This is one of the core things I've been working towards with DNTLS [1]. I love the idea of tunnels, especially for sharing between private parties. The SaaS providers (Tailscale, Cloudflare, etc.) have done a good job making it really easy on their infra, but it really blurs the line of "self-hosted" to me. Ideally we end up with solutions like this that can be run entirely without an intermediary.
No port forwarding. No public IP required. No special proxy to set up.
Iroh already runs public relays. Your two computers will signal through those, and then port-knock and form a direct connection to each other, perfectly encrypted.
We just need to define a new https:// url, like ... let's call it "irohttps://" maybe, so then you could contact my laptop with "irohttps://<hash>/path?query".
This is one of the core things I've been working towards with DNTLS [1]. I love the idea of tunnels, especially for sharing between private parties. The SaaS providers (Tailscale, Cloudflare, etc.) have done a good job making it really easy on their infra, but it really blurs the line of "self-hosted" to me. Ideally we end up with solutions like this that can be run entirely without an intermediary.
[1]: https://dntls.substack.com/p/the-new-internet
For this stuff, I'm most excited about https over iroh.
- https://github.com/aflin/iroh-webproxy
- https://github.com/n0-computer/iroh-proxy-utils
No port forwarding. No public IP required. No special proxy to set up.
Iroh already runs public relays. Your two computers will signal through those, and then port-knock and form a direct connection to each other, perfectly encrypted.
We just need to define a new https:// url, like ... let's call it "irohttps://" maybe, so then you could contact my laptop with "irohttps://<hash>/path?query".
I'm working on something similar with userspace wireguard, will share it soon.
If self-hosted, then why do you need a third-party service *.ssh.luffy.cx ?
You replace it with your domain.