EphemNet reverse-tunnel agent

Make any host reachable, even with no public IP

A single static binary. Run it on a host behind NAT — home network, anywhere with no port-forwarding at all — to make it reachable through EphemNet's relay mode. No install process, no root required.

What it does

An outbound-only tunnel, nothing to configure on your router

ephemnet-agent dials out to the relay over TLS — it looks like a normal outbound HTTPS connection, so it passes through home firewalls and NAT without any port-forwarding or router configuration. Once registered, every inbound connection for your domain gets multiplexed over that one connection and forwarded to a local port you choose.

Never decrypted in transit

The relay routes by TLS SNI and forwards the still-encrypted bytes straight through. TLS terminates at your own server, not at the relay.

Auto-reconnect

If the connection drops for any reason, the agent retries automatically — no manual restart needed for a transient network blip.

Get it

Download

PlatformDownload
Linux (amd64)release builds coming soon
Linux (arm64)release builds coming soon
macOSrelease builds coming soon
Build from sourcego build ./cmd/ephemnet-agent
Quickstart

Point it at your domain

Once you have a domain in relay mode and its token:

ephemnet-agent \
  -relay-addr relay.ephemnet.cinderapps.org:7000 \
  -domain yourhost.example.com \
  -token <your domain's relay token> \
  -local-addr 127.0.0.1:443

Add -status-addr 127.0.0.1:8093 for a local read-only debugging status page (connection state, uptime, bytes transferred) — see ephemnet-agent -h for every flag.