Self-Hosting GoTunnel¶
GoTunnel ships as a single binary that is both the client and the server, so you can run your own tunnel server instead of using the managed host. Self-hosting needs no database, Redis, or email — that machinery only exists for the managed beta's email enrollment. All you need is the binary, a machine with a public IP, and a shared token.
There are two roles:
- Server — runs on a machine reachable from the internet (a VPS).
gotunnel server - Client — runs next to the local service you want to expose.
gotunnel/gotunnel client
1. Install the binary on both machines¶
Grab the right build from the download page or the releases and put gotunnel on your PATH (see the README install steps for macOS/Linux/Windows).
2. Start the server¶
Pick a token your clients will use to authenticate (any long random string):
# simplest: plaintext control channel, public ports start at 10000
gotunnel server --addr :9000 --start-port 10000 --auth-tokens "your-strong-token"
With TLS on the control channel (recommended over the public internet):
gotunnel server \
--addr :9000 --tls \
--tls-cert /path/server-cert.pem \
--tls-key /path/server-key.pem \
--auth-tokens "your-strong-token"
--auth-tokenstakes one or more comma-separated tokens (or setGOTUNNEL_AUTH_TOKENS). There is no default token — the server won't start without one.- Open the tunnel port (
:9000) and the public port range (from--start-portupward) in your firewall. - Add
--max-connections,--max-auth-failures, and--auth-lockoutto taste.
3. Connect a client¶
gotunnel --server your-vps-host:9000 --local localhost:3000 --token "your-strong-token"
You'll get a public your-vps-host:<assigned-port> that forwards to localhost:3000. With TLS on the server, add --tls --tls-ca /path/ca-cert.pem, and --tls-servername if your certificate name differs from the host you dial.
4. (Optional) Subdomain mode¶
To hand out https://<random>.tunnel.example.com URLs instead of ports, run the server with --base-domain tunnel.example.com --http-addr 127.0.0.1:8080, point a wildcard DNS record at the box, and put a TLS-terminating reverse proxy (nginx/Caddy) in front of the HTTP router. This is how the managed host runs.
Running as a service¶
Run the server under systemd so it restarts on boot/failure:
[Unit]
Description=gotunnel
After=network.target
[Service]
ExecStart=/usr/local/bin/gotunnel server --addr :9000 --auth-tokens your-strong-token
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
Updating¶
gotunnel update
Managed vs self-hosted at a glance¶
| Managed (hosted) | Self-hosted | |
|---|---|---|
| Setup | one command, email verification once | run your own server + token |
| Public URL | https://<id>.gotunnel.bakaredev.site |
your host/port (or your own subdomain) |
| TLS | handled for you | your certs or a reverse proxy |
| Data path | through the managed server | entirely your infrastructure |
| Cost | free beta | free, your VPS |
Both modes speak the same binary protocol with the same stream multiplexing and TLS support — the only difference is who owns the server.