Self-hosted HTTP tunnels with SSH and Nginx
- ID
- 31874
- Status
- summarized
- Published
- 05 Oct 2026, 6:25 AM
- Fetched
- 05 Oct 2026, 9:21 PM
- Provider
- Hacker News
- Category
- dev-community
- Original URL
- https://vincent.bernat.ch/en/blog/2026-http-over-ssh
- Source URL
- https://hnrss.org/best
Summary
- Score
- 7.0
- Created
- 05 Oct 2026, 9:34 PM
- Tags
- Audience
- developersvibe_coderssaas_startup_founders
What happened
Vincent Bernat documents a self-hosted HTTP tunnel using only OpenSSH and nginx: `ssh -R 0:localhost:8080 server` allocates a free remote port, and an nginx regex `p(\d\d\d\d\d).ssh.luffy.cx` proxies to `127.0.0.1:$port`. It uses wildcard DNS for `*.ssh.luffy.cx`, Let’s Encrypt DNS-01 via a Route 53 zone, and `ngx_http_secure_link_module` with an MD5 hash plus expiry in the URL username; the allocated port alone has only ~14.785 bits of entropy. The Hacker News thread has 165 points and 34 comments.
Why it matters
If you want an ngrok or Cloudflare Quick Tunnel alternative you control, this gives a concrete OpenSSH+nginx pattern and shows the security tradeoff: the remote port is not a secret, so you need an extra expiring token. Decide whether wildcard DNS, ACME DNS-01, nginx regex, and a weak MD5-based link are worth it versus using managed tunnels for quick localhost previews.
Discussion angle
When would you choose this over ngrok or Cloudflare Quick Tunnels, and how would you harden access control beyond the ~14.8-bit port and MD5 secure-link token?