Network · Cloudflare Spectrum
Query a private database through Spectrum
Cloudflare Spectrum is a Layer 4 reverse proxy for any TCP or UDP service. Here it fronts a PostgreSQL server that lives on a private GCP VM with no public inbound port — yet you can run live queries against it below, all proxied through Cloudflare and tunneled to the origin.
Understand the path
Three slides on Spectrum, followed by a live PostgreSQL example.
Protect any TCP or UDP application
Spectrum places Cloudflare's global network in front of any TCP or UDP service. Clients connect to a Cloudflare anycast endpoint, and Spectrum proxies the native protocol to the origin you configure.
Anycast edge accepts the connection close to the client.
Edge protection filters attacks before they reach the origin.
Clients
Any native application
Spectrum
Anycast TCP / UDP proxy
Origin
Any TCP or UDP service
One public endpoint · native protocol preserved · origin shielded
Live query
Run SQL against the private origin
Run live read-only queries against a private PostgreSQL database. Each query travels from this site, through Cloudflare's network, over a Cloudflare Tunnel, to an origin with no public port — and back with the results.
Predefined queries
A plain SELECT over the demo table. These rows travel the full path: client → Spectrum edge → Cloudflare Tunnel → private origin, and back.
SELECT id, name, colo, note FROM regions ORDER BY id;Connect it yourself
Same endpoint, any Postgres client
Because Spectrum passes the wire protocol through untouched, the endpoint behaves like an ordinary Postgres server. Point psql — or any driver — at the public hostname.
psql "host=db.orangemoussa.net port=5432 dbname=spectrumdemo user=demo sslmode=require"TLS is negotiated with the database itself, so sslmode=require encrypts the session end-to-end. Credentials for the read-only role live in a password manager.