This machineEvery page

The relay

panel-relay runs on a VPS — a small rented server with a public address. Panels connect out to it, so nothing is opened at home, and it passes on connections it cannot read:

  • From outside: a browser asking for a panel's name reaches that panel, if its From outside is on. The connection stays encrypted between the browser and the panel.
  • Between places: panels that joined the same relay find and pair with each other as on one network.

One relay serves several households, kept apart in groups.

What you need

  • A VPS running Debian, with a public address and port 443 free.
  • A domain at Cloudflare, and an API token that may edit its DNS. Cloudflare's free plan is enough. Cloudflare is the relay's DNS only: it has no server to run the relay on, and its proxy (the orange cloud) would end the encrypted connection the relay passes on, so the relay keeps its records DNS only.

Where to run it

There is no free VPS in Europe with a public IPv4 address of its own that stays free. The free ones are trials (AWS's ends after six months), in the US only (Google's), or share one address among many machines, which a relay cannot work behind. A small paid one costs about as much as a coffee a month. Two we know work, then what to look for in any other.

Hetzner Cloud

About €6 a month, with its IPv4 address and 20 TB of traffic, in Germany or Finland.

  1. In the Cloud Console, open a project and choose Add Server.
  2. Location: Falkenstein, Nuremberg or Helsinki — nearest home.
  3. Image: Debian, the newest.
  4. Type: shared vCPU, the smallest — CX23 (x86), or CAX11 (Arm) when the CX is not to be had. The relay runs on both.
  5. Networking: Public IPv4 on. IPv6 too, if you like; the installer asks for it.
  6. SSH key: yours, so you can sign in.
  7. Create. A server with no firewall attached takes every port; if you attach one, allow TCP 443 in (and 22, for you).

Then sign in with ssh root@<its address> and install as below.

Scaleway

About €5 a month for Stardust, of which most is the IPv4 address, in Paris or Amsterdam. Stardust is often sold out; the next size up (DEV1-S) costs about twice that.

  1. In the console, Instances, Create Instance.
  2. Availability zone: Amsterdam or Paris — nearest home.
  3. Type: STARDUST1-S (under Learning), or DEV1-S.
  4. Image: Debian, the newest. A 10 GB volume is plenty.
  5. Public IPv4: on.
  6. Your SSH key, and Create Instance.
  7. Security groups: the default one lets everything in. If yours drops what comes in, add a rule for TCP 443 in.

Sign in with ssh root@<its address> and install as below.

Any other

  • A public IPv4 address of its own. Not IPv6 alone (a phone on a network without IPv6 could not reach it), and not a "NAT VPS" sharing an address. Behind the provider's own address translation is fine as long as port 443 comes to the machine: the installer then has no address to suggest, and you type the one the console shows.
  • Debian, on amd64 or arm64. The smallest machine is enough: one core, 512 MB to 1 GB of memory, 10 GB of disk.
  • Traffic: everything from outside passes through it — a film watched from away is its size again. Look for a terabyte or more a month, or a price per gigabyte you can live with.
  • Port 443 open at the provider's firewall or security group, and on the machine if it has one (ufw allow 443/tcp). Port 80 is not needed: the certificate is proved through Cloudflare's DNS.
  • Near home: every page from outside goes there and back.
  • That stays: a free tier that ends in a year, or credits that run out, take the relay with them.

Installing

Download panel-relay-<version>.tar.gz from the download page. On the VPS:

tar xzf panel-relay-<version>.tar.gz
cd panel-relay-<version>
sudo sh install.sh

It asks for the relay's name (in your Cloudflare zone), its public address, an email and the token, gets its certificate, and prints a join code.

Joining a panel

On the panel: give it a name first (Maintenance, Its name), then Maintenance, Relay, and type the join code. It stays connected, and the row says whether it is, and why not.

From outside

Off until you switch it on, on the panel's Relay row. The relay then points the panel's name at itself, and passes a browser asking for it on to the panel. At home the name keeps pointing at home.

From outside, signing in needs a second factor. An account without one, or a phone paired without one, is refused there and keeps working at home. The Relay row names the accounts that have none.

Against guessing: five failed sign-ins from outside lock signing in from outside for a quarter of an hour, never at home. Ten failures in an hour from one address and the relay drops that address — an hour, doubling up to a day.

Several households

panel-relay group add smith "The Smiths"
panel-relay code smith
panel-relay domain add smith.nl

A panel sees and reaches only its own group's. Each domain the panels are named in has its own token. panel-relay list says who is connected now. See panel-relay(8) for everything it does.