<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Cloudflare on cbugk&#39;s blog</title>
    <link>https://blog.cbugk.com/tags/cloudflare/</link>
    <description>Recent content in Cloudflare on cbugk&#39;s blog</description>
    <generator>Hugo -- 0.140.2</generator>
    <language>en-us</language>
    <lastBuildDate>Wed, 28 Jan 2026 11:12:00 +0300</lastBuildDate>
    <atom:link href="https://blog.cbugk.com/tags/cloudflare/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Letting Auditors into My Hypervisors</title>
      <link>https://blog.cbugk.com/post/letting-auditors-into-hypervisors/</link>
      <pubDate>Wed, 28 Jan 2026 11:12:00 +0300</pubDate>
      <guid>https://blog.cbugk.com/post/letting-auditors-into-hypervisors/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;
&lt;p&gt;I would like to showcase an internet-accessible, hardened homelab some time in 2026. Before I forget, I need to document how to let people log into my Proxmox nodes with their Google accounts as auditors. This post assumes that network access has been provided one way or another.&lt;/p&gt;
&lt;h2 id=&#34;ingredients&#34;&gt;Ingredients&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;A domain name (managed by CloudflareDNS)&lt;/li&gt;
&lt;li&gt;PVE 9.1: Just-In-Time login target&lt;/li&gt;
&lt;li&gt;Cloudflared (for exposing Authentik&amp;rsquo;s ACME client)&lt;/li&gt;
&lt;li&gt;Authentik: OpenID login broker&lt;/li&gt;
&lt;li&gt;Google Cloud - Google Auth Platform Client&lt;/li&gt;
&lt;li&gt;A Google account&lt;/li&gt;
&lt;li&gt;Chatbot of your liking&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&#34;pre-requisites&#34;&gt;Pre-Requisites&lt;/h2&gt;
&lt;h3 id=&#34;proxmox-ve-with-https&#34;&gt;Proxmox VE with HTTPS&lt;/h3&gt;
&lt;p&gt;For authentication to work, services being exposed should have secured subdomains. This &lt;a href=&#34;https://weblog.lkiesow.de/20240114-pve-acme-cloudflare.html&#34;&gt;short blog by Ikiesow&lt;/a&gt; covers most of the process. Create API key from Cloudflare dashboard to be used by Proxmox VE under Datacenter/ACME for DNS-01 or HTTP-01 challanges.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
