diff --git a/README.md b/README.md index 23ee2980..db48cbad 100644 --- a/README.md +++ b/README.md @@ -502,6 +502,44 @@ sudo systemctl start cloudflared --- +### Variant — Tunnel scoped to Twilio webhooks only + +The example above tunnels the whole app (`service: http://localhost:3000`) to the public +subdomain. If the only reason you need public access is Twilio's webhooks (inbound SMS/voice — +see [Twilio In-Browser Calling Setup](#twilio-in-browser-calling-setup-dial-pad) below), point +the tunnel at nginx's port-80 block instead, which only forwards `/api/twilio/*` and returns +`403` for everything else (see [nginx.conf](nginx.conf)) — the rest of the app stays unreachable +from the internet even though the tunnel is live. + +Example actually used for Summit Dental Care's Twilio integration — paste this into +`/etc/cloudflared/config.yml` (`sudo nano /etc/cloudflared/config.yml`, this is a YAML file, not +the certbot `.ini` credentials file from the LAN HTTPS section above): + +```yaml +tunnel: fc423bdb-eaae-4af5-bd6d-961a60b1e624 +credentials-file: /home/gg/.cloudflared/fc423bdb-eaae-4af5-bd6d-961a60b1e624.json + +ingress: + - hostname: summit.mydentalofficemanagement.com + service: http://localhost:80 + - service: http_status:404 +``` + +Then route DNS and install the service same as Steps 6–7 above: + +```bash +cloudflared tunnel route dns summit-dental-twilio summit.mydentalofficemanagement.com +sudo cloudflared service install +sudo systemctl enable cloudflared +sudo systemctl start cloudflared +``` + +Skip Steps 8–9 (Vite `allowedHosts` / backend CORS) for this variant — the public hostname never +reaches the frontend or triggers a login/API CORS check, only the unauthenticated Twilio webhook +routes. + +--- + ### Multi-office overview Each office runs its own `cloudflared` tunnel on its own PC. Ports never conflict because each PC is a separate machine.