Back to articles
Technology Insight

Building a Zero-Trust Remote Access Architecture: Integrating Teleport with Cloudflare Access on a VPS

June 4, 2026

Introduction to Modern Infrastructure Security

In the contemporary digital landscape, traditional perimeter-based security models—often referred to as 'castle-and-moat' security—are no longer sufficient. The rise of remote work, distributed teams, and cloud-hosted infrastructure has dissolved the traditional corporate network boundary. Relying solely on a Virtual Private Network (VPN) or open SSH ports exposes organizations to significant risks, including credential theft, lateral movement, and brute-force attacks.

To mitigate these vulnerabilities, modern enterprises are pivoting toward a Zero-Trust Architecture (ZTA). The core philosophy of Zero Trust is simple yet absolute: never trust, always verify. This blog post provides an enterprise-grade technical guide on building a Zero-Trust Remote Access system by integrating Teleport, a cutting-edge access plane, with Cloudflare Access, a leader in Identity and Access Management (IAM) and secure edge routing, all deployed on a standard Virtual Private Server (VPS).

Understanding the Core Components

Before diving into the integration process, it is essential to understand the roles that both Teleport and Cloudflare Access play in this architecture:

  • Teleport: An open-source identity-aware access plane that consolidates SSH, Kubernetes, web apps, and database access. It replaces static public keys with short-lived certificates issued via Single Sign-On (SSO), providing robust auditing capabilities and session recording.
  • Cloudflare Access: A component of Cloudflare Zero Trust that acts as a secure reverse proxy. It evaluates every request to your infrastructure for identity, device posture, and context, effectively hiding your VPS from the public internet.

By combining these two technologies, you create a multi-layered defense system where Cloudflare Access handles edge authentication and network cloaking, while Teleport manages granular, role-based access control (RBAC) and deep session auditing inside the infrastructure.

Prerequisites and Architecture Overview

To successfully implement this setup, ensure you have the following prerequisites ready:

  1. A Linux-based VPS (e.g., Ubuntu 22.04 LTS or newer) with a public IP address.
  2. A registered domain name fully managed under a Cloudflare account.
  3. A Cloudflare Zero Trust account (available under a generous free tier for small teams).
  4. Administrative access to configure DNS records and system services.
Architecture Note: In this deployment, the VPS will not expose port 22 (SSH) or port 443 (Teleport Web UI) directly to the entire internet. Instead, Cloudflare Tunnels (Cloudflared) will establish an outbound-only connection to the Cloudflare Edge. Users authenticating via Cloudflare Access will be routed through this tunnel directly to the Teleport instance.

Step 1: Preparing the VPS and Installing Teleport

First, update your local package index and install the official Teleport binary repository on your VPS. Execute the following commands in your terminal:

sudo apt-get update && sudo apt-get install -y curl apt-transport-https
curl [https://goteleport.com/static/install.sh](https://goteleport.com/static/install.sh) | bash -s 14.3.3

Once installed, generate a baseline configuration file for Teleport. We will configure Teleport to manage local SSH access and host its proxy service. Replace teleport.yourdomain.com with your actual subdomain:

sudo teleport configure --cluster-name=teleport.yourdomain.com --public-addr=teleport.yourdomain.com:443 -o /etc/teleport.yaml

Open /etc/teleport.yaml in a text editor to verify the settings. Ensure the ssh_service and proxy_service are enabled, then start and enable the Teleport daemon:

sudo systemctl enable teleport
sudo systemctl start teleport

Step 2: Configuring the Cloudflare Tunnel (Cloudflared)

To completely isolate the VPS from inbound internet traffic, we install the Cloudflare Tunnel client. This agent creates an encrypted outbound connection to Cloudflare.

Navigate to the Cloudflare Zero Trust Dashboard, go to Networks > Tunnels, and select 'Create a Tunnel'. Name your tunnel (e.g., vps-zero-trust) and copy the installation script provided for your specific architecture. The command will resemble the following:

curl -L --output cloudflared.deb [https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb](https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb) && dpkg -i cloudflared.deb
sudo cloudflared service install YOUR_TUNNEL_TOKEN

After the service connects successfully, configure the routing inside the Cloudflare dashboard. Route your public hostname (e.g., teleport.yourdomain.com) to the local service address on the VPS, pointing to https://localhost:443. Ensure that you enable 'No TLS Verify' under the HTTP Settings tab, as Teleport may use self-signed certificates initially before Cloudflare applies its edge certificates.

Step 3: Enforcing Zero-Trust Policies with Cloudflare Access

With traffic successfully routing through the Cloudflare Tunnel, the next phase is protecting the hostname with identity verification. Cloudflare Access integrates seamlessly with Identity Providers (IdPs) such as Google Workspace, Okta, Microsoft Entra ID, or github.

  1. In the Cloudflare Zero Trust Dashboard, navigate to Access > Applications.
  2. Click Add an Application and select Self-Hosted.
  3. Enter your Application Name and specify the Application Domain (e.g., teleport.yourdomain.com).
  4. Scroll down to configure the Rules policy. Define who can access this application. For example, you can create a rule stating: Action: Allow, Include: Emails ending in @yourcompany.com.
  5. Save the application.

At this point, any attempt to visit teleport.yourdomain.com will immediately redirect the browser to a Cloudflare login page, shielding the Teleport login screen from unauthorized users and automated bot scanners.

Step 4: Advanced Teleport Configuration & Creating Users

Now that the outer perimeter is secured by Cloudflare, we must configure internal access controls. Return to your VPS terminal to create an administrative user within Teleport:

sudo tctl users add admin --roles=editor,access --logins=root,ubuntu

The terminal will output a unique registration link. Copy this link and paste it into your browser. Because of our setup in Step 3, you will first authenticate via Cloudflare Access. Once authorized, you will land on the Teleport setup wizard to register your multi-factor authentication (MFA) device and establish your local Teleport password.

Teleport leverages Short-Lived Certificates for all downstream access. When a developer or system administrator needs to access the VPS via SSH, they do not use a persistent SSH key. Instead, they authenticate through the command line using the Teleport CLI tool (tsh):

tsh login --proxy=teleport.yourdomain.com:443

This command issues a certificate valid for a limited window (e.g., 8 hours). Once expired, access is automatically revoked until the user re-authenticates against the Zero-Trust identity provider.

Security Benefits Analysis

Implementing this integrated architecture yields substantial security improvements over standard remote access configurations:

Security DimensionTraditional Approach (VPN/Open SSH)Teleport + Cloudflare Zero-Trust
Network VisibilityPublicly open ports or vulnerable VPN endpoints exposed to the internet.Total network cloaking. No inbound ports open on the VPS firewall.
Credential ManagementStatic SSH private keys that can be leaked, lost, or hard to rotate.Short-lived x509 and SSH certificates issued dynamically based on active sessions.
Authentication LevelsSingle-factor or isolated MFA at the network boundary.Dual-layer validation: Edge Identity Provider matching followed by Hardware MFA (WebAuthn/YubiKey).
Compliance & AuditingRudimentary text logs in syslog, easily altered if a system is compromised.Structured JSON audit logs, cryptographic session recording, and live session mirroring.

Conclusion and Continuous Monitoring

Integrating Teleport with Cloudflare Access on a VPS represents a gold standard for secure remote infrastructure management. By shifting the security boundary from the network layer to the identity layer, you ensure that unauthorized actors cannot even attempt an exploit against your servers. Your infrastructure remains completely hidden from public scanning tools while providing a friction-free, single-sign-on experience for your legitimate engineering and operations teams.

As a best practice moving forward, regularly audit your Cloudflare Access logs alongside Teleport’s session compliance recordings to maintain continuous monitoring over your newly established Zero-Trust perimeter.

Building a Zero-Trust Remote Access Architecture: Integrating Teleport with Cloudflare Access on a VPS | DPTCloud