cloudflared: Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared (502)
The tunnel is connected, but cloudflared can’t reach your local service at the address in the ingress rule.
Seen on:
Cloudflare
Meaning
The ingress service URL (http://localhost:8080) is wrong, the app isn’t running, it listens on another interface, or HTTPS is used without the right origin certificate settings. Inside Docker, localhost refers to the cloudflared container.
Common causes
- Local app not running or wrong port
- cloudflared in Docker using localhost instead of the service/container name
- HTTPS origin with self-signed cert (needs noTLSVerify or originServerName)
- App bound to 127.0.0.1 but cloudflared on another host
⚡ Quick fix
- curl the service URL from where cloudflared runs
- Fix the ingress service address (use container name in Docker networks)
- Set originRequest.noTLSVerify for self-signed origins
Detailed fix by platform
YAML
- bash
ingress: - hostname: app.example.com service: http://web:8080 # container name, not localhost, in Docker originRequest: noTLSVerify: true - service: http_status:404
How to diagnose
- Service — Reachable from the cloudflared host/container?
- Logs — cloudflared error lines
- TLS — HTTPS origin?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Cloudflare
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026