Go implementation at the end of article.
- we needed to upgrade all dev servers to serve both HTTPS and HTTP. - we downgraded server to server comms to HTTP (something about invalid cert chain)
I think the ideal solution is to use “local” domain names but that requires a DNS resolver (via Tailscale or similar).
- services exposed via caddy(configured to use my domain on cloudflare for SSL)
- my lan dns resolver(adgaurd home) is configured to rewrite these domains to local IP. Specifically, the rewrite rule looks like `homeassistant.mydomain.com -> rpi.lan`
- Cloudflare tunnel on the rpi for services I want to access outside. I've it configured to require Google auth via cloudflare zero trust(free)
The neat part of this setup is that when I access a service when I'm at home, it works as expected completely locally including https.
If I try to access the service through the public internet, it will still work on the exact same domain and also have proper auth through cloudflare. This way I can access anything on the internet from my home server without worrying about security.
Cloudflare tunnel also offers some other cool things like ssh on your browser(which again uses the previously mentioned Google auth) if you need it.
https://github.com/legobeat/l7-devenv
Something like Lokal might till be useful here to facilitate remote collaboration by providing a tunnel (ie I can connect to your local session behind NAT without you opening ports or connect to VPNs etc).
For tunneling, how is this different / better than ssh -L?
the second answer is, ssh -L are just pretty slow on concurrent request, I might think it's just bloat as there is so much thing happen on ssh that not required for tunneling, also it doesn't do vhost natively as on Lokal you can just choose which domain you want to use, and it's just works...
https://chatgpt.com/share/9cc6ab14-e777-45a6-92b8-c58bbfb433...