Self-hosted HTTP tunnels with SSH and Nginx
2 hours ago
- The article describes a self-hosted HTTP tunnel solution using only OpenSSH and nginx to expose a local service (e.g., localhost:8080) to the internet.
- Basic setup involves SSH remote port forwarding with dynamic port allocation, then configuring nginx as a reverse proxy to that port using a wildcard domain and SSL certificate from Let's Encrypt.
- Access control is enhanced using nginx's secure_link module, which requires a hash and expiration timestamp in the URL username, preventing unauthorized enumeration and providing time-limited access.
- The article provides a complete nginx configuration for secure_link, including map directives, expiration checks, and proxy settings for HTTP and WebSocket.
- A helper script is developed to automate the process: it finds the allocated SSH port, generates the secure link hash, and outputs the shareable URL; the script is installed on the server and integrated into SSH config.
- The solution relies only on OpenSSH and nginx, both already running on the server, and offers a simple command to create a self-hosted tunnel.