The topic you've found discusses ufw rules that are more restrictive than the recommended settings from our guide.
Pi-hole is intended to run on your local network, behind a router's firewall.
In such a scenario, both sets of rules should be applicable - provided that your network range or ranges would match the ones from the discussed rules.
Any firewall requirements specific to your DoH software should be gathered from the documentation for that software.
I can't find anything related to firewalls, except this:
Cloudflare attracts client requests and sends them to you via this daemon, without requiring you to poke holes on your firewall --- your origin can remain as closed as possible.
If I understand correctly, English it's not my language, there is no need to allow any specific port/rule for Cloudfare tunnel. Am I right?