hn.today

Self-hosted HTTP tunnels with SSH and Nginx

vincent.bernat.ch74 points19 comments
Screenshot of Self-hosted HTTP tunnels with SSH and Nginx

This describes a self-hosted way to expose a localhost web service over HTTPS using only OpenSSH and nginx. The client opens a remote TCP forward with ssh -R 0:localhost:PORT to let the server allocate an ephemeral port; nginx is configured to map hostnames of the form p{port}.ssh.example.com to the local TCP listener and a Route 53-hosted ACME DNS-01 zone is used to obtain a wildcard Let's Encrypt certificate. The nginx server_name uses a regex to extract the ephemeral port and proxy_pass forwards traffic to 127.0.0.1:$port, with headers and WebSocket proxying handled appropriately.

Access control is implemented with ngx_http_secure_link_module: the client supplies a username in HTTP Basic auth containing a base64-encoded MD5 hash and an expiration timestamp, which nginx verifies against secure_link_md5 computed from the expires, port, and a shared secret; nginx returns 401 for missing/invalid hashes and 410 for expired links and strips Authorization before proxying. A helper script discovers the allocated port(s) by walking ancestor processes to find sshd-session and using ss (sudo required) to list listening sockets, then prints shareable URLs after generating the MD5+base64 token. The design acknowledges low entropy of kernel-chosen ephemeral ports and the MD5-based hash, but presents a practical, minimal alternative to commercial tunneling services.

Read on vincent.bernat.ch19 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Web

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.