Skip to content

Harden Cloudflare Quick as the bounded temporary public fallback #272

Description

@gongahkia

Decision

Transport scope T2: retain and harden Cloudflare Quick as one explicit, temporary public-relay fallback when a user cannot use a private network.

Product boundary

  • It is temporary Quick Tunnel access only; no account-managed/named Cloudflare surface.
  • It must use the existing fragment-keyed app-layer E2E framing. Cloudflare may see traffic metadata but must not receive terminal bytes, typed input, approval payloads, or control contents in plaintext.
  • It remains opt-in, never an automatic fallback from private transports.

Required evidence

  • Verify pair, PTY, events, controls, and approval decisions are covered by the E2E path with no plaintext bypass.
  • Fail closed if relay E2E bootstrap, verifier, or framing is unavailable.
  • Keep a documented real-device/reconnect/restart smoke gate and reliable child-process cleanup.
  • Give users concise, accurate disclosure of what relay metadata remains visible.

Acceptance criteria

  • Public Cloudflare Quick behavior is bounded to this contract; no named-tunnel/account-management behavior leaks back in.
  • Security, reconnection, cleanup, and real-device tests pass.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions