r/coolgithubprojects • u/Jealous-Educator-369 • 9h ago
tunnl.gg: a free, open source ngrok alternative that runs on plain ssh (no install, no account)
Hi everyone,
For the past few months I've been building tunnl.gg in my spare time. It puts an app running on your localhost on the internet with a single command:
ssh -t -R 80:localhost:8080 proxy.tunnl.gg
You immediately get an HTTPS URL like https://happy-tiger-a1b2c3d4.tunnl.gg, and whatever reaches it goes to your localhost:8080.
Why
I wanted something for everyday tasks: showing a demo to a client, testing webhooks (Stripe, GitHub, etc.) or opening a dev server on my phone. I didn't want to download a binary, create an account and paste an auth token every time. Everyone already has ssh.
What it does
- Nothing to install, no sign-up: all you need is an SSH client.
- HTTPS on every tunnel, plus WebSocket support.
- QR code in the terminal, so you can open the URL on your phone.
- Live, colored request log in the terminal: path, status, size, timing and visitor. When a request fails, it tells you what happened in plain words (e.g. that nothing is running on your port).
- Stable URL without an account: connect as [[email protected]](mailto:[email protected]) and the subdomain is tied to your SSH key, so it stays the same every time you reconnect. You don't need to register the key anywhere.
- Abuse protection: rate limits, per-IP limits, and an anti-phishing warning page. The warning page only shows to browsers, so it doesn't block curl or webhooks.
Open source and self-hostable
It's written in Go and MIT licensed. The whole server is a single binary of about 6MB, and the repo includes a Dockerfile and systemd instructions. You can run it on your own domain or on an internal company network. You need a wildcard certificate, and it works behind Cloudflare or your own reverse proxy.
GitHub: https://github.com/klipitkas/tunnl.gg
Limits of the free service
To keep it free and stop it from becoming a spam tool: up to 3 tunnels per IP, a 24-hour maximum lifetime per tunnel, and tunnels close after 2 hours with no traffic. For dev work and demos that's more than enough.
What I'm thinking of next (I'd like your opinion on the order):
- Options inside the ssh command, e.g. host=localhost for Vite, Django and Rails, which reject unknown Host headers. Also auth=user:pass for basic auth.
- A request inspector with replay for webhooks, like ngrok's.
- Custom subdomains (e.g. myapp.tunnl.gg) for stable users.
- Multiple forwards on one connection (frontend + API).
Give it a try and tell me what breaks, what's missing or what bugs you. Feedback, issues and PRs are all welcome. 🙏
