Cloudflared Windows Service Fix

Last occurrence: 2026-03-04 Has happened before: Yes — recurring issue

Symptom

The cloudflared Windows service crash-loops:

  • Service Control Manager logs: “The Cloudflared agent service terminated unexpectedly” every ~20 seconds
  • Application event log only shows “Cloudflared service starting” — no errors
  • Running cloudflared tunnel run manually (or as SYSTEM via scheduled task) works perfectly
  • cloudflared tunnel ingress validate passes

Root Cause

cloudflared service install registers the service ImagePath as the bare executable with no arguments:

C:\ProgramData\chocolatey\lib\cloudflared\tools\cloudflared.exe

The binary is supposed to auto-detect that it's running as a Windows service and internally invoke tunnel run. This auto-detection is broken (at least in version 2025.10.0 installed via Chocolatey). The process starts, logs “service starting”, then exits immediately.

Fix

Set the service ImagePath to explicitly include the tunnel run arguments:

$regPath = "HKLM:\SYSTEM\CurrentControlSet\Services\cloudflared"
$newPath = '"C:\ProgramData\chocolatey\lib\cloudflared\tools\cloudflared.exe" tunnel --config "C:\Windows\System32\config\systemprofile\.cloudflared\config.yml" run'
Set-ItemProperty -Path $regPath -Name "ImagePath" -Value $newPath
Start-Service cloudflared

Must be run as Administrator.

Verify

Get-Service cloudflared | Select-Object Status, StartType
# Should show: Running / Automatic

Warning

Running cloudflared service install (or updating via Chocolatey) will likely reset ImagePath back to the bare executable, requiring this fix again. Check after any cloudflared update.

Config Location

  • Service config: C:\Windows\System32\config\systemprofile\.cloudflared\config.yml
  • Credentials: C:\Windows\System32\config\systemprofile\.cloudflared\<tunnel-uuid>.json
  • Repo copy: tela\docker\cloudflared-config.yml (keep in sync manually)