MOKEA STUDIO한국어 ↗
TROUBLESHOOTING / CLOUDFLARE TUNNEL + DOCKER

Tunnel is Healthy.
Why does the app return 502?

A Healthy status means cloudflared is connected to Cloudflare. It does not prove that the connector can reach the origin service in your Tunnel route. Trace that hop before changing DNS.

Identify which layer returned the error

Cloudflare 1033

Start with the Tunnel connector: confirm cloudflared is running, the Tunnel is connected, and recent connector logs are clean.

Tunnel 502

The connector may be online but unable to reach the Service URL configured for the public hostname. Check the scheme, hostname, port, and network path to that origin.

Traefik 404 or 503

If the request reaches Traefik, inspect its router rule, entrypoint, and backend. A 404 can mean no router matched; a 503 can mean the selected service has no ready server.

Error codes narrow the next check; they do not prove one root cause. Verify the response source before editing a live route.

Four Docker checks that often find the mismatch

  1. Origin hostname: inside the cloudflared container, localhost means that same container. If the origin is another container, use a service name resolvable on a shared Docker network.
  2. Internal port: a host-published port can differ from the port the app listens on inside its container. Compare the origin URL with the app's actual listening port.
  3. Shared network: cloudflared, Traefik, and the app need a valid network path between the containers involved in the selected route.
  4. HTTP vs HTTPS: use the protocol the origin serves. For an HTTPS origin, check certificate name and validation settings instead of disabling verification as a blind fix.

A public hostname is not access control. Do not expose dashboards, databases, or internal APIs while repairing a route. Apply a separate authentication policy where needed.

Start with read-only checks

Replace service names with the ones in your Compose project. Review logs locally and redact tokens, cookies, internal hostnames, and private IPs before sharing anything.

docker compose ps docker compose logs --tail=60 cloudflared traefik app

Look for connection refused, name-resolution failures, protocol mismatches, or certificate errors. Compare those signals with the origin Service URL's hostname, scheme, and port before making a change.

Verify the route after a change

A successful check confirms the route at that time; it is not a promise of future uptime.

Official documentation

Need help narrowing it down?

A USD 99 written diagnosis covers one existing app and one hostname. It does not change your configuration. Share only the public hostname and visible error—never passwords, API tokens, or private keys.

View the USD 99 diagnosis ↗ Review service scope ↗