← All stories
● Covered by 1 source · 1 reportLow impact1 neutral

Self-hosted HTTP Tunnels Using OpenSSH and Nginx

🔄 Updated 1h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Uses OpenSSH for remote port forwarding.
  • Configures Nginx to proxy requests to forwarded ports.
  • Includes DNS and wildcard certificate setup.
  • Explains securing access with ngx_http_secure_link_module.

Basic Tunnel Setup

The process begins by forwarding connections from a remote server port to a local service using SSH. Specifying '0' as the remote port allows the server to allocate a free port dynamically. For example, a local service running on localhost:8080 can be exposed via a remote port.

Nginx is then configured to proxy incoming requests from a specific subdomain (e.g., p41535.ssh.luffy.cx) to the corresponding local port on the server (e.g., http://127.0.0.1:41535). This involves setting up server blocks in Nginx to listen on HTTPS and use a regular expression to capture the port number from the subdomain.

DNS and Certificates

To enable the subdomain-based routing, DNS records for '*.ssh.luffy.cx' must be added, typically as a CNAME pointing to the remote server. A wildcard SSL certificate is also required for HTTPS, which can be obtained through services like Let's Encrypt. The article mentions using a separate ACME DNS-01 challenge zone for certificate management.

Access Control Implementation

The initial setup relies on the allocated port number as the primary security measure. To enhance security, the ngx_http_secure_link_module can be used. This module computes a hash based on a secret and other values, which is then included in the URL as a username along with an expiration timestamp. This hash is compared against the request to validate access, preventing unauthorized enumeration of ports.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~4 min · 3 stories · Oct 04

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

This article details how to create self-hosted HTTP tunnels using OpenSSH and Nginx to expose local services to the internet. It outlines the setup for remote port forwarding and Nginx proxy configuration, along with methods for access control.