Phát triển Cloudflare One Client trên máy Linux không đầu Deploy the Cloudflare One Client on headless Linux machines ការផ្លាស់ប្តូរអតិថិជន Cloudflare One នៅលើម៉ាស៊ីន Linux មិនមែនជា headless
Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។
← Danh mục ← Catalog ← បញ្ជីGiải thích nhanh Quick context បរិបទរហ័ស
Thuộc Cloudflare One — Zero Trust, truy cập an toàn và kiểm soát traffic người dùng/thiết bị. Tutorial «Triển khai Cloudflare One Client on Linux headless machines» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Docs gốc chia khoảng 4 bước chính; bản tóm tắt dưới đây giúp bạn nắm khung trước khi làm theo từng lệnh.
This tutorial explains how to deploy the Cloudflare One Client on headless Linux devices using a service token and an installation script.
វគ្គបណ្តុះបណ្តាលនេះបង្ហាញពីរបៀបដំឡើងអតិថិជន Cloudflare One នៅលើឧបករណ៍ Linux ដែលមិនមានក្បាលដោយប្រើគណនីសេវាកម្មនិងគណនីដំឡើង។
Lưu ý Note ចំណាំ
Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម
- Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
- Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
- Zero Trust thường cần quyền admin trên tenant Cloudflare One và IdP đã kết nối.
- Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
- This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
- Open the Official docs link below for CLI commands, code snippets, and full screenshots.
- Zero Trust typically requires Cloudflare One tenant admin access and a connected IdP.
- Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
- នេះគឺជាការបញ្ជាក់អំពី Orange Cloud Learning Hub — វាគឺជាការផ្លាស់ប្តូរនៃឯកសារផ្លូវការ។
- ចុចតំណភ្ជាប់ Docs Official នៅខាងក្រោមសម្រាប់ការបញ្ជា CLI, សៀវភៅកូដនិងរូបថតពេញលេញ។
- Zero Trust ជាទូទៅតម្រូវការ Cloudflare One អ្នកគ្រប់គ្រងហិរញ្ញវត្ថុ access និង IdP ។
- Cloudflare បានផ្លាស់ប្តូរជាធម្មតានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅ។
Tài liệu gốc — rà soát lần cuối: 9 months ago Official docs — last reviewed: 9 months ago ឯកសារផ្លូវការ — ពិនិត្យចុងក្រោយ: 9 months ago
Overview Overview Overview
Tutorial này hướng dẫn cách deploy the Cloudflare One Client on Linux devices using a service token and an installation script. This deployment workflow is designed for headless servers - that is, servers which do not have access to a browser for identity provider logins - and…
Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
Điều kiện Prerequisites គោលបំណង
Phần «Yêu cầu trước» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "Prerequisites" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «គោលបំណង» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
1.Điều Tạo token dịch vụ 1. Create a service token 1 ។ ការបង្កើតសេវាកម្ម Token
Phần «Tạo service token» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "1. Create a service token" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «1 ។ ការបង្កើតសេវាកម្ម Token» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
- Trong Cloudflare dashboard ↗, đi đến Zero Trust & > Access controls > Service credentials > Service Tokens.
- Chọn Create Service Token
- Tên của token dịch vụ Tên cho phép bạn dễ dàng xác định các sự kiện liên quan đến token trong nhật ký và thu hồi token riêng lẻ.
- Chọn Service Token Duration Điều này đặt ngày hết hạn cho token.
- Chọn Generate token Bạn sẽ thấy Client ID và Client Secret được tạo cho token dịch vụ, cũng như tiêu đề yêu cầu tương ứng của họ.
- Sao chép khách hàng bí mật.
- In the Cloudflare dashboard ↗, go to Zero Trust \> Access controls \> Service credentials \> Service Tokens.
- Select Create Service Token.
- Name the service token. The name allows you to easily identify events related to the token in the logs and to revoke the token individually.
- Choose a Service Token Duration. This sets the expiration date for the token.
- Select Generate token. You will see the generated Client ID and Client Secret for the service token, as well as their respective request headers.
- Copy the Client Secret.
- ក្នុង Cloudflare dashboard ↗ សូមចូលទៅទៅ Zero Trust \> Access controls \> Service credentials \> Service Tokens ។
- សូមជ្រើស Create Service Token ។
- ប្រព័ន្ធ ប្រតិបត្តិការ Token ឈ្មោះនេះអនុញ្ញាតឱ្យអ្នករកឃើញយ៉ាងងាយស្រួលប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនបើប្រសិនប
- សូមជ្រើស Service Token Duration ។ នេះបានកំណត់ពេលវេលានៃការបញ្ចប់នៃ token នេះ។
- សូមជ្រើស Generate token ។ អ្នកនឹងមើល ID Client និង Client Secret ដែលត្រូវបានបង្កើតឡើងសម្រាប់គណនីសេវាកម្មដូចជាគណនីកំណត់តម្រូវការរបស់ពួកគេ។
- ចម្លងទិន្នន័យរបស់អតិថិជន។
- Thực hiện yêu cầu
POSTđến điểm cuối Access Service Tokens:
- Make a
POSTrequest to the Access Service Tokens endpoint:
- សូមធ្វើតេស្ត
POSTទៅ Access Service Tokens ។
Access: Service Tokens Write Tạo token dịch vụAccess: Service Tokens Write Create a service tokenAccess: Service Tokens Write Create a service tokencurl "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/service_tokens" \
--request POST \
--header "Authorization: Bearer $CLOUDFLARE_API_TOKEN" \
--json '{
"name": "CI/CD token",
"duration": "8760h"
}' - Sao chép các giá trị
client<em>idvàclient</em>secrettrả về trong câu trả lời.
- Copy the
client<em>idandclient</em>secretvalues returned in the response.
- ចម្លងតម្លៃ
client<em>idនិងclient</em>secretដែលបានបង្ហាញនៅក្នុងការឆ្លើយតប។
"result": {
"client_id": "88bf3b6d86161464f6509f7219099e57.access",
"client_secret": "bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5",
"created_at": "2025-09-25T22:26:26Z",
"expires_at": "2026-09-25T22:26:26Z",
"id": "3537a672-e4d8-4d89-aab9-26cb622918a1",
"name": "CI/CD token",
"updated_at": "2025-09-25T22:26:26Z",
"duration": "8760h",
"client_secret_version": 1
} - Thêm quyền sau vào cloudflare\api\token ↗ của bạn:
- Add the following permission to your cloudflare\api\token ↗:
- បន្ថែមអនុញ្ញាតដូចខាងក្រោមទៅ cloudflare\api\token ↗ របស់អ្នក:
Access: Service Tokens WriteAccess: Service Tokens WriteAccess: Service Tokens Write- Cấu hình tài nguyên cloudflare\zero\trust\access\service\_token ↗:
- Configure the cloudflare\zero\trust\access\service\_token ↗ resource:
- សូមបញ្ជាក់អំពី cloudflare\zero\trust\access\service\_token ↗:
resource "cloudflare_zero_trust_access_service_token" "example_service_token" {
account_id = var.cloudflare_account_id
name = "Example service token"
duration = "8760h"
lifecycle {
create_before_destroy = true
}
} - Nhận Client ID và Client Secret của token dịch vụ:
- Get the Client ID and Client Secret of the service token:
- ទាញយក ID កុំព្យូទ័រ និង Client Secret នៃ token សេវាកម្ម:
output "example<em>service</em>token<em>client</em>id" { value = cloudflare<em>zero</em>trust<em>access</em>service<em>token.example</em>service<em>token.client</em>id } output "example<em>service</em>token<em>client</em>secret" { value = cloudflare<em>zero</em>trust<em>access</em>service<em>token.example</em>service<em>token.client</em>secret sensitive = true } ` 2. Apply the configuration: Terminal window ` terraform apply ` 3. Read the Client ID and Client Secret: Terminal window ` terraform output -raw example<em>service</em>token<em>client</em>id ` Terminal window ` terraform output -raw example<em>service</em>token<em>client</em>secret `` Ví dụ: Lưu trữ trong Khay HashiCorp output "example<em>service</em>token<em>client</em>id" { value = cloudflare<em>zero</em>trust<em>access</em>service<em>token.example</em>service<em>token.client</em>id } output "example<em>service</em>token<em>client</em>secret" { value = cloudflare<em>zero</em>trust<em>access</em>service<em>token.example</em>service<em>token.client</em>secret sensitive = true } ` 2. Apply the configuration: Terminal window ` terraform apply ` 3. Read the Client ID and Client Secret: Terminal window ` terraform output -raw example<em>service</em>token<em>client</em>id ` Terminal window ` terraform output -raw example<em>service</em>token<em>client</em>secret `` Example: Store in HashiCorp Vault output "example<em>service</em>token<em>client</em>id" { value = cloudflare<em>zero</em>trust<em>access</em>service<em>token.example</em>service<em>token.client</em>id } output "example<em>service</em>token<em>client</em>secret" { value = cloudflare<em>zero</em>trust<em>access</em>service<em>token.example</em>service<em>token.client</em>secret sensitive = true } ` 2. Apply the configuration: Terminal window ` terraform apply ` 3. Read the Client ID and Client Secret: Terminal window ` terraform output -raw example<em>service</em>token<em>client</em>id ` Terminal window ` terraform output -raw example<em>service</em>token<em>client</em>secret `` Example: Store in HashiCorp Vaultresource "vault_generic_secret" "example_service_token" {
path = "kv/cloudflare/example_service_token"
data_json = jsonencode({
"CLIENT_ID" = cloudflare_access_service_token.example_service_token.client_id
"CLIENT_SECRET" = cloudflare_access_service_token.example_service_token.client_secret
})
} Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
2.Đối với Configure device enrollment permissions (Cấu hình thiết bị đăng nhập quyền) 2. Configure device enrollment permissions 2 ។ ការបញ្ជាទិន្នន័យនៃការបញ្ជាទិន្នន័យ
Phần «Cấu hình device enrollment permissions» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "2. Configure device enrollment permissions" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «2 ។ ការបញ្ជាទិន្នន័យនៃការបញ្ជាទិន្នន័យ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
- Trong Cloudflare dashboard ↗, đi đến Zero Trust \> Team & Resources \> Devices. Chọn tab Management
- Trong Device enrollment permissions, hãy chọn Manage.
- Trong tab Policies, chọn Create new policy. Một tab mới sẽ mở ra với trang tạo chính sách.
- Đối với Action, hãy chọn Service Auth.
- Đối với trường Selector, bạn có hai tùy chọn: bạn có thể cho phép tất cả các token dịch vụ (
Any Access Service Token) hoặc các token dịch vụ cụ thể (Service Token). Ví dụ:
- In the Cloudflare dashboard ↗, go to Zero Trust \> Team & Resources \> Devices. Select the Management tab.
- In Device enrollment permissions, select Manage.
- In the Policies tab, select Create new policy. A new tab will open with the policy creation page.
- For Action, select Service Auth.
- For the Selector field, you have two options: you can either allow all service tokens (
Any Access Service Token) or specific service tokens (Service Token). For example:
- ក្នុង Cloudflare dashboard ↗ សូមចូលទៅទៅ Zero Trust \> Team & Resources \> Devices ។ សូមចុច Management ។
- នៅលើ Device enrollment permissions ចុច Manage ។
- នៅលើបណ្តាញ Policies ចុច Create new policy ។ ស្លាកថ្មីនឹងបើកជាមួយនឹងទំព័របង្កើតគោលការណ៍។
- សម្រាប់ Action ចុច សេវាកម្ម Auth ។
- សម្រាប់ឧបករណ៍ Selector អ្នកមានបំណងពីរដង: អ្នកអាចអនុញ្ញាតបច្ចេកទេសសេវាកម្មទាំងអស់ (
Any Access Service Token) ឬបច្ចេកទេសសេវាកម្មពិសេស (Service Token) ។ ឧទាហរណ៍ :
- Tiết kiệm chính sách
- Quay trở lại Device enrollment permissions và thêm chính sách mới được tạo vào quyền của bạn.
- Chọn Save
- Save the policy.
- Go back to Device enrollment permissions and add the newly created policy to your permissions.
- Select Save.
- រក្សាទុកគោលនយោបាយ
- សូមផ្លាស់ប្តូរទៅ Device enrollment permissions និងបន្ថែមគោលនយោបាយដែលបានបង្កើតថ្មីទៅនឹងការអនុញ្ញាតរបស់អ្នក។
- សូមជ្រើស Save ។
3 Cái Tạo script cài đặt 3. Create an installation script 3 ។ ការបង្កើតកម្មវិធីដំឡើង
Phần «Tạo installation script» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "3. Create an installation script" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «3 ។ ការបង្កើតកម្មវិធីដំឡើង» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
- Trong một thiết bị đầu cuối, tạo một tập tin
.shmới bằng cách sử dụng một trình soạn thảo văn bản. Ví dụ:
- In a terminal, create a new
.shfile using a text editor. For example:
- ក្នុងកំណត់ដំណោះស្រាយ, បង្កើតឯកសារ
.shថ្មីដោយប្រើកម្មវិធីកំណត់ដំណោះស្រាយ។ ឧទាហរណ៍ :
vim install_warp.sh - Nhấn
iđể nhập chế độ chèn và thêm các dòng sau:
- Press
ito enter insert mode and add the following lines:
- ចុច
iដើម្បីចូលដំណើរការ Insert Mode និងបន្ថែមបន្ទាត់ដូចខាងក្រោម:
#!/bin/bash
set -e
# Download and install the Cloudflare One Client
function warp() {
curl -fsSL https://pkg.cloudflareclient.com/pubkey.gpg | sudo gpg --yes --dearmor --output /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] https://pkg.cloudflareclient.com/ $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflare-client.list
sudo apt-get update --assume-yes
sudo apt-get install --assume-yes cloudflare-warp
}
# Create an MDM file with your Cloudflare One Client deployment parameters
function mdm() {
sudo touch /var/lib/cloudflare-warp/mdm.xml
cat > /var/lib/cloudflare-warp/mdm.xml << "EOF"
<dict>
<key>auth_client_id</key>
<string>88bf3b6d86161464f6509f7219099e57.access</string>
<key>auth_client_secret</key>
<string>bdd31cbc4dec990953e39163fbbb194c93313ca9f0a6e420346af9d326b1d2a5</string>
<key>auto_connect</key>
<integer>1</integer>
<key>onboarding</key>
<false/>
<key>organization</key>
<string>your-team-name</string>
<key>service_mode</key>
<string>warp</string>
</dict>
EOF
}
#main program
warp
mdm - Nếu bạn đang sử dụng Debian hoặc RHEL / CentOS, hãy sửa đổi chức năng
warp()để nó cài đặt WARP package ↗ chính xác cho hệ điều hành của bạn. - Thay đổi các giá trị trong hàm
mdm():
- If you are using Debian or RHEL / CentOS, modify the
warp()function so that it installs the correct WARP package ↗ for your OS. - Modify the values in the
mdm()function:
- ប្រសិនបើអ្នកកំពុងប្រើ Debian ឬ RHEL / CentOS, ធ្វើការ
warp()ដើម្បីដំឡើង WARP package ↗ សម្រាប់ប្រព័ន្ធប្រតិបត្តិការរបស់អ្នក។ - ការផ្លាស់ប្តូរគុណសម្បត្តិនៅក្នុងគោលបំណង
mdm():
auth<em>client</em>id và auth<em>client</em>secret, thay thế các giá trị chuỗi bằng Client ID và Client Secret của service token. 2.Đối với Đối với organization, thay thế your-team-name bằng tên nhóm của bạn Zero Trust. 3 Cái (Tùy chọn) Thêm hoặc sửa đổi Cloudflare One Client deployment parameters khác theo sở thích của bạn.auth<em>client</em>id and auth<em>client</em>secret, replace the string values with the Client ID and Client Secret of your service token. 2. For organization, replace your-team-name with your Zero Trust team name. 3. (Optional) Add or modify other Cloudflare One Client deployment parameters according to your preferences.auth<em>client</em>id និង auth<em>client</em>secret, ការផ្លាស់ប្តូរគុណសម្បត្តិ string ដោយ ID Client និង Client Secret នៃ service token របស់អ្នក។ 2 ។ សម្រាប់ organization សូមផ្លាស់ប្តូរ your-team-name ជាមួយ Zero Trust ឈ្មោះក្រុមរបស់អ្នក។ 3 ។ (តម្រូវការ) Add or modify other Cloudflare One Client deployment parameters according to your preferences ។- Nhấn
esc, sau đó nhập:xvà nhấnEnterđể lưu và thoát.
- Press
esc, then type:xand pressEnterto save and exit.
- ចុច
escបន្ទាប់មកចុច:xនិងចុចEnterដើម្បីរក្សាទុកនិងចេញ។
Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)
Bốn Cài đặt WARP 4. Install WARP 4 ។ ទាញយក Warp
Phần «Cài đặt WARP» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.
Read the "4. Install WARP" section below — open the official docs link for full screenshots and configuration tabs.
អានផ្នែក «4 ។ ទាញយក Warp» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។
- Làm cho kịch bản có thể thực hiện:
- Make the script executable:
- សូមធ្វើឱ្យប្រព័ន្ធប្រតិបត្តិការនេះអាចអនុវត្តបាន:
chmod +x install_warp.sh - Chạy kịch bản:
- Run the script:
- ធ្វើការសៀវភៅនេះ:
sudo ./install_warp.sh /var/lib/cloudflare-warp/mdm.xml. Giả sử auto\connect được cấu hình, máy khách Cloudflare One sẽ tự động kết nối với tổ chức Zero Trust của bạn. Sau khi kết nối, thiết bị sẽ xuất hiện trong Cloudflare dashboard ↗ dưới Zero Trust \> Team & Resources \> Devices với email non</em>identity@<team-name>.cloudflareaccess.com./var/lib/cloudflare-warp/mdm.xml. Assuming auto\connect is configured, the Cloudflare One Client will automatically connect to your Zero Trust organization. Once connected, the device will appear in the Cloudflare dashboard ↗ under Zero Trust \> Team & Resources \> Devices with the email non</em>identity@<team-name>.cloudflareaccess.com./var/lib/cloudflare-warp/mdm.xml ។ ប្រសិនបើ auto\connect គឺបានកំណត់, កម្មវិធីអតិថិជន Cloudflare One នឹងបណ្តាញដោយស្វ័យប្រវត្តិជាមួយក្រុមហ៊ុនរបស់អ្នក Zero Trust ។ នៅពេលដែលឧបករណ៍នេះត្រូវបានបង្ហាញនៅក្នុង Cloudflare dashboard ↗ នៅក្រោម Zero Trust \> Team & Resources \> Devices ជាមួយនឹងអ៊ីម៉ែល non</em>identity@<team-name>.cloudflareaccess.com ។{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/cloudflare-one/","name":"Cloudflare One"}},{"@type":"ListItem","position":3,"item":{"@id":"/cloudflare-one/tutorials/","name":"Tutorials"}},{"@type":"ListItem","position":4,"item":{"@id":"/cloudflare-one/tutorials/deploy-client-headless-linux/","name":"Deploy the Cloudflare One Client on headless Linux machines"}}]} Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។
Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗