Forever URL · Cloudflare Named Tunnel · Multi-agent night
The Night DNS Pointed at a Dead Tunnel
Five bots, one sleeping founder, and a forever URL that looked “almost done” until Error 1033 proved the hostname was shaking hands with a corpse.
José wanted sleep. The arcade was locked for Complete. The forever URL —
https://play.sinmuela.org on domain
sinmuela.org — was supposed to be the one chip he could hand a friend
without explaining Cursor VMs. Instead: five agents arguing over the same
Cloudflare dashboard he was tired of babysitting, a connector that glowed
Healthy while the public edge returned 1033, and a false 503 fire drill that
blamed a live origin. This is that movie — witty where it can be, fair where
it must, and short enough to read before the coffee cools.
Timeline · UTC evening 2026-09-21
-
~05:16Z
Cursor blasts browser bots: put Public Hostname on Healthy tunnel
play.sinmuela.org(d6400ae3-fc64-4250-92f8-9eb82562b7a9). Connector Healthy on Cursor VM; origin:8000up (302). Public still 1033 / 530. -
~05:19–21Z
Overnight standing orders while José sleeps. PUBLIC_ORIGIN SSOT,
beta thermometer, war-room reenact ship. Labels reinforced:
CONNECTOR_OK/PUBLIC_HOSTNAME_MISSING/HTTP 1033. Healthy ≠ live URL. -
~05:22–25Z
Opción 1 killed. Windows Add-connector + paste
eyJh…token into chat = FORBIDDEN. José had been steered intocloudflared.exeinstall. Truth: origin already on Cursor VM. -
~05:35–37Z
Founder sleep / no more CF babysitting. Mandatory Cloudflare training
page + quiz land. Bot path: API token in env →
cf_add_public_hostname.py. -
~05:43Z
Claude-in-Chrome fixes DNS: Content had pointed
playat Inactive tunnel named likesinmuela.org, not the Healthy Cursor tunnel. After DNS fix → public 503. - ~05:45Z Cursor correction: origin still 302; cloudflared log “No ingress rules… return 503.” Bots had misdiagnosed origin-down. Last blocker = Public Hostname / ingress.
-
~05:54–56Z
Claude finishes the route. LIVE:
https://play.sinmuela.org→ 302 Arcade loading. Thin postmortem folded into training / url-fijo. Crew told: read before more CF advice.
What Went Wrong
-
Two Cloudflare switches mistaken for one
Connector Healthy was celebrated as “tunnel fixed” while the forever URL still
returned Error 1033. Healthy means the pipe is up — not that your hostname is wired.
Why it hurt: false green lights. José (and bots) stopped looking for the real missing click.
-
DNS Content → Inactive tunnel
play.sinmuela.orgTunnel/CNAME targeted Inactivesinmuela.orginstead of Healthyplay.sinmuela.org(d6400ae3-…). Symptom: 1033 — unbound / wrong tunnel — not propagation.Why it hurt: every “wait for DNS” theory burned sleep while CF already answered from the edge.
-
Opción 1 — Windows connector + token in chat
Guides put Add connector → Windows → paste
eyJh…first. That path was architecturally wrong tonight (origin on Cursor VM) and security-wrong always (connector tokens never belong in chat).Why it hurt: stuck José on an MSI install he didn’t need; nearly leaked a tunnel token into the bot web.
-
503 after DNS fix → “origin down” false lead
cloudflared had no ingress rules. Local
:8000was fine (302). Several bots told Cursor to restartserver.pyanyway.Why it hurt: chased the wrong layer; delayed the one Chrome click that mattered.
-
Quota cliff mid-truth
Codex / ChatGPT hit a usage limit (~5:02 AM reset window) while correctly saying
“not propagation.”
Why it hurt: the alarm that was right went dark; louder wrong advice filled the gap.
-
Expectation that Cursor cloud can click José’s CF UI
Cloud agents own the VM connector and origin. They cannot drive a personal Zero Trust
dashboard without an API token or a browser bot on José’s machine.
Why it hurt: five agents “helping” while zero could finish the last hop — until Claude-in-Chrome could.
What Went Right
-
Claude-in-Chrome closed the forever URL
Found the Inactive DNS binding, retargeted Healthy tunnel UUID, finished Public Hostname /
ingress → LIVE 302 / Arcade loading.
Why it mattered: the only agent who could click the dashboard that night — and did.
-
Cursor kept the boring half alive
Connector Healthy, origin up, refused the Windows-token path, shipped CF training,
PUBLIC_ORIGIN SSOT,
cf_add_public_hostname.py, crew-effort, beta goal, ALCOA+.Why it mattered: when the route finally landed, something real was listening on
:8000. -
José’s screenshots and endurance
Ground-truth UI state beat bot folklore. Founder still got sleep after the kill order on babysitting.
Why it mattered: evidence over vibes — the ALCOA+ lesson before the doc existed.
-
Codex’s early alarm
Named the trap (not propagation / missing public route) before the thrash peaked.
Why it mattered: left a trail other bots could follow once the quota cliff passed.
-
Training + SSOT shipped mid-incident
The night produced durable tools: quiz before advice, forever domain in one JSON,
hostname bot script, ALCOA+ layer accuracy.
Why it mattered: next 1033 is a five-minute quiz, not another movie.
Who Did What
eyJh… in chat — called out as forbidden architecture, not a character flaw. Guides that put Windows first led the founder astray; we bury that path now.
Lessons / Next Time
- ALCOA+ layer accuracy. Name the layer: CONNECTOR_OK vs PUBLIC_HOSTNAME_MISSING vs ORIGIN_DOWN. Accurate beats “looks Healthy.”
- PUBLIC_ORIGIN is SSOT. Cite
forever_urlfrom JSON //api/public-originonly — never hardcode sibling domains. - Pass CF training before advice. Quiz + ACK. Page: /cloudflare-training.
- Hostname bot, not token chat.
CLOUDFLARE_API_TOKENin env →python tools/cf_add_public_hostname.py. Never pasteeyJh…. - Healthy ≠ live. Verify with
curl -sI https://play.sinmuela.org/(want 302), not the connector badge alone. - 503 + local 302 = no ingress. Do not restart a living origin to fix a missing Public Hostname.
- 1033 is not propagation. CF already answered; fix DNS/route binding to the live tunnel UUID.
d6400ae3-… · origin HTTP localhost:8000