Self-hosted HTTP tunnels with SSH and Nginx
Points and comments are a snapshot, not live.
Self-host HTTP tunnels using only OpenSSH and nginx, with access control via secure links.
The article describes setting up HTTP tunnels with SSH reverse port forwarding and nginx proxying. A random port is allocated by SSH, and nginx routes requests from a subdomain like p41535.ssh.luffy.cx to localhost. Access control uses nginx's secure_link_module to add a hash and expiration timestamp in the URL's username field, verified via HTTP basic auth. A helper script automates generation of the hash and URL, and is installed as a RemoteCommand in SSH config.
The setup requires DNS wildcard records, a Let's Encrypt wildcard certificate, and the helper script runs on the server to display the generated tunnel URL.
What commenters are saying
Commenters debate the security and complexity of the approach. Some point out that the first nginx config allows an attacker to proxy to any localhost port, which the author mitigates with the secure_link module in the second part. Others recommend alternatives: sish (a dedicated SSH tunnel server), Tailscale serve, or mTLS client certificates. A concern is raised about tunnel enumeration and abandoned sessions. The thread also discusses ISP ToS restrictions on home hosting and the privacy trade-offs versus third-party services.