frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Show HN: Gopher – open-source self-hosted Cloudflare Tunnel alternative

https://gopherden.org
2•smalex-z•50m ago

Comments

smalex-z•50m ago
Gopher is a self-hosted, open-source version of Cloudflare Tunnel. It turns one public IP into as many as 65k public services by using L4 tunnels from your machines to the edge, rather than traditional L3 routing.

  photos.yourdomain.com → router.yourdomain.com:1024 →Immich on home NAS (192.168.1.50:2283)
  lab.yourdomain.com → router.yourdomain.com:1025 → Jupyter on uni wifi (10.0.10.34:8888)
  vault.yourdomain.com → router.yourdomain.com:1026  → Bitwarden(192.168.56.8:8000)
---

Hi HN, I’m Alex. I built Gopher over the last seven months.

Background: Pre-2025, UCLA used to give every device and VM on eduroam a public IPv4 address (perks of “inventing the internet”, i guess). Incredibly insecure, but as a freshman in college getting into infrastructure and just having bought my first homelab node, it was an absolute blessing.

However, in 2025, they moved to NAT overnight. Instantly all of my servers I had been running for myself, my research lab, and our ACM chapter lost external access. Now the default answer would have been Cloudflare tunnels, but not only was our DNS not on CF, doing so would have involved letting Cloudflare terminate your TLS and see every byte of our traffic in plaintext, which felt like it was defeating the point of self hosting.

Hence, I built Gopher. It’s a single Go binary on a box with a public IP (ideally self-hosted, but realistically a VPS - mine’s on OCI). Origin servers dial outbound to the edge over rathole with Noise transport, so even though we have zero control over the routers (we couldn’t even get a private IP subnet… let alone public IP), we can expose service without an open port or static IP. I mean if you really tried, you could run a server on the coffee shop wifi down the street - not that I would recommend you attempt to.

Caddy on the edge handles TLS termination and L7 subdomain routing. Because the edge decrypts TLS, it can actually filter requests, there's a JS proof-of-work challenge with HMAC-signed session cookies that drop scrapers before they hit the origin, plus password-gated routes. There’s so many possibilities here; the next logical step would be caching (think CDN).

A big distinction from the self-hosted tunneling space (Tailscale, Netbird, etc) is that Gopher is targeted for public services, not private access.This is for things like a membership portal, where users can’t be expected to install a VPN just to access it - it’s zero client configuration access.

Today is the first stable release (v0.1.0). Now to be candid, while it’s been running our ACM chapter’s infra for 6 months (25 services, no incidents), I wouldn’t put it behind an SLA yet. Frankly, I’m the only contributor, and something of this scope needs more eyes and deployments before it has reached that level.

Video Demo: https://youtu.be/iIMS9qrRxow?si=1JsQ6I8fSeaxJ_Ip Video Install: https://youtu.be/KYpr61Ak9FE?si=Ti-7hfj9vcxjre7e GitHub: https://github.com/smalex-z/gopher Website: https://gopherden.org

Camerabuds

https://www.sandbar.com/learning-by-doing
1•minafahmi•38s ago•0 comments

Foreign business owners leave Japan in droves under tighter visa rules

https://asia.nikkei.com/spotlight/japan-immigration/foreign-business-owners-leave-japan-in-droves...
1•mikhael•1m ago•0 comments

Slope over Y Intercept

https://mattrickard.com/hire-slope-not-intercept
1•iacguy•2m ago•0 comments

Claude config-drift-checker: CI for your Claude.md, skills and hooks

https://github.com/jameskomo/config-drift-checker.
1•smartwordworld•3m ago•0 comments

Why do so many tools have JSON config files?

https://textlog.cc/post/895
1•stagas•5m ago•0 comments

Show HN: Codeknow – Architecture health scores for any codebase, no LLM needed

https://github.com/asalsali/codeknow
1•alexjsalsali•7m ago•0 comments

A Million Falcons Went Missing. Here’s How They Were Found

https://www.nationalgeographic.com/animals/article/falcons-migration-angola-falcopolis
3•bryanrasmussen•9m ago•0 comments

What Makes LLM Tokenization Slow?

https://healeycodes.com/what-makes-llm-tokenization-slow
1•ibobev•10m ago•0 comments

Google Donates Longfellow ZKP Library to Linux Foundation Europe

https://blog.google/products-and-platforms/platforms/google-pay/zero-knowledge-proof-library-linu...
1•pentagrama•11m ago•0 comments

Detecting LLMs

https://www.usebox.net/jjm/blog/detecting-llms/
1•speckx•11m ago•0 comments

The companies powering AI are outperforming those building it

https://www.home.saxo/content/articles/commodities/the-companies-powering-ai-are-outperforming-th...
1•toomuchtodo•14m ago•0 comments

Afterword (game): for each adjective, type the noun most likely to follow it

https://afterword.exe.xyz/
1•sea-gold•14m ago•0 comments

No AI until high school:NYC schools announce major classroom technology overhaul

https://abc7ny.com/post/new-york-city-public-schools-banning-ai-use-middle-school-year/19778716/
3•thunderbong•15m ago•0 comments

OWASP Top for Agentic Applications – The Benchmark for Agentic Security

https://genai.owasp.org/2025/12/09/owasp-top-10-for-agentic-applications-the-benchmark-for-agenti...
1•Bluestein•15m ago•0 comments

Meta bricked the cameras on its AI glasses

https://www.businessinsider.com/meta-glasses-camera-disabled-tampering-recording-light-update-2026-9
3•simpleintheory•15m ago•0 comments

Strands Agents SDK

https://strandsagents.com/
1•taylorbuley•15m ago•0 comments

This Fence Has No Farmer (Chesterton's Fence and AI-Generated Code)

https://adamgreenough.net/blog/this-fence-has-no-farmer/
2•xadz•17m ago•0 comments

The Overton Window of Food

https://think-twice.me/?p=116
1•zug_zug•17m ago•0 comments

I Don't Think I Can Stay in Tech

https://coyotetracks.org/blog/stay-in-tech/
3•speckx•17m ago•0 comments

Ask HN: Did HN get much slower recently?

2•progbits•21m ago•2 comments

Google's Fairwind Program: Cyber defense tools for trusted partners

https://blog.google/innovation-and-ai/technology/safety-security/fairwind-program/
1•xnx•21m ago•0 comments

Electronic skin for prosthetics to sense temperature and pressure

https://news.wsu.edu/press-release/2026/08/20/researchers-develop-electronic-skin-for-prosthetics...
1•gmays•22m ago•0 comments

Google escapes ad tech breakup in third Big Tech antitrust loss for US

https://www.reuters.com/legal/litigation/google-defeats-us-bid-force-ad-tech-sale-2026-09-02/
3•tartoran•22m ago•0 comments

Writing. I want to do it, badly. I just don't want to be bad at it

https://textlog.cc/post/2515
1•stagas•22m ago•0 comments

AI is stopping startups from completing puberty

https://ashley.rolfmore.com/ai-is-stopping-startups-from-completing-puberty/
3•mooreds•22m ago•0 comments

Throwing rubbish in a landfill is (usually) better for the environment

https://twitter.com/s8mb/status/2094807676425302386
1•tosh•22m ago•0 comments

Marie Curie

https://en.wikipedia.org/wiki/Marie_Curie
2•chistev•22m ago•0 comments

Running Docker on Vercel

https://vercel.com/kb/guide/docker
1•jcbhmr•23m ago•0 comments

Zuzai, a new word, indicates the absence of AI

https://zuzai.org/
2•birdculture•23m ago•0 comments

Do No Harm in the Age of the Black Box: A Hippocratic Oath for AI Practitioners

https://www.wilmott.com/do-no-harm-in-the-age-of-the-black-box-a-hippocratic-oath-for-ai-practiti...
2•Bluestein•23m ago•0 comments