Guide shows how to self-host HTTP tunnels using OpenSSH and Nginx
A technical post walks through building a self-hosted alternative to services like ngrok or Cloudflare Quick Tunnels, relying only on standard OpenSSH remote port forwarding and an Nginx reverse proxy rather than proprietary clients or servers. It details configuring SSH to forward a local port to a remote server, setting up Nginx to route wildcard subdomains to that port, and obtaining a Let's Encrypt wildcard certificate via DNS-01 challenges on Route 53.
GoKawiil's interpretation of the reporting above, not reported fact.
The approach could let developers expose local development servers to outside testers without depending on third-party tunneling services or their rate limits and costs. Because the method uses a predictable, low-entropy port number as the only access barrier, it suggests additional access controls would be needed for sensitive content, as the author notes other tools add random strings specifically to prevent enumeration.
- Uses only standard OpenSSH remote forwarding and Nginx, no proprietary client needed.
- Requires wildcard DNS and Let's Encrypt certificates via DNS-01 challenges.
- Security relies on port number secrecy, which has acknowledged low entropy.
Source: vincent.bernat.ch — Vincent Bernat, 2026-10-04
Published there as: “Self-hosted HTTP tunnels with SSH and Nginx”
Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.