docs: document Twilio-only-scoped Cloudflare Tunnel variant

Adds the actual config used for Summit Dental Care, where the tunnel
points at nginx's port-80 Twilio-only block instead of the whole app,
so only /api/twilio/* is reachable from the internet.
This commit is contained in:
2026-07-12 18:08:22 -04:00
parent 0d2fe63b9b
commit c4c69bfd62

View File

@@ -502,6 +502,44 @@ sudo systemctl start cloudflared
---
### Variant — Tunnel scoped to Twilio webhooks only
The example above tunnels the whole app (`service: http://localhost:3000`) to the public
subdomain. If the only reason you need public access is Twilio's webhooks (inbound SMS/voice —
see [Twilio In-Browser Calling Setup](#twilio-in-browser-calling-setup-dial-pad) below), point
the tunnel at nginx's port-80 block instead, which only forwards `/api/twilio/*` and returns
`403` for everything else (see [nginx.conf](nginx.conf)) — the rest of the app stays unreachable
from the internet even though the tunnel is live.
Example actually used for Summit Dental Care's Twilio integration — paste this into
`/etc/cloudflared/config.yml` (`sudo nano /etc/cloudflared/config.yml`, this is a YAML file, not
the certbot `.ini` credentials file from the LAN HTTPS section above):
```yaml
tunnel: fc423bdb-eaae-4af5-bd6d-961a60b1e624
credentials-file: /home/gg/.cloudflared/fc423bdb-eaae-4af5-bd6d-961a60b1e624.json
ingress:
- hostname: summit.mydentalofficemanagement.com
service: http://localhost:80
- service: http_status:404
```
Then route DNS and install the service same as Steps 67 above:
```bash
cloudflared tunnel route dns summit-dental-twilio summit.mydentalofficemanagement.com
sudo cloudflared service install
sudo systemctl enable cloudflared
sudo systemctl start cloudflared
```
Skip Steps 89 (Vite `allowedHosts` / backend CORS) for this variant — the public hostname never
reaches the frontend or triggers a login/API CORS check, only the unauthenticated Twilio webhook
routes.
---
### Multi-office overview
Each office runs its own `cloudflared` tunnel on its own PC. Ports never conflict because each PC is a separate machine.