Self-hosted HTTP tunnels with SSH and Nginx

(vincent.bernat.ch)

76 points | by renehsz 4 hours ago

10 comments

  • toomim 3 hours ago
    For this stuff, I'm most excited about https over iroh.

    - https://github.com/aflin/iroh-webproxy

    - https://github.com/n0-computer/iroh-proxy-utils

    No port forwarding. No public IP required. No special proxy to set up.

    Iroh already runs public relays. Your two computers will signal through those, and then port-knock and form a direct connection to each other, perfectly encrypted.

    We just need to define a new https:// url, like ... let's call it "irohttps://" maybe, so then you could contact my laptop with "irohttps://<hash>/path?query".

    • Muromec 2 hours ago
      >and then port-knock and form a direct connection to each other, perfectly encrypted.

      so... ICE/TURN/STUN ? Sorry I forgot which one of them actually works, but they do work

    • _def 1 hour ago
      iroh-ssh works today: https://github.com/rustonbsd/iroh-ssh

      Not perfectly, but good enough for port forwarding web interfaces through cgnat

  • aliasxneo 3 hours ago
    This is one of the core things I've been working towards with DNTLS [1]. I love the idea of tunnels, especially for sharing between private parties. The SaaS providers (Tailscale, Cloudflare, etc.) have done a good job making it really easy on their infra, but it really blurs the line of "self-hosted" to me. Ideally we end up with solutions like this that can be run entirely without an intermediary.

    [1]: https://dntls.substack.com/p/the-new-internet

    • gonzalohm 2 hours ago
      So like wireguard then?
      • subscribed 1 hour ago
        Yeah, and Dropbox is just rsync and scp :)
      • aliasxneo 2 hours ago
        If that's all that was necessary then I feel like a lot of these SaaS tools wouldn't be as popular. I suspect a lot of Tailscale's success is because wireguard is not easy nor does it solve the full problem space (i.e. discovery). With `tailscale serve` I can get a private HTTPS endpoint to my local machine in almost no time.
  • gonzalohm 2 hours ago
    I don't have the code at hand, but I think it's better to just have a nginx server that only serves content if the browser has a specific certificate installed. That way you generate a key pair, share the public key with anyone that you want to share the content with and that's it.

    Downside is that some browsers don't handle the certificates properly (especially on phones)

    • zamadatix 1 minute ago
      You can also do basic auth if you're going to have an HTTPS server. I took the guide to be for "I have some HTTP endpoint I'm halfway through working on something with and just want someone to be able to access it with the tools we all have already real quick". Especially since Windows finally ships OpenSSH these days.
    • jagged-chisel 1 hour ago
      An HTPS server always hands out its public key. Do you mean client secrets or something?
  • guessmyname 3 hours ago
    If self-hosted, then why do you need a third-party service *.ssh.luffy.cx ?
    • benatkin 3 hours ago
      You replace it with your domain.
  • snehesht 3 hours ago
    I'm working on something similar with userspace wireguard, will share it soon.
  • Transformanshen 2 hours ago
    This is what I needed, but I didn't know it
  • superkuh 1 hour ago
    I forward port 80/443 on my router to port 80/443 on my home LAN nginx webserver and point my domain name to my home IPv4. Then I put files in directories. It works great and has worked great for a couple decades. While the number of static nginx vulnerabilities that have come out since AI became good at coding has increased I still haven't run into one that applies to my simple static nginx setup. All this tunneling and secrecy and credentials is... well, it applies to some cases and I don't want to dismiss those. But it really doesn't apply to most human person's use cases. Just host a normal server on your home IPv4. There's nothing to break.
    • tredre3 1 hour ago
      > Just host a normal server on your home IPv4. There's nothing to break.

      There is a privacy aspect. For example you seem to have watched Meet Joe Black and Six Days Seven Nights recently. Do you care that we know that? Maybe not, but I can also see the porn you enjoyed.

      • superkuh 48 minutes ago
        I don't understand how you would know that. If you mean those sites where you put in an ip address and get a list of torrents that IPv4 has been associated with then I guess you aren't aware that those things are wildly inaccurate in the false positive sense. Because of this I am not sure if you were just giving a made up example of information you might find on those sites, or if you actually checked my profile and pinged superkuh.com to get my ipv4 and ran it and got fake results. An IP address is not private info. It's how we participate with each other on the internet. In either case I'm not worried because I know those site's purported results don't mean anything. If you mean nation state level actors or the like, well, yeah. That threat model is a bit beyond this.

        It is much more private to host on your static webserver and link your friend to http(s)://my.ip.goes.here/orwhatever.jpg than it is to use a third party corporate services that both establish third party doctorine of no assumption of privacy and who have a profit-motive to sell your info. Do it yourself and you have a legal assumption of privacy and no one's continued existence is dependent upon selling information about you.

    • jagged-chisel 1 hour ago
      ISP ToS become an issue. Certainly depends on how rabidly one’s ISP enforces the rule …
  • esseph 2 hours ago
    While I do appreciate very much the "we already have the technology, let's just use it!" approach + the self hosting aspect, one of the downsides of self hosting without a proxy is having to expose your endpoint and likely having minimal defensive tools.