Cloudflare Tunnel

Expose the agent port through Cloudflare Tunnel when you cannot forward ports. Free, with a fixed address when you use your own domain.

Fits when you cannot or do not want to forward ports, and the PC can run cloudflared. Does not fit when you want no third-party service in the path at all (use port forwarding), or the PC itself is offline often.

The PC runs cloudflared, which keeps an outbound connection to Cloudflare. Phones connect to the tunnel's public HTTPS address, and Cloudflare passes the WebSocket through to the agent port. Cloudflare terminates TLS, but the Droidline lines inside stay end-to-end encrypted.

Try it with a quick tunnel

A quick tunnel needs no account. Its address changes every time cloudflared restarts, so use it to test.

cloudflared tunnel --url http://localhost:8779

It prints an address such as https://words-words.trycloudflare.com. Add it to config.toml with the wss scheme and the /agent path:

[remote]
addresses = ["wss://words-words.trycloudflare.com/agent"]

Restart droidline serve, then pair a phone or let a paired one connect on Wi-Fi once.

A fixed address with your domain

With a free Cloudflare account and a domain on Cloudflare:

cloudflared tunnel login
cloudflared tunnel create droidline
cloudflared tunnel route dns droidline droid.example.com
cloudflared tunnel run --url http://localhost:8779 droidline
[remote]
addresses = ["wss://droid.example.com/agent"]

Install cloudflared as a service so the tunnel starts with the PC; Cloudflare's documentation covers each operating system.

Check it

curl https://droid.example.com/healthz should print ok. On a phone with Wi-Fi off, droidline devices shows the route tunnel.