Why Every Request Looks Like It Came from Cloudflare Instead of the User
Original client IP is trustworthy only when Caddy knows which proxy was allowed to write it.
Original client IP is trustworthy only when Caddy knows which proxy was allowed to write it.
A service can be healthy on the LAN and unreachable through Cloudflare, TLS, DNS or authentication at the public edge.
The same hostname can resolve to a local reverse proxy on LAN and a Cloudflare Tunnel externally. That is clean when DNS, SNI, certificates, and origin routing agree—and maddening when one layer quietly takes the other path.
A public request can fail before reaching Authelia, inside the authentication flow, or after authentication while the upstream application is unavailable.
A lost counter, duplicate job, stale read, or runaway write bill is usually not 'a Cloudflare bug.' Each storage primitive makes different consistency and delivery promises, so the same application pattern fails differently on each one.