← Back to capsules
DevOps AWS Backend Cloudflare Seguridad

My containers on AWS have no open port to the internet

Published on July 7, 2026

𝗠𝘆 𝗰𝗼𝗻𝘁𝗮𝗶𝗻𝗲𝗿𝘀 𝗼𝗻 𝗔𝗪𝗦 𝗵𝗮𝘃𝗲 𝗻𝗼 𝗼𝗽𝗲𝗻 𝗽𝗼𝗿𝘁 𝘁𝗼 𝘁𝗵𝗲 𝗶𝗻𝘁𝗲𝗿𝗻𝗲𝘁 🔒

And yet they receive real user traffic. 😅

Setting up infra for a production project on 𝗔𝗪𝗦, I asked myself the question every dev should ask before touching a security group: do I 𝗿𝗲𝗮𝗹𝗹𝘆 𝗻𝗲𝗲𝗱 𝘁𝗼 𝗲𝘅𝗽𝗼𝘀𝗲 𝘁𝗵𝗶𝘀?

The answer was no. The solution: 𝗖𝗹𝗼𝘂𝗱𝗳𝗹𝗮𝗿𝗲 𝗧𝘂𝗻𝗻𝗲𝗹.

This is how traffic flows:

🔹 The container on 𝗘𝗖𝟮 opens an 𝗼𝘂𝘁𝗯𝗼𝘂𝗻𝗱 connection to Cloudflare

🔹 Cloudflare receives the user's request

🔹 Routes it through the tunnel to the container

🔹 𝗡𝗼 𝗼𝗽𝗲𝗻 𝗽𝗼𝗿𝘁𝘀. No exposed IP.

Result: zero attack surface from the internet. 💪

Do you already use tunnels in your infra or do you still rely only on security groups? 👇

Keep flying, Champions! ✈️