Cloudflare SSL on a VPS: A Practical Setup Without the Gotchas

Illustrated infographic summarizing: Cloudflare SSL on a VPS: A Practical Setup Without the Gotchas

By Greg Nowak. Updated 19 September 2026.

Putting a VPS behind Cloudflare creates two encrypted connections: one from the visitor to Cloudflare and another from Cloudflare to your origin server. The browser padlock confirms the first connection. It does not prove that the VPS presents the right certificate, that attackers cannot bypass Cloudflare, or that the setup will survive a future DNS change.

For a business site, the objective is bigger than “enable SSL.” You need a configuration that protects the full route, behaves predictably during incidents, and can be maintained by the next developer or agency.

Start with the operating model, not the certificate

For a production VPS you control, Full (strict) should normally be the target Cloudflare encryption mode. Cloudflare then encrypts its connection to the origin and verifies that the origin certificate is unexpired, matches the requested hostname, and was issued by a publicly trusted authority or Cloudflare Origin CA.

Avoid using Flexible as the finished design. It leaves the Cloudflare-to-origin connection on HTTP and can create a redirect loop when Nginx or the application insists on HTTPS.

Operating requirement Best fit at the VPS Operational consequence
Every public request remains proxied Cloudflare Origin CA certificate Simple, but browsers will not trust the certificate when connecting directly to the origin.
Monitoring or a vendor connects directly Publicly trusted certificate Direct HTTPS can work when routing and hostname validation are correct.
The proxy may be paused during an incident Publicly trusted certificate A planned DNS-only fallback will not introduce a certificate warning.
Requests must never bypass Cloudflare Either certificate plus origin access controls A valid certificate alone does not restrict who can reach the VPS.
Choose the origin certificate from the way the service must operate, including its recovery scenarios.

Install and test the Nginx configuration

Before changing Cloudflare’s encryption mode, confirm that every required hostname—usually the apex domain and www—exists in Cloudflare DNS and is proxied. Create a certificate covering those exact names, then store its private key outside the web root with restricted permissions. Never put the key in source control, a ticket, or a general handover document.

A minimal Nginx HTTPS server block might look like this:

server {
    listen 443 ssl;
    server_name example.com www.example.com;

    ssl_certificate     /etc/ssl/cloudflare/origin.pem;
    ssl_certificate_key /etc/ssl/private/cloudflare-origin.key;

    root /var/www/example/public;
    index index.html index.php;
}

Add the directives required by the application, then validate the complete configuration before reloading it:

sudo nginx -t
sudo systemctl reload nginx

Only after the origin works over HTTPS should you select Full (strict) in Cloudflare. Switching too early can produce a 526 response because Cloudflare cannot validate the origin certificate.

When is a public certificate the better choice?

Cloudflare Origin CA certificates are designed for traffic between Cloudflare and the VPS. If someone pauses Cloudflare or changes a DNS record to DNS-only, a normal browser connecting directly will report that certificate as untrusted. Cloudflare also says it does not send expiry notifications for Origin CA certificates, so record the expiry in your own monitoring or asset register.

If direct access is an intentional recovery path—or is required by monitoring, partners, or other infrastructure—use a publicly trusted certificate and verify automated renewal. With a supported Certbot installation, these commands remain useful:

sudo certbot --nginx
sudo certbot renew --dry-run

Follow the current Certbot instructions for the VPS operating system rather than copying an old package-installation command. The ACME HTTP-01 challenge needs inbound port 80 and cannot issue wildcard certificates. DNS-01 supports wildcards and works when the web server is not publicly reachable, but its DNS API credentials should have the narrowest practical permissions.

Give redirects one clear owner

Cloudflare, Nginx, and the application can all redirect HTTP to HTTPS or select a canonical hostname. Assign each redirect responsibility deliberately and document it. For a straightforward site, Cloudflare’s Always Use HTTPS can perform the scheme redirect at the edge. If Nginx or the application owns that redirect, remove overlapping rules and test every hostname to avoid loops and unnecessary hops.

A redirect does not fix mixed content. Search templates, stored content, CSS, scripts, fonts, images, and embeds for old http:// URLs. Then test forms, login, checkout, admin pages, APIs, webhooks, and OAuth callbacks—not merely the homepage.

Protect the origin as a separate task

Full (strict) validates the certificate presented by the VPS; it does not stop someone who knows the server IP from sending requests directly. That could let them bypass Cloudflare’s firewall, rate limiting, and other controls.

Options include allowing only Cloudflare’s current IP ranges at the firewall, using Authenticated Origin Pulls, or adopting Cloudflare Tunnel. Authenticated Origin Pulls adds client-certificate authentication, although Cloudflare’s global certificate only proves that a request came from its network; zone-level or hostname-level certificates provide stronger separation.

Before blocking traffic, inventory monitoring systems, deployment services, health checks, and vendor integrations that legitimately connect to the origin. Roll out the restriction in stages, preserve separate administrative access, and keep a tested recovery path. Cloudflare IP ranges can change, so their maintenance needs an owner too.

Test the service and leave a usable handover

Check HTTP-to-HTTPS behaviour, the apex and www hostnames, certificate coverage, application flows, scheduled jobs, callbacks, and monitoring. Review Nginx and application logs for errors that a visual browser check will miss.

The handover should record the Cloudflare encryption mode, certificate type and expiry, covered hostnames, renewal owner, redirect owner, DNS proxy status, origin restrictions, external dependencies, and rollback steps. That short record turns a working configuration into an operable service.

If your Cloudflare and VPS setup has accumulated certificates, redirects, and firewall rules through several migrations, Greg can review the entire request path and leave your team with a clearer, testable operating model. Get in touch with Greg for a practical review.

Related on GrN.dk

Related on GrN.dk

Need help with this kind of work?

Ask Greg to review your Cloudflare and VPS setup Get in touch with Greg.

Sources

Seneste artikler

Når checkout fejler, skal driftspartneren have noget konkret at arbejde med. Se, hvordan AI, dmesg og journalctl kan samle sporene i en brugbar driftssag.

Brug oktober til at afprøve daglige AI-forslag til genbestilling før Black Friday. Få styr på Shopify-data, leveringstid og budget, før forslagene bliver til indkøb.

Jeg lærte serverdrift ved at ødelægge mine egne servere. Jeg søger en, der vil stå ved siden af mig, mens jeg gør det, og så gøre det selv ugen efter.

Jeg er god til at bygge og dårlig til at ringe. Her er, hvem jeg vil have ved siden af mig, hvad der er lettest at sælge, og hvordan vi deler det.

AI kan samle onboardingopgaverne før første arbejdsdag. Se, hvordan lederen godkender konkret adgang, og hvordan åbne opgaver bliver fulgt til dørs.

En AI-assistent kan svare på spørgsmål og føre kunder til booking. Her er de konkrete grænser for pris, levering, personoplysninger og kontakt med en medarbejder.

Et sikkert AI-workflow kan omsætte Meet- og Teams-transskripter til godkendte beslutninger og opgaver i Jira eller Asana – uden at slippe kontrollen.

AI kan finde opsigelsesfrister og prisreguleringer i leverandørkontrakter, sende usikre fund til godkendelse og oprette de rette påmindelser.

Sådan automatiserer danske virksomheder Gmail og Microsoft 365 med hurtig sortering, begrænsede rettigheder og menneskelig godkendelse.

Samme kunde på flere kort i HubSpot? Se, hvordan CVR-match, AI-forslag og menneskelig godkendelse kan bruges til at rydde op med styr på felter, relationer og kundehistorik.