Port forwarding
Forward one TCP port on your router to the PC, and phones connect to your public address over TLS, pinned to the PC's own certificate.
Fits when you can change your router's settings and your internet connection has a public IPv4 address. Does not fit when your provider puts you behind carrier-grade NAT (the router's WAN address starts with 100.64 to 100.127, or differs from what an IP lookup site shows), or you cannot open ports at work.
Set it up
-
Give the PC a fixed address on your network (a DHCP reservation in the router).
-
In the router, forward TCP 8779 from the internet to the PC's address, port 8779.
-
Find your public address. If it changes from time to time, set up a dynamic DNS name with your router or a DDNS service, and use that name below.
-
Tell the server about the address in
config.toml(droidline doctorprints where the file is):[remote] addresses = ["tls://203.0.113.5:8779"] # or "tls://home.example.net:8779" -
Restart
droidline serve. -
Pair new phones with
droidline pair. Phones that are already paired pick up the address the next time they connect over Wi-Fi.
Why TLS and a fingerprint
On this route the phone connects over TLS to the PC's own self-signed certificate. The pairing QR code includes the certificate's SHA-256 fingerprint, so the phone checks it without any certificate authority, and a lookalike server on the internet is refused. Inside TLS the same end-to-end encryption runs as on every other route.
The certificate is created on first start and kept in the server's folder (tls.crt, with its key in the secret store). If you delete it, a new one is made and phones must pair again.
Check from outside
Turn off Wi-Fi on a paired phone and watch droidline devices: the route should change to direct within a few seconds.