Tunnel Doctor
cloudflared Docker localhost Troubleshooter
Understand Docker network namespaces and test the origin from inside cloudflared.
What this usually means
Inside a cloudflared container, localhost and 127.0.0.1 normally point back to that cloudflared container. They do not automatically refer to the Docker host or another application container.
What it does not mean
Publishing the application's port on the Docker host does not make localhost inside cloudflared point to that application. Container network namespaces remain separate.
Typical redacted log
ERR Unable to reach the origin service: dial tcp 127.0.0.1:8080: connect: connection refused
Check in this order
These are baseline command examples. For Windows Service or Kubernetes, open the analyzer and select the actual environment to get platform-native commands.
docker inspect -f '{{json .NetworkSettings.Networks}}' <cloudflared-container>docker inspect -f '{{json .NetworkSettings.Networks}}' <origin-container>docker network inspect <shared-network>docker run --rm --network container:<cloudflared-container> curlimages/curl:8.12.1 -v <origin-url>Common false diagnoses
- Assuming localhost means the Docker host.
- Opening another host port instead of putting both containers on a shared network.
- Changing Cloudflare DNS records for a container-to-container routing problem.
How to verify recovery
- cloudflared and the origin share the intended Docker network.
- The origin is reachable by its service/container name from cloudflared's network namespace.
- Fresh Tunnel requests stop producing localhost connection errors.
Still unsure?
Paste the relevant cloudflared log into the local analyzer. Redaction is on by default and the log is not uploaded to a TRACER RECART backend.
Open analyzer