Hasty Briefsbeta

双语

Self-hosted HTTP tunnels with SSH and Nginx

2 hours ago
  • The article describes a self-hosted HTTP tunnel solution using only OpenSSH and nginx to expose a local service (e.g., localhost:8080) to the internet.
  • Basic setup involves SSH remote port forwarding with dynamic port allocation, then configuring nginx as a reverse proxy to that port using a wildcard domain and SSL certificate from Let's Encrypt.
  • Access control is enhanced using nginx's secure_link module, which requires a hash and expiration timestamp in the URL username, preventing unauthorized enumeration and providing time-limited access.
  • The article provides a complete nginx configuration for secure_link, including map directives, expiration checks, and proxy settings for HTTP and WebSocket.
  • A helper script is developed to automate the process: it finds the allocated SSH port, generates the secure link hash, and outputs the shareable URL; the script is installed on the server and integrated into SSH config.
  • The solution relies only on OpenSSH and nginx, both already running on the server, and offers a simple command to create a self-hosted tunnel.