A friend wants to proofread your work-in-progress blog post, but its preview only runs on localhost:8080. Several tools can help. Some run as a commercial service, like ngrok or Cloudflare Quick Tunnels. Some are self-hostable but require a specific client, like frp or localtunnel. Some only require a plain SSH client but rely on a specific SSH server, like sish. Let’s implement a self-hosted solution with only Open SSH and nginx!
First, we forward connections from a port on a remote server to your local service: `$ ssh -N -R 0:localhost:8080 web02.luffy.cx`. When you specify `0` as the remote port, the server allocates a free port, such as 41535. Then, we configure nginx to proxy requests from `https://p41535.ssh.luffy.cx` to `http://127.0.0.1:41535` using a server block that matches the port in the domain name.
We also need to add DNS records for `*.ssh.luffy.cx` and get a wildcard certificate through Let’s Encrypt. In my case, Nix OS gets the certificates automatically. Access control is achieved using the ngx_http_secure_link_module, which computes a hash over a set of values, including a secret, and compares it with the hash from the request. The hash is base64-encoded and placed in the URL as a username, along with its expiration timestamp.
来源: Hacker News · 由HeadlinesBriefing整理摘要