Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Collabora Online (CODE)
  3. Update Documentation to warn of Cloudflare Proxy issues

Update Documentation to warn of Cloudflare Proxy issues

Scheduled Pinned Locked Moved Collabora Online (CODE)
feature-requesttrusted ips
5 Posts 3 Posters 214 Views 3 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • marcusquinnM Offline
    marcusquinnM Offline
    marcusquinn
    wrote last edited by
    #1
    • https://docs.cloudron.io/packages/collabora/

    Connecting Nextcloud to the Cloudron Collabora Online app doesn't work by default with Cloudflare Proxy enabled on the subdomain.

    The fix is to add Cloudflare Trusted IPs to your Cloudron > Network > Configure Trusted IPs & Ranges, like so:

    # Cloudflare IPv4 ranges
    173.245.48.0/20
    103.21.244.0/22
    103.22.200.0/22
    103.31.4.0/22
    141.101.64.0/18
    108.162.192.0/18
    190.93.240.0/20
    188.114.96.0/20
    197.234.240.0/22
    198.41.128.0/17
    162.158.0.0/15
    104.16.0.0/13
    104.24.0.0/14
    172.64.0.0/13
    131.0.72.0/22
    # Cloudflare IPv6 ranges
    2400:cb00::/32
    2606:4700::/32
    2803:f800::/32
    2405:b500::/32
    2405:8100::/32
    2a06:98c0::/29
    2c0f:f248::/32
    

    Source: https://www.cloudflare.com/en-gb/ips/

    @girish and @nebulon I wonder if these IPs should be pulled and updated from the Cloudflare API when anyone uses Cloudflare DNS settings in Cloudron?

    Might save from much confusion potential and many support issues?

    Web Design & Development: https://www.evergreen.je
    Technology & Apps: https://www.marcusquinn.com

    1 Reply Last reply
    4
    • jamesJ Online
      jamesJ Online
      james
      Staff
      wrote last edited by
      #2

      Hello @marcusquinn
      That is interesting and might be worth considering when using Cloudflare as the DNS provider.
      Questions I am asking myself are the following:

      • should this be done by default when Cloudflare is used
      • should this only be done if Cloudflare is used with the Enable proxying for new DNS records setting is enabled
        d0cd2081-f5db-4735-880b-af5357fcd982-image.png
      • how often should this list be checked for updates to prevent wrong IP addresses in the Trusted IPs setting

      I like idea.

      fbartelsF 1 Reply Last reply
      2
      • jamesJ james

        Hello @marcusquinn
        That is interesting and might be worth considering when using Cloudflare as the DNS provider.
        Questions I am asking myself are the following:

        • should this be done by default when Cloudflare is used
        • should this only be done if Cloudflare is used with the Enable proxying for new DNS records setting is enabled
          d0cd2081-f5db-4735-880b-af5357fcd982-image.png
        • how often should this list be checked for updates to prevent wrong IP addresses in the Trusted IPs setting

        I like idea.

        fbartelsF Offline
        fbartelsF Offline
        fbartels
        App Dev
        wrote last edited by
        #3

        @james said in Update Documentation to warn of Cloudflare Proxy issues:

        should this be done by default when Cloudflare is used

        Does this refer to the Allow list for WOPI requests setting in Nextcloud? Automatically allowing all requests that come from the Cloudflare infrastructure seems like a bad idea for me.

        1 Reply Last reply
        1
        • jamesJ Online
          jamesJ Online
          james
          Staff
          wrote last edited by
          #4

          Hello @fbartels

          @marcusquinn said in Update Documentation to warn of Cloudflare Proxy issues:

          The fix is to add Cloudflare Trusted IPs to your Cloudron > Network > Configure Trusted IPs & Ranges, like so:

          As I understood it, it is about the https://docs.cloudron.io/networking/#trusted-ips configuration and not the app itself and not the WOPI setting of this specific app.
          This post is also more a feature request with the example working on collabora.

          marcusquinnM 1 Reply Last reply
          2
          • jamesJ james

            Hello @fbartels

            @marcusquinn said in Update Documentation to warn of Cloudflare Proxy issues:

            The fix is to add Cloudflare Trusted IPs to your Cloudron > Network > Configure Trusted IPs & Ranges, like so:

            As I understood it, it is about the https://docs.cloudron.io/networking/#trusted-ips configuration and not the app itself and not the WOPI setting of this specific app.
            This post is also more a feature request with the example working on collabora.

            marcusquinnM Offline
            marcusquinnM Offline
            marcusquinn
            wrote last edited by
            #5

            @james @fbartels Correct, this is just for pre-populating and updating the values in Cloudron > Network > Configure Trusted IPs & Ranges, when "Enable proxying for new DNS records" is ticked on any app.

            If you are using Cloudflare Proxying, you are implying you trust Cloudflare IPs to relay traffic.

            The Nextcloud WOPI setting, although I think it could be pre-populated, is easier to do from following the documentation, if there's any concern why you wouldn't want that internal IP address pre-populated. Although, I can't think of why you would be concerned with an internal IP address being pre-populated in Nextcloud.

            Web Design & Development: https://www.evergreen.je
            Technology & Apps: https://www.marcusquinn.com

            1 Reply Last reply
            1
            Reply
            • Reply as topic
            Log in to reply
            • Oldest to Newest
            • Newest to Oldest
            • Most Votes


            • Login

            • Don't have an account? Register

            • Login or register to search.
            • First post
              Last post
            0
            • Categories
            • Recent
            • Tags
            • Popular
            • Bookmarks
            • Search