This seems to work, but only partially. for example:
the following command incus ls works without issues but incus start ct responds with Error: Failed to fetch https://incus.example.xyz:443/1.0/events: 502 Bad Gateway although the operation seems actually go through still so in this case the container would be started.
So the way I got it working for me was by forcing the cloudflared daemon to use the quic protocol instead of http2. Also, I haven’t tested this but it doesn’t hurt to enable Websockets under Websites → <domain> → Network: