cloudflared Unable to reach the origin service 🟧 Cloudflare

cloudflared: Unable to reach the origin service. The service may be down or it may not be responding to traffic from cloudflared (502)

The tunnel is connected, but cloudflared can’t reach your local service at the address in the ingress rule.

Seen on: Cloudflare

Meaning

The ingress service URL (http://localhost:8080) is wrong, the app isn’t running, it listens on another interface, or HTTPS is used without the right origin certificate settings. Inside Docker, localhost refers to the cloudflared container.

Common causes

  • Local app not running or wrong port
  • cloudflared in Docker using localhost instead of the service/container name
  • HTTPS origin with self-signed cert (needs noTLSVerify or originServerName)
  • App bound to 127.0.0.1 but cloudflared on another host

⚡ Quick fix

  1. curl the service URL from where cloudflared runs
  2. Fix the ingress service address (use container name in Docker networks)
  3. Set originRequest.noTLSVerify for self-signed origins

Detailed fix by platform

YAML

  1. bash
    ingress:
      - hostname: app.example.com
        service: http://web:8080        # container name, not localhost, in Docker
        originRequest:
          noTLSVerify: true
      - service: http_status:404

How to diagnose

  1. Service — Reachable from the cloudflared host/container?
  2. Logs — cloudflared error lines
  3. TLS — HTTPS origin?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.