Cloudflare SSL on a VPS: A Practical Setup Without the Gotchas

Illustrated infographic summarizing: Cloudflare SSL on a VPS: A Practical Setup Without the Gotchas

By Greg Nowak. Updated 19 September 2026.

Putting a VPS behind Cloudflare creates two encrypted connections: one from the visitor to Cloudflare and another from Cloudflare to your origin server. The browser padlock confirms the first connection. It does not prove that the VPS presents the right certificate, that attackers cannot bypass Cloudflare, or that the setup will survive a future DNS change.

For a business site, the objective is bigger than “enable SSL.” You need a configuration that protects the full route, behaves predictably during incidents, and can be maintained by the next developer or agency.

Start with the operating model, not the certificate

For a production VPS you control, Full (strict) should normally be the target Cloudflare encryption mode. Cloudflare then encrypts its connection to the origin and verifies that the origin certificate is unexpired, matches the requested hostname, and was issued by a publicly trusted authority or Cloudflare Origin CA.

Avoid using Flexible as the finished design. It leaves the Cloudflare-to-origin connection on HTTP and can create a redirect loop when Nginx or the application insists on HTTPS.

Operating requirement Best fit at the VPS Operational consequence
Every public request remains proxied Cloudflare Origin CA certificate Simple, but browsers will not trust the certificate when connecting directly to the origin.
Monitoring or a vendor connects directly Publicly trusted certificate Direct HTTPS can work when routing and hostname validation are correct.
The proxy may be paused during an incident Publicly trusted certificate A planned DNS-only fallback will not introduce a certificate warning.
Requests must never bypass Cloudflare Either certificate plus origin access controls A valid certificate alone does not restrict who can reach the VPS.
Choose the origin certificate from the way the service must operate, including its recovery scenarios.

Install and test the Nginx configuration

Before changing Cloudflare’s encryption mode, confirm that every required hostname—usually the apex domain and www—exists in Cloudflare DNS and is proxied. Create a certificate covering those exact names, then store its private key outside the web root with restricted permissions. Never put the key in source control, a ticket, or a general handover document.

A minimal Nginx HTTPS server block might look like this:

server {
    listen 443 ssl;
    server_name example.com www.example.com;

    ssl_certificate     /etc/ssl/cloudflare/origin.pem;
    ssl_certificate_key /etc/ssl/private/cloudflare-origin.key;

    root /var/www/example/public;
    index index.html index.php;
}

Add the directives required by the application, then validate the complete configuration before reloading it:

sudo nginx -t
sudo systemctl reload nginx

Only after the origin works over HTTPS should you select Full (strict) in Cloudflare. Switching too early can produce a 526 response because Cloudflare cannot validate the origin certificate.

When is a public certificate the better choice?

Cloudflare Origin CA certificates are designed for traffic between Cloudflare and the VPS. If someone pauses Cloudflare or changes a DNS record to DNS-only, a normal browser connecting directly will report that certificate as untrusted. Cloudflare also says it does not send expiry notifications for Origin CA certificates, so record the expiry in your own monitoring or asset register.

If direct access is an intentional recovery path—or is required by monitoring, partners, or other infrastructure—use a publicly trusted certificate and verify automated renewal. With a supported Certbot installation, these commands remain useful:

sudo certbot --nginx
sudo certbot renew --dry-run

Follow the current Certbot instructions for the VPS operating system rather than copying an old package-installation command. The ACME HTTP-01 challenge needs inbound port 80 and cannot issue wildcard certificates. DNS-01 supports wildcards and works when the web server is not publicly reachable, but its DNS API credentials should have the narrowest practical permissions.

Give redirects one clear owner

Cloudflare, Nginx, and the application can all redirect HTTP to HTTPS or select a canonical hostname. Assign each redirect responsibility deliberately and document it. For a straightforward site, Cloudflare’s Always Use HTTPS can perform the scheme redirect at the edge. If Nginx or the application owns that redirect, remove overlapping rules and test every hostname to avoid loops and unnecessary hops.

A redirect does not fix mixed content. Search templates, stored content, CSS, scripts, fonts, images, and embeds for old http:// URLs. Then test forms, login, checkout, admin pages, APIs, webhooks, and OAuth callbacks—not merely the homepage.

Protect the origin as a separate task

Full (strict) validates the certificate presented by the VPS; it does not stop someone who knows the server IP from sending requests directly. That could let them bypass Cloudflare’s firewall, rate limiting, and other controls.

Options include allowing only Cloudflare’s current IP ranges at the firewall, using Authenticated Origin Pulls, or adopting Cloudflare Tunnel. Authenticated Origin Pulls adds client-certificate authentication, although Cloudflare’s global certificate only proves that a request came from its network; zone-level or hostname-level certificates provide stronger separation.

Before blocking traffic, inventory monitoring systems, deployment services, health checks, and vendor integrations that legitimately connect to the origin. Roll out the restriction in stages, preserve separate administrative access, and keep a tested recovery path. Cloudflare IP ranges can change, so their maintenance needs an owner too.

Test the service and leave a usable handover

Check HTTP-to-HTTPS behaviour, the apex and www hostnames, certificate coverage, application flows, scheduled jobs, callbacks, and monitoring. Review Nginx and application logs for errors that a visual browser check will miss.

The handover should record the Cloudflare encryption mode, certificate type and expiry, covered hostnames, renewal owner, redirect owner, DNS proxy status, origin restrictions, external dependencies, and rollback steps. That short record turns a working configuration into an operable service.

If your Cloudflare and VPS setup has accumulated certificates, redirects, and firewall rules through several migrations, Greg can review the entire request path and leave your team with a clearer, testable operating model. Get in touch with Greg for a practical review.

Related on GrN.dk

Related on GrN.dk

Need help with this kind of work?

Ask Greg to review your Cloudflare and VPS setup Get in touch with Greg.

Sources

Latest articles

When checkout fails, your operations provider needs concrete evidence to work with. See how AI, dmesg and journalctl can gather the evidence into a useful incident ticket.

OpenAI’s hosted Evals platform is closing. Preserve your tests, validate replacement scoring and keep releases covered before the October and November 2026 deadlines.

Decide which AI-assisted pages to keep, improve, combine or remove. Check claims, page overlap and metadata, then put clear review controls into your CMS.

Use October to trial daily AI reorder recommendations before Black Friday. Get your Shopify data, lead times and budget in order before turning recommendations into purchases.

When an OpenAI request stalls, customers need an accurate status. Set sensible retry limits, preserve submissions, and make unresolved work visible.

I learned server operations by breaking my own servers. I want someone who stands next to me while I do it, then does it themselves the week after.

I am good at building and bad at calling. Here is who I want next to me, what is easiest to sell, and how we split it.

An AI assistant can prepare a refund, but a person should approve the exact payment and amount. Here is how to make that approval hold up through execution and retries.

AI can pull together onboarding tasks before a new hire’s first day. See how the manager approves specific access and how outstanding tasks are followed through.

An internal AI assistant can cite an obsolete handbook with confidence. Here is how to manage document ownership, updates, deletions, access and answer review.