Self-hosted HTTP tunnels with SSH and nginx
Curated from Lobsters
Relying on third-party tunneling services introduces unnecessary trust boundaries and potential data leaks, especially when handling sensitive internal tools. This piece details a robust alternative using native SSH port forwarding combined with nginx reverse proxying. It is particularly relevant for teams that must maintain strict compliance or operate in air-gapped environments where external dependencies are prohibited. The approach leverages standard infrastructure components you likely already manage, reducing the attack surface compared to installing proprietary agents on every host. By controlling the encryption and routing logic yourself, you eliminate the risk of a compromised relay service intercepting traffic. The primary challenge lies in correctly configuring the proxy to handle stateful connections and ensure proper header forwarding. Review the specific nginx directives to understand how they mitigate common tunneling pitfalls, then test your setup in a staging environment before deploying to production to verify latency and reliability under load.
Comments
— Lobsters