Cloudflare Tunnel starts from Cloudflare's edge. It is a strong choice when a private HTTP origin should inherit Cloudflare's CDN, WAF, DDoS protection, Access policies, and Zero Trust network controls. Cloudflare One and Mesh also provide a mature model for identity-aware Layer 3 connectivity between users, devices, and private networks.
rstream starts from the connection an application needs. The same runtime publishes HTTP, TCP, TLS, QUIC, and DTLS endpoints, and lets CLI or SDK clients dial private bytestream and datagram tunnels. Public TCP works with standard clients rather than a matching connector. WebTTY, live client and tunnel state, and separate local and hosted MCP surfaces connect those transports to real-time media, private AI systems, remote operations, and AI tools.
Cloudflare operates its edge and control plane while customers operate cloudflared connectors. rstream is developed in Europe and offers global hosted, dedicated, and on-premises paths, together with the free self-hosted Engine CE core runtime. Cloudflare remains the clearer fit for a comprehensive web edge or managed Zero Trust network. rstream is a stronger fit when the system needs application-facing protocols, private SDK access, remote operations, AI tooling, or control over the runtime deployment.