nx1x/Cloudflare WARP Setup

Headless Cloudflare WARP enrollment for GitHub Actions runners. Full network access via your Zero Trust org.

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Stale
License
None
namedescriptionrequireddefault
organizationCloudflare Zero Trust organization/team name (the subdomain in https://<team>.cloudflareaccess.com)yes
auth-client-idCloudflare Access service token Client ID (used for headless device enrollment)yes
auth-client-secretCloudflare Access service token Client Secret (used for headless device enrollment)yes
modeWARP connection mode: "warp" (full tunnel), "proxy" (local SOCKS5/HTTP proxy), "doh" (DNS-only), or "warp+doh"nowarp
exclude-routesCIDR ranges to exclude from the WARP tunnel (split-tunnel exclude mode, one per line). Example: "192.168.0.0/16"no""
include-routesCIDR ranges to include in the WARP tunnel (split-tunnel include-only mode, one per line). When set, ONLY these ranges are routed through WARP.no""
test-connectionVerify WARP is connected after setupnotrue
test-hostInternal hostname or IP to ping for connection verification (optional, only used when test-connection is true)no""
retry-countNumber of attempts when waiting for connection / pinging the test hostno3
retry-delaySeconds to wait between retry attemptsno5
namedescription
warp-versionInstalled cloudflare-warp client version (e.g. "2024.6.415")
connection-statusFinal WARP connection status: "connected", "failed", or "skipped"
warp-ipThe runner's WARP tunnel IPv4 address on the CloudflareWARP interface (empty if interface unavailable)