SirTunnel, a personal ngrok alternative
eighty-twenty.org
eighty-twenty.org
Personally, I believe tunneling is the closest way currently to provide the unrealized future IPv6 promised. By sharing IPv4 addresses and routing based on SNI, anyone with a domain can host a website or service from home and tunnel through a nearby server with a public IP. You get the added benefit that your IP address stays private.
What I've been doing for my own work, in the case that I need to access a server from one device on another, is to use Yggdrasil.
https://yggdrasil-network.github.io/
Yggdrasil is essentially a p2p VPN where peers have IPv6 addresses that are declared by their public/private keys. I set up a dedicated peer as a nano EC2 instance in AWS so that my devices can reach each other no matter where they're located or what sort of firewall they're behind. My EC2 instance also provides a nameserver for my Yggdrasil peers.
I know it's not exactly the same as Ngrok, but I've found it really useful for development purposes and simply for the purpose of being able to control my devices. My phone, both my Macbooks, Raspberry Pi, and even my car stereo are peers on my Yggdrasil network. The downside is sharing with a 3rd party means they need to install Yggrasil, that is unless you set up a public web server to act as a "tunnel" to the web servers in your network.
Before someone mentions security, not all of my devices are connected all the time (e.g. my phone), and my EC2 peer whitelists which peers can connect.
Yggdrasil is pretty dang easy, though. If you don't have your own clearnet peer, there's plenty of public peers on the main net to use. I just prefer using my own peer because I don't intend on sharing my network with other parties. The EC2 server isn't hard to setup and costs peanuts to run. Everything else basically just works as long as you have one or more peers configured. I haven't had a situation where I couldn't get it to work in a few minutes.
> designating exit nodes
As far as I'm aware, that's not a feature of Yggrasil. My understanding is if the IP for a connection falls out of its range (it uses some deprecated range of IPv6 addresses that are technically still valid), it just passes it through without treating it like a potential peer.
(I’d love to hear what SirTunnel and caddy bring to the table! I think the auto registering of tunnels is certainly less hacky than the approach in the above gist, but on its own that’s not enough for me to care..)
> It's that simple there's no authentication at all
In practice it should require ssh key auth, that’s what I’ve always done. But without requiring password. And limited to just being able to create tunnels via the ForceCommand sshd config.
Disclaimer: I'm the author of sish
I've had issues with localhost.run going down before, which is why I switched.
The great thing about this method is that it works with literally any provider that provides SSH access.
Does anyone know of an alternative that does this as well?