cloudflare / cloudflare/cloudflared

🐛 Cloudflared metrics return 1 HA connection when there are none.

Open
#1,633 0 comments 0 reactions 0 assignees View on GitHub
Priority: Normal Type: Bug
Dominant language
Go
Stars
15.6k
Forks
1.4k
PR merge metrics
No merged PRs in 30d

Description

**Describe the bug**

The `cloudflared` metrics endpoint (`/metrics`) reports `cloudflared_tunnel_ha_connections 1` even though no QUIC connections to the Cloudflare edge have been successfully established. All connection attempts are failing with `timeout: no recent network activity`, yet the `cloudflared_tunnel_ha_connections` gauge incorrectly shows 1 active HA connection instead of 0.

---

**To Reproduce**

Steps to reproduce the behavior:

1. Configure a Cloudflare Tunnel using a tunnel token (remotely managed) with metrics enabled on `0.0.0.0:7013`
2. Start `cloudflared` in an environment where QUIC connections to the Cloudflare edge time out (e.g., firewall blocking UDP to Cloudflare edge IPs)
3. Observe repeated `ERR Failed to dial a quic connection` errors in the logs — no connection is ever successfully established
4. Query the metrics endpoint at `http://:7013/metrics`
5. Observe that `cloudflared_tunnel_ha_connections` reports `1` despite zero successful connections

---

**Expected behavior**

When all QUIC connection attempts to the Cloudflare edge fail and no tunnel connections are active, the metric `cloudflared_tunnel_ha_connections` should report `0`, not `1`. The gauge should only increment once a connection is successfully established, and should accurately reflect the number of *active* HA connections at any given time.

---

**Environment and versions**

| Field | Value |
| ------------ | ------------------------------------------------------------------------- |
| OS | Docker container deployment on Debian 12 |
| Architecture | AMD64 |
| Version | 2026.3.0 |
| Protocol | QUIC |

---

**Additional context**

This machine would have had access to port cloudflare services on 80:443, but not the additional ports used, e..g 7844

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.