# Cloudflare Mesh
Mesh is [[Cloudflare]]'s private networking product: every enrolled server, laptop and phone gets a private IP (a "Mesh IP", from `100.96.0.0/12`) and can reach every other participant over TCP, UDP or ICMP. Think [[Tailscale]], except the traffic always goes through Cloudflare's network instead of directly between devices. Cloudflare announced it on April 14, 2026, during Agents Week. It's in beta and available to every Cloudflare One account, Free plan included.
It's a rename plus a new experience more than a brand-new technology. WARP Connector became the "Mesh node", the WARP client became the Cloudflare One Client, and the old peer-to-peer connectivity became "Mesh connectivity". Existing deployments kept working without migration, and the node limit went from 10 to 50 per account.
## How it works
Two kinds of participants:
- **Mesh nodes**: Linux servers, VMs or containers running the Cloudflare One Client (`warp-cli`) headless. They can advertise CIDR routes (IPv4 and, since May, IPv6) and hostname routes to make whole subnets reachable, and they support active-passive high availability replicas
- **Client devices**: laptops, phones and desktops running the Cloudflare One Client with a UI. They reach nodes and each other by Mesh IP; client-to-client works without deploying any node
Everything is managed from the dashboard (Networking > Mesh) or the API: network map, routes, diagnostics, a setup wizard. Nodes must use the MASQUE tunnel protocol (the default); with [[WireGuard]], hostname routes, IPv6 routes and high availability don't work. Traffic is post-quantum encrypted.
Because every packet passes through Cloudflare, the rest of Cloudflare One applies automatically: Gateway network/DNS/HTTP policies, device posture checks, DLP, and Access for Infrastructure for SSH and RDP sessions. See [[Cloudflare Access and Zero Trust]].
## Why agents are the angle
Cloudflare sells Mesh as private networking for [[AI Agents]], with three scenarios:
- Reach a personal agent running on a home machine ([[OpenClaw]] on a Mac mini in their example) from your phone, without exposing it to the Internet
- Let a local coding agent ([[Claude Code]], Cursor, Codex) query a staging database or internal API in a private VPC
- Let agents deployed on [[Cloudflare Workers]] reach private services
That last one goes through Workers VPC: a VPC Network binding with `network_id: "cf1:network"` exposes your whole Mesh to a Worker, a [[Cloudflare Durable Objects|Durable Object]] or an [[Cloudflare Agents SDK]] agent through a single `fetch()`. Since June 2026, the same binding also sends Worker egress to the public Internet through Gateway, so your existing policies and logs cover what your Workers call.
## Mesh vs Tunnel
The question everyone asks. [[Cloudflare Tunnel]] (`cloudflared`) is outbound-only and unidirectional: it publishes specific apps, hostnames or IP ranges to clients. Mesh (`warp-cli`) is bidirectional and many-to-many: every participant has an address and anything can initiate a connection. Mesh works at L3/L4 and keeps long-lived TCP connections intact (database replication, RDP, ERP systems). Tunnel proxies HTTP/S, TCP, SSH, RDP and SMB over WebSocket.
Rule of thumb: Tunnel to publish a service, Mesh to put machines on the same private network.
## Mesh vs Tailscale
The docs ship a mapping table for people coming from Tailscale or plain WireGuard: tailnet = your account's Mesh, subnet router = node with CIDR routes, ACLs = Gateway network policies plus device posture, exit node = a node with a public CIDR attached, MagicDNS = Local Domain Fallback plus Gateway resolver policies.
The key difference is the routing model. Tailscale tries direct peer-to-peer connections and falls back to relays when NAT traversal fails. Mesh never goes direct: everything goes through the nearest Cloudflare data center (330+ cities). Cloudflare frames that as a feature (no degraded relay path, inspection on every packet). It also means Cloudflare sees and can filter all your private traffic, which is the point if you want a SASE, and a drawback if you don't.
## What shipped since launch
- **May**: IPv6 CIDR routes; high availability replica management in the dashboard, with manual failover; granular permissions for Tunnel and Mesh
- **July 2**: hostname routes (route `wiki.internal.local` to a node without running a DNS server; a hosts-file entry on the node is enough). Hostname routing went GA on August 11
- **August 7**: the `cloudflare/mesh` container image (amd64 and arm64) for [[Docker]] Compose, [[Kubernetes]] (StatefulSet or sidecar) and [[Continuous Integration (CI)|CI]] runners that join the Mesh, run integration tests against private infrastructure and disappear
- **September**: bulk route creation, guided onboarding for participants, and Mesh replicas identified in network logs
Still announced but not shipped as far as I can tell: Mesh DNS (automatic `<node>.mesh` hostnames) and identity-aware routing, where each agent carries its own identity (human sponsor, agent, scope) that Gateway policies can evaluate.
## Pricing
Free for up to 50 nodes and 50 users on every Cloudflare account. Above that, you're in Cloudflare One (Zero Trust) paid-plan territory; I found no separate Mesh price list.
## My take
For a developer, the free tier is generous, and the Workers VPC binding is the genuinely new part: no other mesh VPN lets serverless code join your private network with one line of config. Agents reaching private resources through a network you can log and filter is a sane default too. The trade-off is clear though: all traffic hairpins through Cloudflare, and you're buying into the Cloudflare One stack. If you only want two machines to talk, Tailscale or plain WireGuard stay simpler.
## References
- [Secure private networking for everyone: users, nodes, agents, Workers, introducing Cloudflare Mesh](https://blog.cloudflare.com/mesh/) (Cloudflare blog, 2026-04-14)
- Mesh documentation: https://developers.cloudflare.com/mesh/
- How Cloudflare Mesh works (Mesh vs Tunnel, Tailscale mapping): https://developers.cloudflare.com/mesh/concepts/
- Platform and availability: https://developers.cloudflare.com/mesh/platform/
- Mesh in Cloudflare One docs: https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-mesh/
- Changelog, Introducing Cloudflare Mesh (2026-04-14): https://developers.cloudflare.com/changelog/post/2026-04-14-cloudflare-mesh/
- Changelog, VPC Networks and Mesh support in Workers VPC (2026-04-14): https://developers.cloudflare.com/changelog/post/2026-04-14-vpc-networks/
- Changelog, IPv6 CIDR routes (2026-05-06): https://developers.cloudflare.com/changelog/post/2026-05-06-mesh-ipv6-routes/
- Changelog, high availability replica management (2026-05-28): https://developers.cloudflare.com/changelog/post/2026-05-28-mesh-ha-replica-ui/
- Changelog, Worker egress through Gateway (2026-06-05): https://developers.cloudflare.com/changelog/post/2026-06-05-gateway-egress/
- Changelog, hostname routing for Mesh (2026-07-02): https://developers.cloudflare.com/changelog/post/2026-07-02-mesh-hostname-routing/
- Changelog, container image for Mesh (2026-08-07): https://developers.cloudflare.com/changelog/post/2026-08-07-mesh-container-image/
- Changelog, hostname routing GA (2026-08-11): https://developers.cloudflare.com/changelog/post/2026-08-11-hostname-routing-ga-public-initial-resolved-ips/
- Changelog, guided participant onboarding (2026-09-23): https://developers.cloudflare.com/changelog/post/2026-09-23-mesh-participant-onboarding/
- Hacker News discussion: https://news.ycombinator.com/item?id=47765623
## Related
- [[Cloudflare]]
- [[Cloudflare Tunnel]]
- [[Cloudflare Access and Zero Trust]]
- [[Cloudflare Workers]]
- [[Cloudflare Agents SDK]]
- [[Tailscale]]
- [[WireGuard]]
- [[Virtual Private Network (VPN)]]
- [[AI Agents]]