I’ve had my HA system running for about 4-5 years now. For external access, I used to use DuckDNS, and then a year or two ago I switched to a CloudFlare tunnel. All was good.
My HA configuration is a total disaster, orphaned add-ons that no longer work, configuration lines that refer to missing integrations, etc. So today I finally decided to start some overdue spring cleaning.
Which brings me to the http section of my configuration.yaml file. It looks like:
http:
server_port: 8123
ssl_certificate: /ssl/fullchain.pem
ssl_key: /ssl/privkey.pem
use_x_forwarded_for: true
trusted_proxies:
- 172.30.33.0/24
As with all of this clean-up, my first approach was “delete it and see what happens” – so after deleting the entire http block, and being locked out of my HA config (via the web) I realized that was bad, so I quickly restored it.
But after doing more digging into this, it seems the only two lines I should need are the latter two (specifically for CloudFlare forwarding to my docker ingress). Each of the AI models I’ve asked about this also state that the first three lines should absolutely not be necessary for the CF tunnel to work, yet when I delete these lines, I can still access HA via my local URL, but not via Cloudflare.
Is there still some DuckDNS remnant lying around that’s breaking something, or is there some other “cloudflared” config that I need to be looking at to determine why these SSL lines are needed here at all?