Add self-healing Cloudflare tunnel with 60s watchdog for USB deck.

Replaces fragile batch-based tunnel install with a single PowerShell
script (cloudflare/start-tunnel.ps1) that installs cloudflared as a
Windows service (admin) or runs as a background process (non-admin),
clears stale EventLog registry keys that caused service rollback, and
runs a 60-second watchdog that auto-restarts the connector on failure.
Hostname changed to aether.thetempleofdoom.com. LAUNCH.bat and
pack-usb.bat updated accordingly.
This commit is contained in:
AetherForge
2026-06-01 15:03:17 -07:00
parent feba06e008
commit 3605d540da
18 changed files with 1455 additions and 215 deletions

View File

@@ -1,22 +1,56 @@
========================================================
AetherForge — Cloudflare Tunnel
https://killa.thetempleofdoom.com
https://killa.thetempleofdoom.com -> localhost:8989
========================================================
NO SETUP REQUIRED.
AUTOMATIC — nothing to configure.
The tunnel token is baked into LAUNCH.bat. On first run it will:
1. Install cloudflared from cloudflared-windows-amd64.msi (if needed)
2. Register the cloudflared Windows service with your token
3. Start the service — tunnel points at localhost:8989
LAUNCH.bat opens a second window "AetherForge Tunnel" that:
1. Finds cloudflared (bundled here or downloads if missing)
2. Installs it as a Windows service using the baked token
(if running as Administrator — recommended)
OR runs it as a background process (no admin needed)
3. Waits for killa.thetempleofdoom.com to respond
4. Checks every 60 seconds and auto-restarts if tunnel drops
Just double-click LAUNCH.bat in the parent folder (Run as Administrator
once if service install fails).
Log file: data\logs\tunnel.log
After that:
Dashboard: https://killa.thetempleofdoom.com
Dropper: iex (irm 'https://killa.thetempleofdoom.com/install.ps1')
ROUTING
-------
Routing is managed in Cloudflare Zero Trust dashboard:
Zero Trust > Networks > Tunnels > your tunnel
> Public Hostname: killa.thetempleofdoom.com -> http://localhost:8989
credentials.json is NOT used — ignore the placeholder file if present.
The tunnel connector (cloudflared) connects this machine to Cloudflare.
The dashboard route tells Cloudflare where to send incoming traffic.
BOTH must be correct for the public URL to work.
VERIFY
------
When LAUNCH.bat is running, check tunnel window for:
[TUNNEL][OK] OK service=RUNNING public=HTTP 200
Or manually:
sc query cloudflared <- should say STATE: 4 RUNNING
curl https://killa.thetempleofdoom.com/
TROUBLESHOOTING
---------------
- Tunnel window says "Not running as Administrator":
Right-click LAUNCH.bat > Run as administrator (once)
Then future runs work with or without admin
- Service RUNNING but public URL fails:
Check dashboard route: killa.thetempleofdoom.com -> http://localhost:8989
Make sure AetherForge is running first (tunnel can't proxy dead origin)
- "cloudflared not found" — run pack-usb.bat on dev PC to rebundle
FILES
-----
start-tunnel.ps1 <- main script (install + watchdog)
tunnel-config.json <- token, hostname, origin (edit to change)
cloudflared.exe <- bundled binary (~52 MB)
cloudflared-windows-amd64.msi <- MSI installer backup
========================================================