Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
To share a web app running at localhost:8080 through a public HTTPS URL, use SSH remote port forwarding to carry requests from a public server back to your machine, then use NGINX on that server to route a hostname to the forwarded port. SSH provides the tunnel; NGINX handles public HTTP routing and can terminate TLS.
How the tunnel routes a request
The setup has two connections. Your computer opens an outbound SSH connection to a server reachable from the internet. That connection carries traffic arriving at a server-side port back to the local web service. NGINX accepts a request for a hostname on the public server and proxies it to that forwarded port.
- A visitor opens a URL such as
https://p<port>.ssh.example. - DNS directs the hostname to the public server, where NGINX receives the HTTPS request.
- NGINX proxies the request to
http://127.0.0.1:<port>on the server. - SSH carries the connection through the remote forward to the application listening on your machine, for example
localhost:8080.
This arrangement can work when your machine is behind NAT because it initiates the SSH connection outward. The public server still needs to be reachable, and its SSH policy must permit remote forwarding. Vincent Bernat documents this pattern in an SSH reverse-forwarding example.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
What you need before configuring it
- A local HTTP application and its listening port, such as
localhost:8080. - A public server with SSH access, remote forwarding permitted, and NGINX installed.
- A domain name with DNS records that direct the desired hostname or wildcard hostnames to that server.
- A TLS certificate valid for the hostname pattern. A wildcard certificate can be obtained using ACME DNS-01 validation.
- A plan for restricting access to the exposed application.
Wildcard DNS is useful when each tunnel gets a hostname derived from its allocated port. DNS alone does not configure NGINX routing or provide a certificate: those must also cover the hostnames visitors will use.
#1 Best Overall
- Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
- Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
- CanaKit Turbine Black Case for the Raspberry Pi 5
- CanaKit Low Noise Bearing System Fan
- Mega Heat Sink - Black Anodized
Open an SSH remote forward
For the example service on port 8080, run this from the computer hosting the application:
ssh -N -R 0:localhost:8080 web02.luffy.cx
In this command, -R requests remote forwarding, -N tells SSH not to run a remote command, and 0 asks OpenSSH on the server to allocate an available remote port. The application target, localhost:8080, is reached from the SSH client side. The allocated port is needed for the server-side routing configuration.
Rank #2
- Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM)
- Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
- CanaKit Premium High-Gloss Raspberry Pi 4 Case with Integrated Fan Mount, CanaKit Low Noise Bearing System Fan
- CanaKit 3.5A USB-C Raspberry Pi 4 Power Supply (US Plug) with Noise Filter, Set of Heat Sinks, Display Cable - 6 foot (Supports up to 4K60p)
- CanaKit USB-C PiSwitch (On/Off Power Switch for Raspberry Pi 4)
The command is an example, not a universal deployment recipe. Confirm how the installed SSH client and server report the allocated port, and verify the server’s SSH configuration permits the requested forwarding. Firewall rules must allow the relevant traffic to reach the forwarding listener and NGINX.
Route a hostname through NGINX
Once the forwarding port is known, configure NGINX to route the corresponding hostname to the server’s loopback address and that port. In the documented pattern, a hostname such as p<port>.ssh.example maps to http://127.0.0.1:<port>. NGINX’s ngx_http_proxy_module provides the proxy_pass directive for selecting an upstream and proxy_set_header for setting or changing request headers; see the NGINX proxy module documentation.
Rank #3
- Design for Raspberry Pi: Supports installation of 4 Raspberry Pis and 4 ssds, compatible with any 2.5” Solid State Drive (7mm/9mm) and Rpi 4B/3B+, and other B/B+ models.
- The SSD mounting bracket also has two holes reserved for the SD card extension adapter ASIN: B09CKRDFTH, which allows you to access the SD card from the front of the rack.
- Easy to Setup: Just use two included thumbscrews to mount the rackmount, which adopts a screw-in design, which helps you install and replace quickly and easily, no tools needed!
- Applications: This is a hardware solution to get ingenious use of the Raspberry Pi, with this kit and open source software OpenMediaVault, you can use the Pi as a NAS Server, Surveillance station, or even a Web server.
- Optional accessories: Single mounting bracket: B09GFQLPTY; Micro SD card extension adapter ASIN: B09CKRDFTH. I/O Panel: B09FXRQPFM
NGINX can accept HTTPS and proxy the request onward, but HTTPS support depends on the installed build. NGINX documents that its SSL module requires OpenSSL and must be enabled in the build configuration; check the NGINX SSL module documentation and your server’s actual version and build.
Pay attention to the upstream Host header if the application uses host-based routing. Set forwarded headers deliberately as well: applications should trust client-IP or proxy headers only from known proxy infrastructure, not arbitrary incoming clients. For streaming or long-lived connections, check the application’s needs against NGINX timeout and buffering behavior; the basic tunnel example does not define production settings for those cases.
Rank #4
- [ULTIMATE RASPBERRY PI 5 CASE & MINI PC] - Unlock the full potential of your Raspberry Pi 5 with the Pironman 5-MAX — the most advanced Raspberry Pi 5 Case for power users. This high-performance Raspberry Pi 5 Cooling Case features dual NVMe M.2 slots with RAID 0/1 support, AI accelerator compatibility ( e.g. Hailo-8l M.2 AI), a PCIe Gen2 switch, a PWM tower cooler + dual RGB fans and a smart OLED display. With its dual transparent panels and optimized cable management (including full-size HDMI), it’s the ideal Raspberry Pi 5 Enclosure for building a high-speed NAS, AI edge computing device, or Home Assistant hub. (Raspberry Pi NOT Included)
- [DUAL NVMe M.2 SLITS & NAS RAID SUPPORT] - Supercharge your storage with the best Raspberry Pi 5 NVMe Case solution. Featuring two expandable NVMe M.2 slots (2230-2280) powered by a built-in PCIe Gen2 switch, this Raspberry Pi 5 NAS Case supports RAID 0/1 for ultra-fast data setups. Whether you're using a high-speed NVMe SSD or a Hailo-8L AI accelerator, Pironman 5-MAX delivers the ultimate performance boost for advanced Raspberry Pi 5 AI applications and edge computing
- [ADVANCED COOLING SYSTEM] - Engineered for high-performance builds, Pironman 5-MAX features a powerful tower cooler, one PWM fan, and dual RGB fans for enhanced airflow. The dual transparent panel design improves ventilation while showcasing vibrant RGB lighting. Ideal for cooling both the Raspberry Pi 5 and dual NVMe SSDs or AI accelerators like Hailo-8L, it ensures stable operation under heavy workloads with low noise and long-term durability
- [SMART OLED DISPLAY WITH VIBRATION WAKE-UP] - Pironman 5-MAX features a 0.96" OLED screen that delivers real-time system insights including CPU usage, memory, temperature, IP address, and disk status. With customizable display options and auto sleep mode, the screen can be instantly reactivated by a light tap thanks to the built-in vibration sensor—offering a smarter and more interactive experience
- [ENHANCED FUNCTIONALITY] - Pironman 5-MAX empowers your Raspberry Pi 5 with advanced features like safe shutdown via a metal power button, customizable RGB lighting, dual full-size HDMI ports, vibration-triggered OLED wake-up, and an external GPIO extender. It also includes RTC battery support for timekeeping and seamless Home Assistant integration. With detailed guides, online tutorials, and full technical support from SunFounder, setup and use are effortless and worry-free
Protect the application, not just the URL
A tunnel makes the local service reachable by people who can access its public address. A hard-to-guess URL is not reliable access control. The frp documentation states, “Anyone who can guess your tunnel URL can access your local web server unless you protect it with a password.” Apply the same security principle to an SSH-and-NGINX setup.
- Use the application’s authentication or suitable proxy-level access controls.
- Expose only the intended service and keep credentials and other secrets out of public URLs.
- Configure trusted-proxy handling so spoofed forwarding headers cannot be mistaken for verified client identity.
- For frp’s SSH Tunnel Gateway specifically, configure a token: its documentation warns that the minimal setup does not authenticate SSH connections.
See the frp project documentation for its tunnel security guidance. The exact controls available depend on the application, proxy configuration, and tunnel implementation.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choose between OpenSSH, frp, and a hosted tunnel
These options differ mainly in who operates the public endpoint and how much routing and security configuration you manage. There are no comparable performance measurements in the cited sources, so speed or reliability should not be inferred from this comparison.
| Approach | Control and operating work | Infrastructure and routing | Security and dependency |
|---|---|---|---|
| OpenSSH plus NGINX | You operate the relay server and configure SSH, NGINX, DNS, TLS, access controls, and maintenance. | Requires a public server, domain/DNS control, and NGINX routing. Suitable when you want to configure the pieces yourself. | Secure the app and proxy; verify SSH forwarding policy, headers, and certificate coverage. No hosted tunnel provider is required. |
| frp with SSH Tunnel Gateway | Self-hostable project with additional proxy features and configuration to manage. | Supports SSH-based TCP and HTTP proxy modes; consult the project documentation for current configuration and version-specific details. The SSH Tunnel Gateway was added in v0.53.0. | Pay particular attention to its token/authentication configuration; a tunnel URL by itself does not protect the service. |
| Hosted tunnel such as ngrok | The provider operates the cloud service, reducing the infrastructure the user must run. | The vendor describes an outbound local-agent connection to its service, avoiding the need for users to open ports, provision TLS certificates, or operate their own reverse proxy. | Relies on the hosted provider and its service. The description is vendor-provided, not an independent performance comparison. |
Choose OpenSSH plus NGINX when you already have a public server and want direct control of routing and TLS. Consider frp when its additional proxy modes fit your requirements and you are prepared to configure its authentication. A hosted tunnel shifts more infrastructure work to a provider, but also makes the service dependent on that provider.
Verify the deployment for your environment
The example establishes a pattern, not a complete recipe for every Linux distribution, SSH version, NGINX build, application, or threat model. Before sharing a URL, check that the SSH server permits remote forwarding, the allocated port is reachable as intended, wildcard DNS resolves to the public server, the certificate covers the requested hostname, and NGINX sends the request to the correct local port. Then test authentication, host routing, client-IP handling, and any streaming or long-lived behavior your application depends on.
Recommended Free Tools
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

