Authenticated WebSockets fail only on one route family behind Cloudflare Tunnel.
A Cloudflare Access tunnel looks authenticated and still fails WebSockets because one edge path downgrades to HTTP/1.1 without preserving the upgrade chain
The session authenticates, but the downgrade path strips the headers needed for WebSocket continuation.
Scenario
What to check first
- Identify the primary failure signal in the The Session Cleared Access and the Downgrade Path Quietly Took Away Its Upgrade Papers scenario.
- Separate visible symptoms from the underlying technical dependency.
- Describe the safest recovery path and the follow-up prevention work.
Checking checklist
- Summarize the current impact and the last known change.
- Collect direct evidence from logs, runtime state, and configuration before changing anything.
- Separate immediate recovery from permanent prevention work.
Recovery and prevention
Compare protocol downgrade behavior and upgrade header preservation before changing origin timeouts.
Questions worth viewing together
No. Keep commands, logs, file names, APIs, and product names unchanged, then explain the reasoning in the selected UI language.
State the root cause, the evidence that supports it, and the safest recovery direction.
The source scenario is treated as an incident artifact. Guidance, checklist, hints, and explanations can be localized around it.
Similar cases seen in the field