The "No Open Ports" Lie
It started with a simple premise: port forwarding is for people who enjoy having their NAS cryptomined. Also for people who think "admin/admin" is a strong password.
April 2026. Home Assistant on a dedicated machine. Wanted remote access without Nabu Casa. ChatGPT suggested Cloudflare Tunnels. "No open ports, free TLS, Access policies." Sounded perfect — famous last words.
Two days later I was debugging why cloudflared on Home Assistant OS wouldn’t trust the proxy IP. The error — 400 Bad Request — haunted me for an evening. The fix was three lines in configuration.yaml and a full restart (not the "quick reload" that lies to you). trusted_proxies: 172.30.33.0/24. Works now. Three lines. One evening. The ratio haunts me.
Then came the Proxmox host. Installed cloudflared directly on the host (dpkg, not Docker — at first). Exposed Proxmox UI, Portainer. Later added the media stack services.
Proxmox spoke HTTPS on 8006. cloudflared expected HTTP. noTLSVerify: true + https://127.0.0.1:8006. Portainer same — HTTPS on 9443, self-signed cert, noTLSVerify needed there too. Two evenings for three config lines. The ratio still haunts me. At this point I have memorized noTLSVerify better than my own phone number.
The Pivot
April 25. A conversation titled "Cloudflare vs Twingate."
I’d been using Cloudflare Tunnels for public ingress — services that need HTTPS, Access policies, WebSocket support. But the private stuff? SSH into Proxmox, database connections, internal APIs, mounting network drives. Cloudflare Access works for HTTP but sucks for "I want my laptop to behave like it’s inside my LAN."
The assistant’s breakdown was clear: Cloudflare = expose services through Cloudflare edge. Twingate = join your laptop to your private network. Different tools for different jobs.
The recommendation: use both. (Because why have one tunnel when you can have two?)
Cloudflare for dashboards (Portainer, Proxmox UI), public-ish services.
Twingate for SSH, database connections, private services you don’t want exposed at all.
The TV Rabbit Hole (Separate Thread)
It started with a real problem: Plex remote streaming quality was terrible.
Hotel WiFi, family visits — 1080p transcoding on the Ryzen 5600 CPU looked like garbage. Buffering, artifacts, the works. Plex Remote Watch ($2/mo) helped with connectivity but not quality. It’s like paying for a gym membership but only using the water fountain. And the water fountain is broken.
So I looked into running Twingate on the TV directly. Android TV, maybe there’s an app? No. Philips TV runs Android TV but no Twingate client in the Play Store for TV. Chromecast? Even worse — no apps at all. Google really wants you to use their ecosystem, preferably with a credit card attached. I checked. There is no Twingate for Android TV. There is no Twingate for Chromecast. There is no Twingate for "smart" TVs that stopped getting updates in 2019.
Then I researched running a Twingate headless client on a separate machine and routing the TV through it. The assistant suggested this path: Debian VM, headless client, TV gateway = VM, NAT + IP forwarding. Sounded reasonable at 11 PM. It was not reasonable.
That didn’t work either. twingate start killed SSH. YouTube spun forever because the VM NAT’d everything to the tunnel interface. The iptables fix worked technically — split routing, sdwan0 for Twingate resources, ens18 for internet — but the Twingate headless client solution simply didn’t fix the Plex problem even after all the tweaking. I had built a Rube Goldberg machine that worked perfectly for everything except the thing I built it for. It was a masterpiece of engineering that solved a problem I didn’t have while ignoring the one I did.
In the end? Upgraded from Plex Remote Watch to Plex Pass (monthly). GTX 1060 NVENC unlocked. Hardware transcoding. Multiple concurrent remote streams, smooth 1080p, 4K→1080p works. Fixed all my Plex issues. $5/mo vs three evenings of iptables debugging. The math is embarrassing. I could have bought a nice dinner for the cost of those three evenings. Instead I have iptables rules I’ll never fully understand.
What I Actually Run Now
Current setup: Cloudflare Tunnel (public dashboards — Proxmox UI, Portainer, media stack; Access policies, WebSocket for Home Assistant) + Twingate connector on the Infra Node Docker VM (private infra — SSH, DB, AdGuard, Samba/NFS; resource-based, split tunneling). Zero open ports.
It’s two tunnel systems doing different jobs. Cloudflare handles "I want HTTPS on my dashboard." Twingate handles "I want my laptop to think it’s in my living room." They don’t overlap. They don’t fight. It’s the only relationship in my infrastructure that works this well.
The Compromises I Live With
| Thing | Reality |
|---|---|
| Twingate connector HA | Single connector. If it dies, no private access. I’ll deal with it when it happens. Probably at 2 AM. On a Sunday. During a holiday. |
| mDNS across homes | Doesn’t cross natively. Solved with Twingate DNS rewrites + AdGuard in both homes routing all traffic. Works. Don’t ask me to explain it at a party. You’ll lose the will to live. |
The Honest Summary
Six months ago: "I’ll just use Cloudflare Tunnels, no open ports, done."
Today: Two tunnel systems. The headless client experiment failed — removed it. Kept the Twingate connector for remote network access. Chromecast that still won’t cast from a hotel. A trusted_proxies line I’ve memorized. The Proxmox HTTPS mismatch that cost two evenings. I have noTLSVerify: true in more places than I’m comfortable admitting.
Zero open ports. Works from anywhere. No "install this app" for family.
But the diagram in my head is messier than the one I’d draw for a blog post. The Twingate connector has no HA. The DNS rewrites only work inside the tunnel. The Chromecast problem is fundamentally unsolvable without Google’s cooperation — and they have zero incentive to fix it. I’ve accepted that my TV will never be "smart" enough for my tunnel.
Engineering is trade-offs. This one works. Mostly. At 2 AM I still check twingate status sometimes, like a nervous parent checking on a sleeping baby. The baby is a VPN connector. The parent is me. We both need therapy.