deploymate

Optional

No open ports? Use a tunnel

DeployMate normally serves the internet directly: ports 80 and 443 open, a domain pointing at the server. That is the simplest setup, and the quickstart uses it. This page is for when you can't or don't want to do that — a machine at home or in an office, an internet provider that blocks the ports or shares one address between customers, or a router you can't configure.

A tunnel flips the direction. A small program on your server connects out to a provider, and visitors reach your server through it. Nothing has to be opened, forwarded or made public. Cloudflare Tunnel is one such service and has a free plan; the steps below use it. It is a convenience, not part of DeployMate.

What you needA free Cloudflare account and a domain whose DNS is on Cloudflare (you can register one there or move an existing one). The server needs only an ordinary outbound internet connection.

1. Create the tunnel

  1. In the Cloudflare dashboard open Zero Trust (it may be named "Cloudflare One"), then Networks → Tunnels → Create a tunnel.
  2. Choose Cloudflared, give it a name, and pick the operating system (Debian/Ubuntu) and CPU of your server.
  3. Cloudflare shows an install command that contains a long token. Run it on the server. Keep the token private: it lets anyone run a tunnel into your account. After a minute the tunnel shows Healthy.

2. Point names at DeployMate

In the tunnel's Public hostname tab, add one entry per name you want reachable:

ForTypeURLNotes
An app's domain, e.g. app.example.comHTTPSlocalhost:443Turn on No TLS Verify (see below). Also add the same domain to the app in DeployMate and redeploy it.
The dashboard, e.g. dash.example.comHTTPlocalhost:8080Protect it — see step 3.
SSH, e.g. ssh.example.comSSHlocalhost:22Optional: lets you log in from anywhere. Needs cloudflared on your own computer.

Cloudflare creates the DNS records for you. Apps go to port 443 because DeployMate's proxy (Traefik) redirects plain HTTP to HTTPS; No TLS Verify tells the tunnel not to insist on a certificate the proxy hasn't obtained, since Cloudflare serves the real certificate to your visitors.

3. Protect the dashboard

The dashboard can deploy to and control your server, so don't leave it behind a single password. In Zero Trust open Access → Applications → Add → Self-hosted, enter the dashboard's hostname, and add a policy that allows only your email address. You then sign in twice — Cloudflare first, then DeployMate — which is what you want. Leave the Access policy off hostnames that are meant to be public.

One exception. GitHub, GitLab and Gitea can't sign in to Access, so a webhook sent to the dashboard's address would be refused. Add a second Access application for the same hostname with the path hooks/* and a Bypass policy. Only that path is opened, and every webhook is still checked against its secret. See Deploy on every push.

4. Optional: SSH through the tunnel

With the SSH hostname in place, install cloudflared on your own computer and add this to ~/.ssh/config:

Host dm-server
  HostName ssh.example.com
  User your-user
  ProxyCommand cloudflared access ssh --hostname %h

then ssh dm-server works from anywhere. Use key-based login, and consider an Access policy on this hostname too.

Things to know

  • Certificate warnings in Traefik's log are expected. Traefik tries to obtain its own Let's Encrypt certificate, which needs port 80 reachable from the internet; through a tunnel it can't, so it logs a failure and keeps going. Visitors still get a valid certificate from Cloudflare.
  • One hostname per domain. Each domain you attach to an app needs its own public hostname on the tunnel.
  • It adds a dependency. If Cloudflare or the connector is down, so is access. The server and its apps keep running, and you can still reach it on your local network.
  • It isn't the only way. A router port-forward, a VPS in front, or another tunnel product also works. DeployMate only needs requests for your domains to arrive at the server's ports 80/443.