed-by points at a filename from an older tutorial, rewrite both files.
“Unable to locate package cloudflared.” Either apt-get update wasn’t run after adding the source, or the .list file has a typo. Check with cat /etc/apt/sources.list.d/cloudflared.list.
The tunnel stays unhealthy while the service runs. That is almost always egress on 7844, or the service running a different tunnel than expected. Work through the error 1033 fixes, which check the process, then the ports, then DNS.
How to remove cloudflared cleanly
sudo cloudflared service uninstall
sudo apt-get remove cloudflared
sudo rm /etc/apt/sources.list.d/cloudflared.list /usr/share/keyrings/cloudflare-main.gpg
sudo apt-get update
Removing the connector doesn’t delete the tunnel object or its DNS routes. Hostnames still pointing at it serve error 1033 until you delete the tunnel in the dashboard, or with cloudflared tunnel delete <NAME> for a locally-managed tunnel. If the tunnel replaced a port forward, don’t reopen that port as a shortcut. Tunnel versus port forwarding explains why the closed port was the point.
FAQ
does cloudflared work on ubuntu 24.04
Yes. Cloudflare’s repository publishes a noble suite for Ubuntu 24.04, alongside jammy (22.04) and focal (20.04). The recommended any suite installs the same package on any Debian-based release. GitHub releases include amd64 and arm64 builds for x86 servers and 64-bit ARM boards.
is there a snap package for cloudflared
Cloudflare doesn’t list a snap on its downloads page. The documented Linux options are the pkg.cloudflare.com apt repository, the .deb and standalone binaries on GitHub, and the cloudflare/cloudflared Docker image. Any snap would be third-party packaging of a daemon holding your tunnel credentials. Stick with Cloudflare’s own repository.
how do i check if cloudflared is running on ubuntu
Run systemctl status cloudflared and look for active (running). Then confirm the tunnel shows Healthy under Networking > Tunnels in the dashboard, or in cloudflared tunnel list for a locally-managed tunnel. A running process with an unhealthy tunnel usually means port 7844 egress is blocked. journalctl -u cloudflared shows each connection attempt.
does cloudflared update automatically on ubuntu
Not if installed from apt or a .deb. Cloudflare’s docs say built-in auto-updates aren’t available for package-manager installations, so update with apt-get install --only-upgrade cloudflared and restart the service. Only the standalone GitHub binary running as a service updates itself, checking every 24 hours by default unless you pass --no-autoupdate.
Related across the network
- How to Run Ollama in Docker: CPU, NVIDIA and AMD GPU Setup — ollamalab.com
- Jellyfin Hardware Transcoding in Docker: QSV, NVENC, VA-API — dockerhomelab.com