siinghd/tunnel

Self-hosted HTTP and WebSocket tunnel exposing local ports at custom subdomains, in Go

★ 1Forks 0GoGitHub ↗Compare

README

htunnel

Self-hosted HTTP/WebSocket tunnel — exposes a local port at https://<subdomain>.yourdomain via a single Go binary on each side.

What it does

  • Server accepts WebSocket client connections and routes inbound HTTP requests by subdomain
  • Client dials the server, registers a subdomain, and forwards traffic to a local port
  • Shared-secret auth via TUNNEL_SECRET; subdomain reservation and capacity limits
  • Status pages (rendered server-side) showing active tunnels
  • Cross-platform prebuilt clients in bin/ (linux/darwin/windows, amd64/arm64) and a one-line install.sh

Stack

Go 1.24, gorilla/websocket. No database — state is in memory.

Run it

Build:

go build -o bin/htunnel-server ./cmd/htunnel-server
go build -o bin/htunnel        ./cmd/htunnel

Server (set env first, see .env.example):

./bin/htunnel-server

Client:

htunnel <local-port> -s <subdomain> -t <token>
# e.g. htunnel 3000 -s myapp -t YOUR_TOKEN

Notes

  • Required env on the server: PORT, BASE_DOMAIN, TUNNEL_SECRET, REQUEST_TIMEOUT, MAX_BODY_SIZE. See .env.example.
  • Nginx in front of the server is recommended for TLS + wildcard subdomain routing — see nginx.conf.
  • The bin/ directory contains committed release binaries; remove from .gitignore if you don't want them shipped.

Contributors

siinghd

Issues