Skip to content

Self-Hosting GoTunnel

GoTunnel ships as a single binary that is both the client and the server, so you can run your own tunnel server instead of using the managed host. Self-hosting needs no database, Redis, or email — that machinery only exists for the managed beta's email enrollment. All you need is the binary, a machine with a public IP, and a shared token.

There are two roles:

  • Server — runs on a machine reachable from the internet (a VPS). gotunnel server
  • Client — runs next to the local service you want to expose. gotunnel / gotunnel client

1. Install the binary on both machines

Grab the right build from the download page or the releases and put gotunnel on your PATH (see the README install steps for macOS/Linux/Windows).

2. Start the server

Pick a token your clients will use to authenticate (any long random string):

# simplest: plaintext control channel, public ports start at 10000
gotunnel server --addr :9000 --start-port 10000 --auth-tokens "your-strong-token"

With TLS on the control channel (recommended over the public internet):

gotunnel server \
  --addr :9000 --tls \
  --tls-cert /path/server-cert.pem \
  --tls-key  /path/server-key.pem \
  --auth-tokens "your-strong-token"
  • --auth-tokens takes one or more comma-separated tokens (or set GOTUNNEL_AUTH_TOKENS). There is no default token — the server won't start without one.
  • Open the tunnel port (:9000) and the public port range (from --start-port upward) in your firewall.
  • Add --max-connections, --max-auth-failures, and --auth-lockout to taste.

3. Connect a client

gotunnel --server your-vps-host:9000 --local localhost:3000 --token "your-strong-token"

You'll get a public your-vps-host:<assigned-port> that forwards to localhost:3000. With TLS on the server, add --tls --tls-ca /path/ca-cert.pem, and --tls-servername if your certificate name differs from the host you dial.

4. (Optional) Subdomain mode

To hand out https://<random>.tunnel.example.com URLs instead of ports, run the server with --base-domain tunnel.example.com --http-addr 127.0.0.1:8080, point a wildcard DNS record at the box, and put a TLS-terminating reverse proxy (nginx/Caddy) in front of the HTTP router. This is how the managed host runs.

Running as a service

Run the server under systemd so it restarts on boot/failure:

[Unit]
Description=gotunnel
After=network.target

[Service]
ExecStart=/usr/local/bin/gotunnel server --addr :9000 --auth-tokens your-strong-token
Restart=always
RestartSec=5

[Install]
WantedBy=multi-user.target

Updating

gotunnel update

Managed vs self-hosted at a glance

Managed (hosted) Self-hosted
Setup one command, email verification once run your own server + token
Public URL https://<id>.gotunnel.bakaredev.site your host/port (or your own subdomain)
TLS handled for you your certs or a reverse proxy
Data path through the managed server entirely your infrastructure
Cost free beta free, your VPS

Both modes speak the same binary protocol with the same stream multiplexing and TLS support — the only difference is who owns the server.