Application Access

Make web applications private without changing the application stack

Choose ordinary public delivery, identity-protected publishing, or private-network access when you create an app, and let Wodby manage the connection throughout its lifecycle.

Internal dashboards, CMS installations, preview environments, customer portals, and agent gateways still need stable HTTPS addresses. Application Access gives them a managed connection path through Cloudflare or Tailscale without requiring each stack or application to implement private networking itself.

Protect the entire app or only selected HTTP endpoints
Choose Cloudflare Access, Cloudflare One, or Tailscale
Keep endpoint reconciliation and provider cleanup in the app lifecycle

Choose the experience users should have

Application Access starts with the product outcome, not tunnel configuration.

Public

Use Wodby’s ordinary public routing when the app should be available to everyone on the internet.

Identity protected

Publish through Cloudflare and require an approved identity policy before a browser can reach the app.

Private network

Keep endpoints reachable only from enrolled Cloudflare One devices or authorized Tailscale users and devices.

Public remains the default. Select Protected during app creation or from the app instance settings when Cloudflare or Tailscale should become the connection path.

Protect the complete app or only the endpoints that need it

A private application does not have to mean an all-or-nothing network decision.

Entire app

Move every eligible external HTTP endpoint behind the selected access provider and suppress matching ordinary public routes.

Selected endpoints

Keep the main website public while protecting an admin interface, preview service, dashboard, or operational tool.

  • Choose the primary protected endpoint users should open first.
  • Give each protected service a stable address appropriate to the provider.
  • Leave unselected routes operating normally when only part of the app should be protected.

Use the access provider that matches your organization

Cloudflare and Tailscale fit the same app-level workflow while providing different user experiences.

Cloudflare

Use protected publishing with a Cloudflare Access identity policy, or keep endpoints inside a Cloudflare One private network for enrolled devices.

Tailscale

Give authorized users and devices stable private HTTPS addresses inside an existing tailnet.

Review the Cloudflare integration or Tailscale integration before choosing a provider. Tailscale Node remains a separate use case for stacks where the network node itself is the workload being deployed.

Turn ordinary web stacks into internal applications

The same stack can serve a public website in one app and a private business workflow in another.

Internal CMS and portals

Deploy Drupal or WordPress for an intranet, knowledge base, operations portal, or private publishing workflow.

Admin and preview tools

Protect staging sites, customer previews, dashboards, and supporting interfaces without adding authentication to each app.

Private gateways

Keep OpenClaw and other operator-facing gateways available to approved users without publishing an ordinary public route.

Keep access attached to the app lifecycle

The protected path should change when the application changes.

  • Suppress matching public routes from the beginning when an app is intended to be protected.
  • Reconcile provider endpoints when eligible app services and routes change.
  • Restore ordinary public routing when Application Access is removed.
  • Clean up Wodby-managed connector and provider resources when the app is deleted.

Access work is visible in the app instance state and task history, so teams can follow provisioning, reconciliation, failures, and cleanup from the same operational surface as the app itself.

Use the right access control for the right boundary

Application Access, platform permissions, and route authentication solve different problems.

Application Access

Controls who can reach the running HTTP application through Cloudflare or Tailscale.

Platform access control

Controls who can view and operate Wodby projects, apps, clusters, stacks, and integrations.

Routes and ports

Controls ordinary public HTTP routing, Basic Auth, custom domains, and published TCP or UDP ports.

Application Access protects eligible HTTP endpoints. It does not automatically publish databases or arbitrary TCP and UDP services.

Next step

Give every app the access model it actually needs

Start public, protect the complete app, or move only selected HTTP endpoints behind Cloudflare or Tailscale from the same app creation workflow.