Cloudflare Tunnel

无法进行端口转发时,通过 Cloudflare Tunnel 暴露 agent 端口。免费,使用你自己的域名时地址固定。

本页为译文。如与英文版不一致,以英文版为准。 English

适用情况:你不能或不想做端口转发,而电脑可以运行 cloudflared。不适用情况:你希望连接路径上完全没有第三方服务(请使用端口转发),或者电脑本身经常离线。

电脑运行 cloudflared,与 Cloudflare 保持一条出站连接。手机连接隧道的公网 HTTPS 地址,Cloudflare 把 WebSocket 转交给 agent 端口。TLS 在 Cloudflare 终止,但其中的 Droidline 数据行仍然保持端到端加密。

先用快速隧道试试

快速隧道不需要账户。每次 cloudflared 重启,它的地址都会改变,所以只用来测试。

cloudflared tunnel --url http://localhost:8779

它会打印一个类似 https://words-words.trycloudflare.com 的地址。用 wss 协议和 /agent 路径把它加入 config.toml:

[remote]
addresses = ["wss://words-words.trycloudflare.com/agent"]

重启 droidline serve,然后配对一部手机,或者让已配对的手机在 Wi-Fi 下连接一次。

用你的域名获得固定地址

需要一个免费的 Cloudflare 账户,以及一个托管在 Cloudflare 上的域名:

cloudflared tunnel login
cloudflared tunnel create droidline
cloudflared tunnel route dns droidline droid.example.com
cloudflared tunnel run --url http://localhost:8779 droidline
[remote]
addresses = ["wss://droid.example.com/agent"]

把 cloudflared 安装为服务,让隧道随电脑一起启动;Cloudflare 的文档介绍了各个操作系统上的做法。

检查

curl https://droid.example.com/healthz 应当输出 ok。在一部关闭了 Wi-Fi 的手机上,droidline devices 会显示路由为 tunnel。