Vincent Bernat has published a guide on implementing self-hosted HTTP tunnels using only OpenSSH and Nginx, offering an alternative to commercial services like ngrok or Cloudflare Quick Tunnels.

The approach leverages SSH’s remote port forwarding feature combined with Nginx’s proxy and secure link capabilities. According to Bernat, the basic setup involves three steps: forwarding connections from a remote server port to a local service using SSH, configuring Nginx to proxy requests from a dynamically generated domain to the forwarded port, and setting up DNS records and Let’s Encrypt wildcard certificates.
When a user runs ssh -R 0:localhost:8080, the SSH server allocates a free ephemeral port. Nginx then proxies HTTPS requests from a domain like p41535.ssh.luffy.cx to the local service on 127.0.0.1:41535. The port number becomes the primary identifier for accessing the tunnel.
Bernat adds a security layer using Nginx’s ngx_http_secure_link_module, which computes an MD5 hash based on an expiration timestamp, port number, and a shared secret. The hash is included in the URL as HTTP basic authentication credentials, allowing access control with time-limited links. Requests with invalid or expired hashes receive 401 or 410 HTTP status codes accordingly.
The implementation includes a helper script that addresses the main technical challenge: discovering which ephemeral port OpenSSH allocated. The script examines ancestor sshd-session processes and uses ss to identify listening ports, then generates URLs with embedded authentication tokens valid for 24 hours by default.
Bernat notes that the solution requires only two existing components—OpenSSH and Nginx—already running on most servers. He provides the complete helper script and mentions a NixOS configuration module for users of that distribution. The approach allows developers to share work-in-progress services with a single command and generated URL.
Key facts
- Uses OpenSSH remote port forwarding and Nginx proxy to create tunnels without additional services
- Secures access using MD5-based hash authentication with time-limited tokens embedded in URLs
- Includes a helper script that automatically discovers allocated ephemeral ports and generates shareable links
- Supports WebSocket connections and works with standard HTTP clients like curl
