+39
−6
Loading
cloudflared writes the tunnel credentials JSON only at `tunnel create`. An idempotent re-run against a tunnel that already exists — or a reset + re-bootstrap where the old box's ~/.cloudflared was wiped but the Cloudflare-side tunnel survived — finds no local credentials file, and the connector crash-loops with "Tunnel credentials file doesn't exist". A tunnel that never comes up leaves op.console unreachable, so the one-time setup link minted just before it ages out (30-min TTL) unredeemed. CreateTunnel now resolves the tunnel id on both paths (fresh create and already-exists) and routes through ensureCredentials, which re-fetches the token with `cloudflared tunnel token --cred-file` (authenticating via cert.pem, preserving the same id / DNS / Access) when the file is absent. The secret is written to the file, not stdout, and the file is chmod 0600 so it is not left world-readable next to cert.pem. The self-heal is unconditional on re-bootstrap: Setup gates on Pre.check() (cert.pem present) before CreateTunnel, so the token re-fetch always has its cert.pem authority.