Telling Technology · Learning in public
All episodes TL;DR →
EP.27 — CLOUDFLARE TUNNEL
The simplest infra is the kind that forgets you

I deleted Tailscale from my phone AI — one Cloudflare command gives me HTTPS in seconds

My phone voice AI needs a trusted HTTPS URL or the browser won't hand it the microphone. I was solving that with Tailscale — an account, a device to enroll, DNS to point. Then I found cloudflared quick tunnels: no account, one command, and a live *.trycloudflare.com URL with a real trusted certificate in seconds. I wrapped it in a 20-line script and pulled Tailscale out of the loop.

A terminal running run-tunnel.ps1 printing a live https://something.trycloudflare.com URL, next to a phone on cellular loading the voice-AI mic UI over that same URL, house aurora-teal style
⌁ one command · live HTTPS · no account · ~3s to a phone-ready URL
First: why a local server is useless to a phone until it's HTTPS
01 The problem · the phone won't talk to localhost

The voice AI worked on my desk — and was unreachable from my phone

Last episode I put a voice assistant on my phone: tap to talk, it routes the question, it talks back. The catch nobody mentions: a browser will only hand a page the microphone over HTTPS with a trusted certificate. My voice server runs on localhost with no cert, so on the phone the mic button was dead. My fix was Tailscale — it gave me a stable private address with HTTPS, and it worked. But it's heavy: an account, the app installed and enrolled on every device, and a fresh machine means re-auth, re-enroll, re-configure before the phone can hear a thing.

claude code — desktop
> the phone mic won't turn on over http — i'm exposing the voice server with tailscale and it works, but it's a lot: account, device enrollment, dns. is there a lighter way to get trusted https to my phone?
The mic gate is real — browsers require a secure context for getUserMedia, so you need a trusted cert, not just a LAN IP. Tailscale solves it but it's a persistent identity layer you have to enroll into. If you just need an ephemeral public HTTPS URL pointing at a local port, cloudflared quick tunnels do exactly that with no account. Want the one-liner?
A diagram of the Tailscale setup: phone and laptop each needing an account login, device enrollment and DNS before a private HTTPS link connects them, labelled 'works — but heavy', house aurora-teal style
the heavy way
tailscale: account + device enrollment + dns, per machine
02 The fix · one command, zero account

cloudflared quick tunnels: one line, a live trusted URL, nobody asked who I was

A Cloudflare quick tunnel needs no account and no DNS. You run cloudflared tunnel --url http://localhost:8080 and it hands back a *.trycloudflare.com address — a real, browser-trusted HTTPS endpoint forwarding straight to your local port, live in a couple of seconds. I'd already folded the voice UI and the WebSocket onto one port (UI on /, socket on /ws), so one tunnel URL covers the whole app. Then I wrapped the command in run-tunnel.ps1 — it starts the tunnel and prints a fat "copy this URL to your phone" line, so there's no hunting through log output.

powershell — run-tunnel.ps1
> ./run-tunnel.ps1
Starting voice server on :8080 … up.
Opening Cloudflare quick tunnel …
──────────────────────────────
📱 Copy to your phone:
https://calm-river-1234.trycloudflare.com
──────────────────────────────
No account. No DNS. Trusted cert. Ctrl-C closes the tunnel and the URL dies.
A terminal where cloudflared prints a fresh https trycloudflare.com URL highlighted in a box that says 'copy to your phone', with the local :8080 voice server feeding it, house aurora-teal style
the light way
one command → a live phone-ready HTTPS URL
03 The honest part · what you trade for "no account"

The URL is throwaway — and that's the feature, not a bug, but know the trade

A quick tunnel is deliberately disposable. The URL is random and temporary: close the window and it's gone, run it again and you get a different one. There's no auth in front of it — while it's up, anyone who has that link can reach your local server, so it's a demo/dev tool, not a way to publish a service to the world. And it's rate-limited and offers no uptime promise. For this use case that's perfect: I want a link that forgets me the moment I close the laptop. But if you need a stable address, a private mesh between your own machines, or real access control, that's exactly where Tailscale still earns its keep — I kept it installed as the heavyweight option, I just stopped reaching for it first.

claude code — desktop
> so should i delete tailscale entirely? what am i actually giving up by switching the phone demo to a quick tunnel?
Don't delete it — pick the right tool per job. Quick tunnel: ephemeral, unauthenticated, no account — ideal for "let my phone hit this for 10 minutes." Tailscale: stable identity, private mesh, access control — ideal for an always-on link between machines you own. For the phone voice demo, the throwaway URL is the better fit. Keep Tailscale for the persistent stuff.
A side-by-side trade-off card: quick tunnel column reads ephemeral, no account, no auth, demo-only; Tailscale column reads stable, private mesh, access control, always-on, house aurora-teal style
pick per job
throwaway URL vs persistent mesh — different tools
⚠️

A quick tunnel is an open door while it's open

The *.trycloudflare.com URL has no password in front of it. Anyone holding the link can reach your local server until you Ctrl-C. Fine for a quick phone demo on a non-sensitive dev server; do not point one at anything with private data and walk away. Close the window when you're done — the URL dies with it.

04 The receipts

The script, the URL appearing, the phone on cellular, and the setup compared

Four pieces of the swap: the whole run-tunnel.ps1 on one screen, the moment the trusted URL appears, the phone loading the voice UI on cellular (no Wi-Fi, no VPN), and a plain side-by-side of everything Tailscale asked for versus the single Cloudflare command. Tap any image to enlarge it and read the exact prompt that drew it.

RUNNING LIVE ON CELLULAR — NO ACCOUNT, NO VPN

Tap, talk, answer — over a URL that didn't exist three seconds ago

This is the whole point. I run one script, a trusted HTTPS URL appears, I open it on my phone over plain mobile data, and the voice AI just works — mic and all. No app to install on the phone, no account to log into, nothing enrolled. When I close the laptop the URL evaporates and leaves no trace. The simpler solution was one flag away the whole time — sometimes the best infrastructure is the kind that forgets you the moment you walk away.

A phone held in hand on cellular, mid-conversation with the voice AI, connected through a glowing trycloudflare.com link from a laptop running run-tunnel.ps1 in the background, house aurora-teal style
one command → trusted HTTPS → phone mic live · close the window and the URL is gone
06 Steal this

Give your own localhost a phone-ready HTTPS URL

The run-tunnel.ps1 wrapper (start a local server, open a cloudflared quick tunnel, print the URL in a copy-to-phone box), the single-port pattern that puts your UI and WebSocket behind one tunnel, and the cloudflared install one-liner. Everything in this episode is free and open — clone it, run it, make it yours.

script run-tunnel.ps1 cmd cloudflared one-liner pattern single-port UI + /ws notes when to use Tailscale instead
run it winget install Cloudflare.cloudflared; cloudflared tunnel --url http://localhost:8080

No GitHub? Comment TUNNEL on the post and the bot DMs you the link.

Next episode

I drew my whole AI brain — then asked Claude to code it

This tunnel is one wire in a much bigger machine. Next: the AIOS architecture infographic — every tool in my AI operating system, 20-plus of them with real brand logos, mapped as a single live web page and served as the dashboard banner. One picture of the entire stack the voice AI lives inside.

Darkened teaser — a sprawling node-and-logo map of an entire AI operating system, 20-plus tools wired together as one infographic, house aurora-teal style
drops next · follow @tellingtechnology so you don't miss it