Lộ trình đang học Current learning path Current learning path

Cloudflare One Cloudflare One Cloudflare One

Bảo vệ users, access, SaaS và networks — follow-along từ tài khoản đến go-live. Secure users, access, SaaS, and networks — follow along from account to go-live. Secure users, access, SaaS, and networks — follow along from account to go-live.

Về trang lộ trình Track home Track home

Phần 4: ZTNA — Access và connectors Part 4: ZTNA — Access and connectors Part 4: ZTNA — Access and connectors · Bài 1/3 Lesson 1/3 មេរៀន 1/3

Tunnel outbound và public hostname Outbound Tunnel and public hostname Outbound Tunnel and public hostname

Mô-đun 4 — ZTNA: Xuất bản ứng dụng nội bộ với Access

Mục tiêu: Làm cho một ứng dụng nội bộ tới được an toàn từ mọi nơi — không cần VPN và không mở bất kỳ cổng firewall vào nào — và kiểm soát chính xác ai có thể tới nó.

👤 Ai làm việc này Chủ ứng dụng + Security
⏱️ Thời gian ~60 phút
🎯 Kết thúc bạn sẽ có Một ứng dụng nội bộ được xuất bản tại URL thật, chỉ những người bạn cho phép mới tới được
✋ Trước khi bắt đầu Mô-đun 1–3 xong; một ứng dụng web nội bộ để thử (ví dụ wiki nội bộ, Grafana, công cụ dev) chạy ở nơi bạn kiểm soát; một máy chủ/VM tới được ứng dụng đó

🧭 Cách hoạt động: Bạn chạy một chương trình nhỏ tên cloudflared cạnh ứng dụng. Nó tạo kết nối an toàn, chỉ chiều ra (một "Tunnel") tới Cloudflare — nên bạn không bao giờ phơi ứng dụng ra Internet. Rồi Access đặt kiểm tra đăng nhập phía trước.

Chúng ta sẽ làm: (A) tạo Tunnel → (B) kết nối ứng dụng → (C) thêm ứng dụng Access → (D) viết chính sách → (E) kiểm tra → (F) xây nhóm dùng lại được.


Phần A — Tạo Tunnel

  1. 👉 Zero Trust → Networks → Tunnels.
  2. 👉 Nhấp Create a tunnel.
  3. 👉 Chọn Cloudflared → Next.
  4. ⌨️ Đặt tên theo vị trí, ví dụ datacenter-1 → Save tunnel.

📺 Bạn sẽ thấy: Trang "Install and run a connector" với lệnh cho từng hệ điều hành và một install token dài đã điền sẵn.

  1. 👉 Chọn tab cho hệ điều hành máy chủ của bạn (Windows / macOS / Debian / Red Hat / Docker).
  2. 👉 Sao chép lệnh hiện ra — nó đã chứa token duy nhất của bạn.

⚠️ Lưu ý: Lệnh đó chứa token bí mật. Hãy coi như mật khẩu; đừng dán vào chat hoặc ticket.


Phần B — Kết nối ứng dụng của bạn

Bước B1 — Chạy connector trên máy chủ

  1. 👉 Đăng nhập vào máy chủ/VM tới được ứng dụng của bạn.
  2. 👉 Dán và chạy lệnh bạn đã sao chép. Ví dụ, trên Debian/Ubuntu trông như:
    curl -L https://pkg.cloudflare.com/install.sh | sudo bash   # if cloudflared isn't installed
    sudo cloudflared service install eyJhIjoiZXhhbXBsZS...      # your token
    
  3. 📺 Quay lại bảng điều khiển, Connector status của tunnel đổi thành Connected / Healthy (cho khoảng ~30 giây).

✅ Điểm kiểm tra: Bảng điều khiển hiện connector của bạn là Healthy. Nhấp Next.

Bước B2 — Báo Cloudflare ứng dụng sống ở đâu (public hostname)

Giờ bạn sẽ ánh xạ một URL công khai tới ứng dụng nội bộ.

  1. 📺 Bạn đang ở bước Route tunnel / Public Hostnames.
  2. 👉 Nhấp Add a public hostname và điền:
    Trường Ví dụ Ý nghĩa
    Subdomain wiki Tên người dùng sẽ gõ
    Domain yourcompany.com Một domain trong tài khoản Cloudflare của bạn
    Type HTTP Cách cloudflared tới ứng dụng cục bộ
    URL localhost:3000 Nơi ứng dụng chạy trên máy chủ đó
  3. 👉 Nhấp Save tunnel.

📺 Bạn sẽ thấy: wiki.yourcompany.com nay đã được xuất bản và proxy tới ứng dụng nội bộ.

💡 Chưa có domain trong Cloudflare? Bạn cần thêm một domain (zone) để dùng ứng dụng Access self-hosted với hostname của riêng bạn. Nhờ quản trị viên thêm domain, hoặc dùng domain bạn đã quản lý trong Cloudflare.

✅ Điểm kiểm tra: Truy cập https://wiki.yourcompany.com — bạn tới được ứng dụng (lúc này nó mở cho bất kỳ ai; phần tiếp theo sẽ khóa lại).


Phần C — Thêm ứng dụng Access

Phần này đặt kiểm tra đăng nhập phía trước wiki.yourcompany.com.

  1. 👉 Zero Trust → Access controls → Applications.
  2. 👉 Nhấp Create new application (Add an application).
  3. 👉 Chọn Self-hosted and private.

📺 Bạn sẽ thấy: Trang cấu hình ứng dụng.

  1. ⌨️ Application name: Internal Wiki.
  2. 👉 Nhấp Add public hostname và nhập cùng hostname bạn đã xuất bản: subdomain wiki, domain yourcompany.com.
  3. 👉 Đặt Session Duration thành 24h (dùng giá trị ngắn hơn như 1h cho ứng dụng nhạy cảm).
  4. 👉 Dưới authentication, chọn identity provider từ Mô-đun 2.
    • 💡 Nếu bạn chỉ có một IdP, bật Apply instant authentication để người dùng bỏ qua màn hình chọn.
    • 💡 Bật Authenticate with Cloudflare One Client để người dùng WARP đã đăng nhập vào được liền mạch.
  5. Đừng nhấp Create ngay — trước hết thêm chính sách ở Phần D (trình hướng dẫn cho phép thêm ngay trong luồng), hoặc nhấp Create rồi thêm chính sách ngay sau. Cả hai đều được.

Phần D — Viết chính sách truy cập (ai được phép)

  1. 👉 Trong ứng dụng, vào phần Policies → Add a policy (hoặc Create new policy).

  2. ⌨️ Policy name: Allow — Employees on healthy devices.

  3. 👉 Action: Allow.

  4. 👉 Xây các quy tắc:

    Loại quy tắc Selector Operator Value
    Include Emails ending in — @yourcompany.com
    Require Device Posture in Disk encrypted (từ Mô-đun 3)

    (Nếu nhóm IdP của bạn đã kiểm tra đúng ở Mô-đun 2, dùng Include → IdP Groups → Engineering thay cho domain email để kiểm soát chặt hơn.)

  5. 👉 Nhấp Save chính sách, rồi Save/Create ứng dụng.

💡 Thực hành tốt — thêm lưới default-deny: tạo chính sách thứ hai, ưu tiên thấp hơn, tên Block — Everyone với Action = Block và Include = Everyone. Vì chính sách được đọc từ trên xuống, Allow khớp người của bạn trước và mọi người khác gặp Block.

⚠️ Lưu ý: Không bao giờ dùng action Bypass trên ứng dụng nhạy cảm — nó gỡ hoàn toàn kiểm tra đăng nhập.


Phần E — Kiểm tra (phần đáng thỏa mãn)

Kiểm tra 1 — người dùng được phép

  1. 👉 Trên thiết bị pilot (đã đăng nhập với tư cách nhân viên được phép), mở https://wiki.yourcompany.com.
  2. 📺 Bạn được đưa tới đăng nhập công ty (hoặc vào thẳng, nếu instant auth + phiên WARP). Sau đăng nhập, ứng dụng của bạn tải. ✅

Kiểm tra 2 — người dùng bị chặn

  1. 👉 Mở cùng URL trong cửa sổ riêng tư/ẩn danh và đăng nhập với người không được phép (hoặc dùng email cá nhân).
  2. 📺 Bạn thấy trang chặn Cloudflare "You don't have access". ✅

Kiểm tra 3 — xem nhật ký

  1. 👉 Zero Trust → Logs → Access (hoặc Access → Logs).
  2. 📺 Bạn thấy cả hai lần thử: một Allowed, một Blocked, mỗi cái kèm email người dùng và chính sách đã quyết định.

✅ Điểm kiểm tra: Đúng người vào được, sai người bị chặn, và bạn thấy điều đó trong nhật ký. Bạn vừa thay thế VPN cho ứng dụng này. 🎉


Phần F — Xây nhóm dùng lại được (để không phải gõ lại)

Hiện các quy tắc của bạn được gõ vào một ứng dụng. Khi bạn thêm ứng dụng thứ 2, 3, 10, bạn không muốn gõ lại. Xây một Access Group dùng lại được một lần.

  1. 👉 Zero Trust → Access controls → Policies → Groups (hoặc Reusable components → Groups).
  2. 👉 Nhấp Add a group.
  3. ⌨️ Name: Secure employees.
  4. 👉 Thêm quy tắc một lần, ví dụ:
    • Include → Emails ending in → @yourcompany.com
    • Require → Device Posture → Disk encrypted
  5. 👉 Nhấp Save.

Giờ trong chính sách của bất kỳ ứng dụng nào, bạn chỉ cần chọn Include → Access Groups → Secure employees. Đổi nhóm một lần, mọi ứng dụng cập nhật.

💡 Mẹo: Cũng tạo Lists dùng lại được (Zero Trust → Reusable components → Lists) cho những thứ như danh sách email Offboarding hoặc số serial thiết bị được duyệt — rồi Exclude → Emails in list → Offboarding trên mọi ứng dụng.


✅ Mô-đun 4 hoàn tất!

Bạn hiện có:

  • ✅ Ứng dụng nội bộ được xuất bản qua Tunnel (không mở cổng vào)
  • ✅ Chính sách Access cho phép đúng người, chặn người khác
  • ✅ Kiểm tra allow/block hoạt động, thấy được trong nhật ký
  • ✅ Nhóm dùng lại được để áp dụng cho ứng dụng sau

Muốn thêm loại ứng dụng?

  • Ứng dụng SaaS (Salesforce, v.v.): Applications → Create new application → SaaS → tích hợp qua SAML/OIDC.
  • Máy chủ SSH / RDP: xuất bản qua cùng Tunnel và dùng Access for Infrastructure (tùy chọn render trên trình duyệt, không cần client).
  • Phương án dự phòng thiết bị không quản lý: giữ Allow cho thiết bị khỏe mạnh, và thêm quy tắc Gateway → Isolate (Mô-đun 5) để thiết bị rủi ro mở ứng dụng trong trình duyệt từ xa an toàn thay vì bị chặn.

Khắc phục sự cố nhanh

Vấn đề Cách xử lý
URL ứng dụng hiện lỗi Cloudflare, không phải ứng dụng của bạn Connector tunnel không healthy, hoặc URL/port cục bộ sai — kiểm tra lại Phần B
Mọi người bị chặn, kể cả bạn Quy tắc Include quá hẹp hoặc chính sách Block nằm trên Allow — sửa thứ tự (Phần D)
Quy tắc nhóm không bao giờ khớp Nhóm không đi qua được ở bài Test của Mô-đun 2 — sửa IdP trước
Được phép nhưng ứng dụng cứ hỏi đăng nhập Session duration quá ngắn, hoặc cookie bị chặn — tăng session duration
"DNS record already exists" Đã có bản ghi cho hostname đó; xóa nó hoặc chọn subdomain khác

🔌 Muốn bức tranh đầy đủ về connectors? Mô-đun này dùng một Cloudflare Tunnel cho một ứng dụng. Để kết nối cả subnet, làm site-to-site / device mesh, hoặc đưa cả văn phòng lên mạng, xem Mô-đun 4b — Connectors: Tunnel, Mesh & Appliance.

👉 Tiếp theo: Mô-đun 4b — Connectors · hoặc Mô-đun 5 — Gateway

Mô-đun 4b đi sâu về Tunnel, Mesh và Cloudflare One Appliance. Hoặc chuyển sang Gateway để bắt đầu lọc lưu lượng.

Module 4 — ZTNA: Publish a Private App with Access

Goal: Make an internal application reachable securely from anywhere — without a VPN and without opening any inbound firewall ports — and control exactly who can reach it.

👤 Who does this App owner + Security
⏱️ Time ~60 minutes
🎯 You'll finish with A private app published at a real URL, reachable only by the people you allow
✋ Before you begin Modules 1–3 done; a private web app to test (e.g. an internal wiki, Grafana, a dev tool) running somewhere you control; a server/VM that can reach that app

🧭 How this works: You'll run a tiny program called cloudflared next to your app. It makes a safe, outbound-only connection (a "Tunnel") to Cloudflare — so you never expose your app to the internet. Then Access puts a login check in front of it.

We'll go: (A) create a Tunnel → (B) connect your app → (C) add an Access application → (D) write the policy → (E) test → (F) build reusable groups.


Part A — Create a Tunnel

  1. 👉 Zero Trust → Networks → Tunnels.
  2. 👉 Click Create a tunnel.
  3. 👉 Choose Cloudflared → Next.
  4. ⌨️ Name it after the location, e.g. datacenter-1 → Save tunnel.

📺 What you'll see: An "Install and run a connector" page with commands for each operating system and a long install token already filled in.

  1. 👉 Choose the tab for your server's OS (Windows / macOS / Debian / Red Hat / Docker).
  2. 👉 Copy the command shown — it already contains your unique token.

⚠️ Watch out: That command contains a secret token. Treat it like a password; don't paste it into chat or tickets.


Part B — Connect your app

Step B1 — Run the connector on your server

  1. 👉 Log in to the server/VM that can reach your app.
  2. 👉 Paste and run the command you copied. For example, on Debian/Ubuntu it looks like:
    curl -L https://pkg.cloudflare.com/install.sh | sudo bash   # if cloudflared isn't installed
    sudo cloudflared service install eyJhIjoiZXhhbXBsZS...      # your token
    
  3. 📺 Back in the dashboard, the tunnel's Connector status changes to Connected / Healthy (give it ~30 seconds).

✅ Checkpoint: The dashboard shows your connector as Healthy. Click Next.

Step B2 — Tell Cloudflare where your app lives (public hostname)

You'll now map a public URL to your internal app.

  1. 📺 You're on the Route tunnel / Public Hostnames step.
  2. 👉 Click Add a public hostname and fill in:
    Field Example Meaning
    Subdomain wiki The name users will type
    Domain yourcompany.com A domain in your Cloudflare account
    Type HTTP How cloudflared reaches your app locally
    URL localhost:3000 Where your app runs on that server
  3. 👉 Click Save tunnel.

📺 What you'll see: wiki.yourcompany.com is now published and proxied to your internal app.

💡 No domain in Cloudflare yet? You'll need to add one (a zone) to use self-hosted Access apps with your own hostname. Ask your admin to add the domain, or use a domain you already manage in Cloudflare.

✅ Checkpoint: Visit https://wiki.yourcompany.com — you reach your app (right now it's open to anyone; the next part locks it down).


Part C — Add an Access application

This puts the login check in front of wiki.yourcompany.com.

  1. 👉 Zero Trust → Access controls → Applications.
  2. 👉 Click Create new application (Add an application).
  3. 👉 Choose Self-hosted and private.

📺 What you'll see: An application configuration page.

  1. ⌨️ Application name: Internal Wiki.
  2. 👉 Click Add public hostname and enter the same hostname you published: subdomain wiki, domain yourcompany.com.
  3. 👉 Set Session Duration to 24h (use a shorter value like 1h for sensitive apps).
  4. 👉 Under authentication, select the identity provider from Module 2.
    • 💡 If you only have one IdP, turn on Apply instant authentication so users skip the chooser screen.
    • 💡 Turn on Authenticate with Cloudflare One Client to let already-signed-in WARP users in seamlessly.
  5. Don't click Create yet — first add a policy in Part D (the wizard lets you add it inline), or click Create and add the policy right after. Either works.

Part D — Write the access policy (who's allowed)

  1. 👉 In the application, go to the Policies section → Add a policy (or Create new policy).

  2. ⌨️ Policy name: Allow — Employees on healthy devices.

  3. 👉 Action: Allow.

  4. 👉 Build the rules:

    Rule type Selector Operator Value
    Include Emails ending in — @yourcompany.com
    Require Device Posture in Disk encrypted (from Module 3)

    (If your IdP groups tested correctly in Module 2, use Include → IdP Groups → Engineering instead of the email domain for tighter control.)

  5. 👉 Click Save the policy, then Save/Create the application.

💡 Best practice — add a default-deny net: create a second, lower-priority policy named Block — Everyone with Action = Block and Include = Everyone. Because policies are read top-down, the Allow matches your people first and everyone else hits the Block.

⚠️ Watch out: Never use the Bypass action on a sensitive app — it removes the login check entirely.


Part E — Test it (the satisfying part)

Test 1 — an allowed user

  1. 👉 On your pilot device (signed in as an allowed employee), open https://wiki.yourcompany.com.
  2. 📺 You're sent to your company login (or straight in, if instant auth + WARP session). After login, your app loads. ✅

Test 2 — a blocked user

  1. 👉 Open the same URL in a private/incognito window and sign in as someone not allowed (or use a personal email).
  2. 📺 You see the Cloudflare "You don't have access" block page. ✅

Test 3 — check the logs

  1. 👉 Zero Trust → Logs → Access (or Access → Logs).
  2. 📺 You see both attempts: one Allowed, one Blocked, each with the user's email and the policy that decided it.

✅ Checkpoint: The right people get in, the wrong people are blocked, and you can see it in the logs. You've just replaced VPN for this app. 🎉


Part F — Build reusable groups (so you don't repeat yourself)

Right now your rules are typed into one app. When you add a 2nd, 3rd, 10th app, you don't want to re-type them. Build a reusable Access Group once.

  1. 👉 Zero Trust → Access controls → Policies → Groups (or Reusable components → Groups).
  2. 👉 Click Add a group.
  3. ⌨️ Name: Secure employees.
  4. 👉 Add rules once, e.g.:
    • Include → Emails ending in → @yourcompany.com
    • Require → Device Posture → Disk encrypted
  5. 👉 Click Save.

Now in any application's policy, you can simply select Include → Access Groups → Secure employees. Change the group once, and every app updates.

💡 Tip: Also create reusable Lists (Zero Trust → Reusable components → Lists) for things like an Offboarding email list or approved device serial numbers — then Exclude → Emails in list → Offboarding across all apps.


✅ Module 4 complete!

You now have:

  • ✅ A private app published via Tunnel (no inbound ports opened)
  • ✅ An Access policy allowing the right people, blocking others
  • ✅ A working allow/block test, visible in logs
  • ✅ A reusable group to apply to future apps

Want more app types?

  • SaaS apps (Salesforce, etc.): Applications → Create new application → SaaS → integrate via SAML/OIDC.
  • SSH / RDP servers: publish through the same Tunnel and use Access for Infrastructure (optionally browser-rendered, no client needed).
  • Unmanaged-device fallback: keep the Allow for healthy devices, and add a Gateway → Isolate rule (Module 5) so risky devices open the app in a safe remote browser instead of being blocked.

Quick troubleshooting

Problem Fix
App URL shows a Cloudflare error, not your app Tunnel connector not healthy, or the local URL/port is wrong — recheck Part B
Everyone is blocked, including you Your Include rule is too narrow or a Block policy is above the Allow — fix order (Part D)
Group rule never matches Groups didn't come through in Module 2's Test — fix the IdP first
Allowed but app keeps asking to log in Session duration too short, or cookies blocked — raise session duration
"DNS record already exists" A record for that hostname exists; delete it or pick another subdomain

🔌 Want the full picture on connectors? This module used one Cloudflare Tunnel for a single app. To connect whole subnets, do site-to-site / device mesh, or bring an entire office online, see Module 4b — Connectors: Tunnel, Mesh & Appliance.

👉 Next: Module 4b — Connectors · or Module 5 — Gateway

Module 4b goes deep on Tunnel, Mesh, and the Cloudflare One Appliance. Or skip to Gateway to start filtering traffic.

Nguồn cộng đồng — không phải tài liệu chính thức của Cloudflare: https://zerotrust.cfsase.workers.dev Community source — not an official Cloudflare publication: https://zerotrust.cfsase.workers.dev

Lưu ý (best practices) Note (best practices) Note (best practices)

App nội bộ có iframe/service phụ thuộc — khai báo nhiều top-level domain trong một Access application thay vì tách rời. Internal apps with interdependent services (iframes, embedded systems) — specify multiple top-level domains in a single Access application. Internal apps with interdependent services (iframes, embedded systems) — specify multiple top-level domains in a single Access application.

Nguồn: Source: Source: Access application — Best practices Access application — Best practices Access application — Best practices ↗

Ví dụ triển khai (Cloudflare Resources) Deployment examples (Cloudflare Resources) Deployment examples (Cloudflare Resources)

Ví dụ chính thức từ Cloudflare Resources — gợi ý theo chủ đề bài học trong lộ trình này. Official examples from Cloudflare Resources — matched to this lesson within this path. Official examples from Cloudflare Resources — matched to this lesson within this path.

Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access và bảo mật cơ sở dữ liệu MySQL bằng cách sử dụng Cloudflare Tunnel và chính sách mạng Access and secure a MySQL database using Cloudflare Tunnel and network policies Access និងធានានូវមូលដ្ឋានទិន្នន័យ MySQL ដោយប្រើ Cloudflare Tunnel និងគោលការណ៍បណ្តាញ

Sử dụng mạng riêng của Cloudflare Tunnel, người dùng có thể kết nối với các ứng dụng dựa trên TCP/UDP, chẳng hạn như cơ sở dữ liệu. Bạn có thể thiết lập chính sách mạng thực hiện các điều khiển zero trust để xác định ai và những gì access có thể sử dụng các ứng dụng đó bằng cách sử dụng Cloudflare One Client.

Using Cloudflare Tunnel's private networks, users can connect to arbitrary non-browser based TCP/UDP applications, like databases. You can set up network policies that implement zero trust controls to define who and what can access those applications using the Cloudflare One Client.

ដោយប្រើបណ្តាញឯកជនរបស់ Cloudflare Tunnel អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធី TCP/UDP ដែលមានមូលដ្ឋានលើកម្មវិធីរុករកតាមអំពើចិត្ត ដូចជាមូលដ្ឋានទិន្នន័យជាដើម។ អ្នកអាចរៀបចំគោលការណ៍បណ្តាញដែលអនុវត្តការគ្រប់គ្រង zero trust ដើម្បីកំណត់ថាតើនរណា និងអ្វីដែលអាច access កម្មវិធីទាំងនោះដោយប្រើ Cloudflare One Client ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Màn hình Cloudflare Tunnel với Grafana Monitor Cloudflare Tunnel with Grafana ទូរទស្សន៍ Cloudflare Tunnel ជាមួយ Grafana

Hướng dẫn này bao gồm cách tạo điểm cuối số và thiết lập máy chủ Prometheus.

This tutorial covers how to create the metrics endpoint and set up the Prometheus server.

វគ្គបណ្តុះបណ្តាលនេះគ្របដណ្តប់ធ្វើដូចម្តេចដើម្បីបង្កើត endpoint metrics និងបង្កើតផ្នែកបណ្តាញ Prometheus ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Sử dụng Cloudflare Tunnels với các plugin xác thực khách hàng của Kubernetes Use Cloudflare Tunnels with Kubernetes client-go credential plugins ការប្រើប្រាស់ Cloudflare Tunnels ជាមួយ Kubernetes client-go credential plugins

Hướng dẫn này giải thích làm thế nào để sử dụng Cloudflare Tunnels với Kubernetes client-go credential plugins để xác thực. Bằng cách làm theo các bước này, bạn có thể an toàn access cụm Kubernetes của bạn thông qua một Cloudflare Tunnel.

This tutorial explains how to use Cloudflare Tunnels with Kubernetes client-go credential plugins for authentication. By following these steps, you can securely access your Kubernetes cluster through a Cloudflare Tunnel.

វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដើម្បីប្រើ Cloudflare Tunnels ជាមួយ Kubernetes client-go credential plugins សម្រាប់ការអនុម័ត។ ដោយធ្វើដូច្នេះអ្នកអាច access ដោយសុវត្ថិភាពក្លឹប Kubernetes របស់អ្នកតាមរយៈ Cloudflare Tunnel ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម
Tutorial Tutorial Tutorial Cloudflare One Cloudflare One Cloudflare One

Access một ứng dụng web thông qua tên máy chủ riêng của nó mà không có Cloudflare One Client Access a web application via its private hostname without the Cloudflare One Client Access កម្មវិធីបណ្តាញតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់វាដោយគ្មាន Cloudflare One Client

Với Cloudflare cách ly trình duyệt và các chính sách giải quyết, người dùng có thể kết nối với các ứng dụng dựa trên web riêng tư thông qua tên máy chủ riêng của họ.

With Cloudflare Browser Isolation and resolver policies, users can connect to private web-based applications via their private hostnames.

ជាមួយនឹង Cloudflare គោលការណ៍ញែកកម្មវិធីរុករក និងដំណោះស្រាយ អ្នកប្រើប្រាស់អាចភ្ជាប់ទៅកម្មវិធីដែលមានមូលដ្ឋានលើបណ្តាញឯកជនតាមរយៈឈ្មោះម៉ាស៊ីនឯកជនរបស់ពួកគេ។

Tìm hiểu thêm Learn more ស្វែងយល់បន្ថែម

Xem thêm ví dụ trong lộ trình → More examples in this path → More examples in this path →

Tài liệu Cloudflare Developers Cloudflare Developer docs Cloudflare Developer docs

Sơ đồ kiến trúc tham chiếu (Cloudflare Docs) Architecture diagrams (Cloudflare Docs) Architecture diagrams (Cloudflare Docs)

Hình 1: Chỉ traffic đã qua mạng Cloudflare và policy liên quan mới được phép vào ứng dụng SaaS.

Truy cập SaaS an toàn với SASE Secure access to SaaS applications with SASE Secure access to SaaS applications with SASE

Zero Trust cho SaaS: policy theo identity, device posture và network context qua Cloudflare One. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications. Cloudflare's SASE platform offers the ability to bring a more Zero Trust orientated approach to securing SaaS applications. Centralized policies, based on device posture, identity attributes and granular network location can be applied across one or many Saas applications.

Thuật ngữ: Concepts: Concepts: SASE · Gateway · Access · Device posture · SaaS

Sơ đồ chính thức ↗ Official diagram ↗ Official diagram ↗ · SASE / Cloudflare One Secure Access Service Edge (SASE) Secure Access Service Edge (SASE)

Sản phẩm liên quan Related products Related products

Học xong hoặc muốn đổi hướng? Finished or want a different path? Finished or want a different path?

Ba lộ trình độc lập — mỗi lộ trình chỉ gồm bài học và tài liệu trong phạm vi đó. Chọn lộ trình khác khi sẵn sàng, không cần học song song. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel. Three independent paths — each includes only lessons and materials for that scope. Switch when you are ready; no need to study paths in parallel.

Chưa chắc — làm bài chọn lộ trình Not sure — use the path selector Not sure — use the path selector · So sánh cả ba lộ trình Compare all three paths Compare all three paths