Self-hosted HTTP Tunnels With SSH And Nginx
AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A report published on Vincent Bernat’s blog describes a way to expose a local web service through a self-hosted server using OpenSSH remote forwarding and Nginx. The setup can issue links with expiring access tokens, but the article does not provide independent security testing or adoption data.

Vincent Bernat has published a technical report describing how to expose a service running on a local machine through a public HTTPS link using OpenSSH and Nginx. The approach gives operators a self-hosted option for sharing previews without relying on a commercial tunnel provider or installing a separate tunnel client, while adding signed links with an expiration time.

The method starts with an SSH remote forward: a user connects to a server and asks OpenSSH to bind an automatically allocated remote port, forwarding traffic to a local service such as one listening on port 8080. Bernat’s example uses Nginx as a reverse proxy, routing requests for a hostname tied to that remote port to the corresponding local port on the server. Wildcard DNS and a wildcard TLS certificate allow the service to be reached over HTTPS.

Bernat adds access checks using Nginx’s secure_link module. The link carries a generated hash and expiration timestamp as HTTP basic-auth credentials; Nginx checks those against the port, expiration time and a shared secret. The configuration returns an authentication challenge when the hash is missing or invalid and a 410 response when the link has expired. It removes the authorization header before proxying the request and includes settings for WebSocket traffic.

The report also describes a helper script to print the access URL and keep the SSH session open. Because OpenSSH does not expose the allocated ephemeral port through an environment variable, the script finds it by inspecting related server processes and listening sockets. That method requires elevated access to inspect socket processes, according to the example. The source presents a particular deployment and configuration; it does not report formal testing, independent security review or measured performance.

At a glance
reportWhen: Published in 2026; the source does not…
The developmentVincent Bernat published a technical report showing how to build self-hosted HTTP tunnels with OpenSSH and Nginx.

A Tunnel Operators Can Host

The setup offers developers and system administrators another way to let someone reach a local web preview without moving the service to a public hosting environment. Its components—OpenSSH, Nginx, DNS and TLS—are commonly used server tools, so an operator with an existing server can control the endpoint and how links are issued.

The tradeoff is operational responsibility. The server needs suitable DNS and certificate configuration, and the link-based check depends on a shared secret and correct expiration handling. The report’s example explains how the pieces fit together, but it does not establish that the arrangement is appropriate for sensitive services or secure under every deployment. Readers would need to assess their own exposure, configuration and threat model.

Amazon

OpenSSH remote forwarding setup

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

From Remote Forwarding to HTTPS

HTTP tunnel services typically make a locally running application reachable from outside the machine or network where it runs. Bernat’s report places his method among options that include hosted services such as ngrok and Cloudflare Quick Tunnels, self-hostable tools that need their own client, and tools that use SSH but require a particular server implementation.

The distinctive choice in this report is to use plain OpenSSH for forwarding and Nginx for the public HTTPS endpoint. An SSH server can allocate a free remote port when the requested port is zero. Nginx then maps a hostname containing that port to the server’s loopback address and forwards the request. Bernat says his own deployment obtains wildcard certificates automatically through NixOS and uses DNS records that direct ACME DNS-01 validation.

Amazon

Nginx reverse proxy with SSL

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Security and Deployment Questions

The report does not say whether the configuration has undergone independent security review, nor does it provide testing results for load, reliability or compatibility across server setups. It also does not document how operators should rotate the shared secret, revoke a link before its expiry, or handle applications that need additional proxy behavior.

Bernat presents the mechanism as a way to secure the links “a bit,” rather than as a complete security guarantee. The article does not establish that the approach is suitable for confidential material, and it gives no broader adoption figures or comparison of security with the named tunnel services. Those points remain unverified in the source.

Amazon

wildcard DNS SSL certificate

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Running and Reviewing the Setup

The next step for readers interested in the method is to review Bernat’s full configuration and adapt the DNS, certificate and Nginx settings to their own server. They would also need to decide how to manage the shared secret and link lifetime, and whether the helper script’s need to inspect listening sockets fits their permissions model.

The source does not announce a release schedule, follow-up milestone or wider deployment plan. Further details about testing, security review or changes to the example may come from Bernat or from operators who try the configuration, but no such developments are confirmed in the report.

Amazon

signed URL generator for HTTPS

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What does the setup do?

It forwards requests from a public HTTPS address through an OpenSSH remote tunnel to a web service running on the user’s machine.

What role does Nginx play?

Nginx terminates HTTPS and proxies requests from a hostname associated with the allocated SSH port to that port on the server’s loopback interface.

How does the example limit access?

It uses a generated hash and expiry timestamp in HTTP basic-auth credentials. Nginx checks them against the port and a shared secret, rejecting invalid or expired links.

Has the method been independently security-tested?

The source report does not describe an independent security review or provide formal test results.

Does the setup require a custom tunnel client?

The forwarding uses an SSH client, while the report’s helper script automates URL generation and keeps the session open. The source does not describe a separate tunnel client.

Source: hn

HALLOWEEN

Halloween Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

How DNS Filtering Fits Into a Defense-in-Depth Strategy

DNS filtering blocks threats before connections form. Here’s how it layers with firewalls, EDR, and zero trust — plus honest limits and setup tips.

What a Firewall Does and What It Cannot Do

A clear, jargon-free guide to firewalls: how they filter network traffic, what they genuinely protect against, and the blind spots no firewall can fix.

2 Best Home Night Lights in 2026

Discover the best home night lights of 2026, featuring adjustable and fixed options for different rooms, with expert insights on features and power use.

The Difference Between Router, Gateway, Firewall and Switch

A clear, jargon-free guide to what routers, gateways, firewalls, and switches actually do — and how they work together in your home or lab network.