Self-hosted HTTP tunnels with SSH and Nginx

(vincent.bernat.ch)

53 points | by renehsz 2 hours ago

9 comments

  • toomim 1 hour ago
    For this stuff, I'm most excited about https over iroh.

    - https://github.com/aflin/iroh-webproxy

    - https://github.com/n0-computer/iroh-proxy-utils

    No port forwarding. No public IP required. No special proxy to set up.

    Iroh already runs public relays. Your two computers will signal through those, and then port-knock and form a direct connection to each other, perfectly encrypted.

    We just need to define a new https:// url, like ... let's call it "irohttps://" maybe, so then you could contact my laptop with "irohttps://<hash>/path?query".

    • Muromec 1 hour ago
      >and then port-knock and form a direct connection to each other, perfectly encrypted.

      so... ICE/TURN/STUN ? Sorry I forgot which one of them actually works, but they do work

  • aliasxneo 2 hours ago
    This is one of the core things I've been working towards with DNTLS [1]. I love the idea of tunnels, especially for sharing between private parties. The SaaS providers (Tailscale, Cloudflare, etc.) have done a good job making it really easy on their infra, but it really blurs the line of "self-hosted" to me. Ideally we end up with solutions like this that can be run entirely without an intermediary.

    [1]: https://dntls.substack.com/p/the-new-internet

    • gonzalohm 1 hour ago
      So like wireguard then?
      • aliasxneo 1 hour ago
        If that's all that was necessary then I feel like a lot of these SaaS tools wouldn't be as popular. I suspect a lot of Tailscale's success is because wireguard is not easy nor does it solve the full problem space (i.e. discovery). With `tailscale serve` I can get a private HTTPS endpoint to my local machine in almost no time.
  • gonzalohm 1 hour ago
    I don't have the code at hand, but I think it's better to just have a nginx server that only serves content if the browser has a specific certificate installed. That way you generate a key pair, share the public key with anyone that you want to share the content with and that's it.

    Downside is that some browsers don't handle the certificates properly (especially on phones)

  • guessmyname 2 hours ago
    If self-hosted, then why do you need a third-party service *.ssh.luffy.cx ?
    • benatkin 2 hours ago
      You replace it with your domain.
  • snehesht 1 hour ago
    I'm working on something similar with userspace wireguard, will share it soon.
  • Transformanshen 1 hour ago
    This is what I needed, but I didn't know it
  • esseph 49 minutes ago
    While I do appreciate very much the "we already have the technology, let's just use it!" approach + the self hosting aspect, one of the downsides of self hosting without a proxy is having to expose your endpoint and likely having minimal defensive tools.