Cloudflare Zero Trust v1.0 • Open Source

GNU Screen Zero Trust

A shell script and configuration for running GNU Screen terminal sessions behind Cloudflare Zero Trust tunnels. It lets you attach to remote sessions without opening inbound firewall ports or managing public SSH keys.

How it works

Traditional remote access

Opening port 22 to the internet requires static IP allowlists or dedicated bastion hosts. If an SSH connection drops, running processes can terminate abruptly.

Cloudflare Zero Trust routing

Cloudflare Tunnel creates an outbound-only connection to Cloudflare edge nodes. Access policies verify identity and MFA before opening terminal access.

Key capabilities

  • Screen multiplexing keeps services running in the background even if your local network connection drops.
  • Cloudflared creates an outbound connection, so servers do not need public IP addresses or forwarded ports.
  • Cloudflare Access enforces authentication policies (such as Google Workspace, GitHub, or one-time PINs) before terminal access is granted.

Quickstart and deployment

bash github.com/ihsanberahim/gnu-screens
# 1. Clone the repository
git clone https://github.com/ihsanberahim/gnu-screens.git
cd gnu-screens

# 2. Configure environment credentials
cp .env.example .env

# 3. Launch secure tunnel service
./start-service.sh

Configuration options, token setup, and tunnel routing instructions are documented in the README on GitHub.

Next project in Lab

CanAI for WordPress

A WordPress plugin for authoring templates with Twig 3 and Tailwind CSS via MCP.

View project