Self-hosted HTTP tunnels with SSH and Nginx
First reported by Vincent.bernat.ch ·
You can create secure, temporary public URLs for local web services without relying on third-party tunneling providers.
Vincent Bernat details a method for creating self-hosted HTTP tunnels using OpenSSH and Nginx, bypassing commercial services like ngrok or Cloudflare. The approach involves establishing an SSH remote forward connection from a client to a server, directing traffic from a port on the server to a local service (e.g., localhost:8080). Nginx is then configured on the server to proxy incoming HTTPS requests on a wildcard domain (e.g., *.ssh.luffy.cx) to the locally forwarded port. Access control is enhanced using Nginx's `ngx_http_secure_link_module` to generate signed URLs with expiration times, preventing unauthorized access. Bernat provides a complete Nginx configuration and a helper script to automate the generation of these secure URLs by identifying the dynamically allocated SSH port. This setup allows users to expose local web services to the internet using only standard SSH and Nginx tools.
This solution leverages existing infrastructure, primarily OpenSSH and Nginx, to offer a self-hosted alternative to commercial tunneling services. By using SSH's remote port forwarding and Nginx's proxying capabilities, developers can expose local development environments or internal services to the internet for testing or collaboration. The integration of `ngx_http_secure_link_module` adds a crucial layer of security, allowing for time-limited access via cryptographically signed URLs, which mitigates the risks associated with exposing local services.
The article highlights a technical approach that appeals to users prioritizing control and cost-effectiveness over the convenience of managed services. The method's reliance on widely adopted open-source tools makes it accessible for individuals and organizations already managing their own servers. Future developments might focus on further simplifying the helper script or integrating this tunneling capability into broader development workflows, potentially reducing the need for specific client installations or complex server configurations for basic tunneling needs.
AI-written summary. May contain errors.