10 ms·
Pgrok – Poor Man’s Ngrok
- joe2010xtmf 4y agoA multi-tenant HTTP reverse tunnel solution through SSH remote port forwarding.
- ytwySXpMbS 4y agoIn a couple places grok is typoed as gork
- joe2010xtmf 4y agoThanks! will fix!
- groestl 4y agoI was under the impression that pgrok was unmaintained until now, to the extend that I was looking for alternatives. Did I miss something?
- prettyStandard 4y agoI'm on mobile so it's hard browse the repo, but it looks like the initial commit was 4 days ago. So I think this would be a different project with the same name. https://github.com/pgrok/pgrok/commit/1f57713c323ea494780590fac55b5020b31918b7 https://github.com/pgrok/pgrok/commit/1f57713c323ea494780590...
- groestl 4y agoI see.. it's bit confusing, since there's an existing project in the same space (https://github.com/jerson/pgrok https://github.com/jerson/pgrok). It's even linked on the project above via the awesome https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling list, I don't know why this is necessary.
- jeroenhd 4y agoFor one, this seems to integrate with OIDC setups, which makes it easier to use it with existing company credentials (rather than manage accounts for every tool you use). The naming conflict is unfortunate. At least the old repository is archived, but it'd still be better if this tool could be renamed IMO, especially since it's so new.
- Bluecobra 4y ago> This is intended for small teams that need to expose the local development environment to the public internet As someone who has to manage enterprise firewalls, this is a nightmare from a security perspective. I’m more than happy to host some project in a DMZ. I have already had some devs skirt our security policies with ngrok rather than simply talk to us about their needs. I can’t say I’m a fan of punching permanent holes into a firewall like this.
- mukesh610 4y agoNot exactly sure how streamlined your security process is, but for some orgs it is a red tape roller coaster to even get one TCP port open. Anyways, you could also block all traffic to ngrok servers just to ensure your Dev teams aren't skirting around your firewall.
- IceWreck 4y agoNgrok is just one company tho, there are thousands of ways. Wireguard or nebula can be selfhosted and another server with an actual port open will forward traffic. People can use SSH's reverse port forwarding too. Or you can use cloudflared or another one of ngrok's competitors.
- Bluecobra 4y agoYeah I get it, but everyone needs to be responsible for security as well. Look what happened with Lastpass. I can totally see someone doing something silly like exposing a device with default creds like a MySQL db on a production box, then forgetting about it and getting a new job a year later. I do block proxies like this, but it’s hard to block every little thing.
- alexnewman 4y agoI remember when I believed in bastions and DMZ. Many companies have given up on this due to the fact that it can only be enforced by policy and not by tech
- 4y ago
- stavros 4y agoWhy do projects that are meant to be lightweight use Postgres instead of SQLite? The latter is much easier to deploy (you, well, just don't need to), and does 99% of what anyone needs, and definitely 100% of what small projects need.
- capableweb 4y agoCargo culting. If you never used SQLite, anytime you need a database you use whatever you've used before without shopping around or considering if what you're about to use is right.
- stavros 4y agoI guess... That's too bad, this project looks great but having to install/connect Postgres is putting me off installing it.
- capableweb 4y agoYeah, in better news though, it seems to be using gorm which has different drivers available (https://gorm.io/docs/connecting_to_the_database.html https://gorm.io/docs/connecting_to_the_database.html), SQLite being one of them. So unless they are doing something postgres specific, should be relatively easy to switch it out.
- PLG88 4y agoIf you want a similar project which 'just works' then consider using zrok. Its fully opensource which you can self-host or use the free hosted version - https://zrok.io/ https://zrok.io/
- pizza 4y agoHang on a second- this project looks to be assuming that the db will be remote and over the internet. Even the SQLite official document recommends people to use PostresSQL in that scenario [0]: >Generally, if your data is separated from the application by a network, you want to use a client/server database. This is due to the fact that the database engine acts as a bandwidth-reducing filter on the database traffic ... Use a client/server database engine. PostgreSQL is an excellent choice. [0] https://www.sqlite.org/useovernet.html https://www.sqlite.org/useovernet.html
- nickjj 4y agoHas anyone tried this for a free ngrok alternative that works with HTTPS, doesn't require setting up a server and has no rate limit within reason? https://developers.cloudflare.com/pages/how-to/preview-with-cloudflare-tunnel https://developers.cloudflare.com/pages/how-to/preview-with-... Based on the page it looks like you can install Cloudflare's CLI and then run `cloudflared tunnel --url http://localhost:3000 http://localhost:3000`, and you'll get back a URL to visit such as https://seasonal-deck-organisms-sf.trycloudflare.com https://seasonal-deck-organisms-sf.trycloudflare.com. Looks like it supports being able to associate it with a custom domain too so you can have repeatable URLs.
- Hawxy 4y agoYep! We use this to test our webhook integrations locally. Works great.
- capableweb 4y agoI guess the biggest (and only?) drawback is that it (presumably) requires a Cloudflare account to use. So if you're living in Iran, Syria, Lebanon (and some more) you're out of luck as you cannot have an account with Cloudflare then. Otherwise it looks like a nice offering for sure.
- radec 4y agoIt doesn't appear to require an account. I just gave it a try, installed the deb, typed that one line command and it just worked. No idea if it would work in those countries though, I only tried it in a US location.
- orf 4y agoYes, I use this a lot and it’s fantastic. Works pretty flawlessly, is fast and super simple to set up.
- schemescape 4y agoLast time I checked, if you want to use a custom domain, your domain needed to be managed by Cloudflare.
- dr_faustus 4y agoWe’ve used https://github.com/antoniomika/sish https://github.com/antoniomika/sish quite successfully. It‘s very easy to setup with docker compose and even supports letsencrypt wildcard certificates.
- antoniomika 4y agoThanks for posting! I’d suggest this to anyone that wants a stateless setup method which uses standard SSH key/password auth. sish also has support for internal tunnels (hidden from the world and accessible with local/remote SSH forwards), SNI tunnels (zero trust TLS tunnels), TCP, and of course HTTP(S)/WS. Also does request inspection ala actual ngrok :) Disclaimer: I’m the author and have done tunneling for years
- deleted 4y ago[deleted]
- Eun 4y agoI don’t see a usecase where a non dev should expose some local resource to the internet. These people don’t run local webservers, nor know how they work. ngrok is a developer tool. I don’t see why marketing a dev tool to non devs is a good idea, maybe somebody can explain?
- remexre 4y agoWhat makes this seem like a non-developer tool? You need a server you control, you need to mess with YAML files, "configure Caddy" is one step that's assumed to be easy, etc.
- Eun 4y agoIt says literally: > Not everyone is a dev who knows about server operations. For people working as community managers, sales, and PMs, booting up something locally could already be a stretch and requiring them to understand how to set up and fix server problems is a waste of team's productivity.
- remexre 4y agoOh, I read that as "you can send the links to community managers, sales, and PMs rather than making them run the app locally," since that's like, the main usecase.
- Eun 4y agoAh could also be, but the whole sentence was like this: > Why not just pick one from the Awesome Tunneling? Think broader. Not everyone is a dev… So I read this as targeting non devs. I think every other alternative from that list also supports common usable links.
- pcthrowaway 4y agoFrom their docs: Why? Stable subdomains and SSO are two things too expensive. Why not just pick one from the Awesome Tunneling? Think broader. Not everyone is a dev who knows about server operations. For people working as community managers, sales, and PMs, booting up something locally could already be a stretch and requiring them to understand how to set up and fix server problems is a waste of team's productivity. Copy, paste, and run is the best UX for everyone.
- Felminor 4y agoGreat thing about k8s: you can expose all your dev env needs super fast and easy. And adding a dex or so upfront is also super easy. If you are a small company and need this regularly try to take a look at managed k8s. It will be worth it
- johnstonnorth 4y agoDon’t think I’ve ever seen an alternative to ngrok that includes their “Inspection Interface” - that is such a useful feature for debugging.
- PLG88 4y agoI work on the open source OpenZiti project. We recently released zrok (https://zrok.io/ https://zrok.io/), we have Local Debugging Interface in the backlog - https://github.com/openziti/zrok/issues/73 https://github.com/openziti/zrok/issues/73.
- eliben 4y agoI recently wrote about how ngrok-like functionality is easily implemented in Go via SSH port forwarding: https://eli.thegreenplace.net/2022/ssh-port-forwarding-with-go/ https://eli.thegreenplace.net/2022/ssh-port-forwarding-with-...
- t43562 4y agoI find it quite amusing that I read the pgrok and ngrok websites (at least the front page) and cannot understand what the hell either of them do. It's like they can do almost anything...what exactly? .... well whatever you can think of.....er like what? You can open localhost to the internet.......?????????? Sorry? Anyhow if anyone would care to put me out of my misery by explaining a bit I'd be grateful.
- asalahli 4y agoWelcome to Zombo.com :)
- shortrounddev 4y agoProxies HTTP requests from a temporary server with a public domain record to a localhost server. Useful for some development environments, and also if you don't feel like dealing with networking in docker. At one company I worked at, we ran everything through vagrant and running ngrok was easier than a junior java engineer learning anything about networking.
- mfkp 4y agoLet's say you're running a local development server on localhost:3000 If you want to share this with someone not on your computer, it will proxy through a real domain name that someone else can access remotely.
- deleted 4y ago[deleted]
- ahzhou 4y agoWe use ngrok for testing OAuth2 handshakes on localhost.
- deleted 4y ago[deleted]
- bgpdude 4y agoAlso check out https://docs.border0.com/docs https://docs.border0.com/docs. Super easy to get going, and supports HTTP(s), SSH and Database protocols such as mysql and postgres. Ideal for private resources, as it has a nice policy to control who should have access to what, when and where. Finally you can use Google and Github for authentication.
- retrobox 4y agoI love seeing alternatives but one thing I really appreciate about ngrok is the web UI. The log of incoming requests, headers and payloads, is very helpful during development. Do any of these alternatives offer something similar? Or is there an additional tool that can be leveraged?
- PLG88 4y agoI work on the open source OpenZiti project. We recently released zrok (https://zrok.io/ https://zrok.io/), we have Local Debugging Interface in the backlog - https://github.com/openziti/zrok/issues/73 https://github.com/openziti/zrok/issues/73.
- 8n4vidtmkvmk 4y agoif you're already running nginx on a server somewhere, you can set up a subdomain to tunnel to localhost with no software to install. just a tiny bit of config. use just ssh on the client. i only use it to test callbacks but it can be shared too
- panzi 4y agoSince I don't need a lot of HTTPS development servers, but the few that I do need, need to have a fixed domain name, I simply configured nginx on one of our servers (not the production server, of course) to proxy to a localhost port and then do a SSH tunnel to that server and port from my development PC. Good enough for what I do. Though I should look into auto-ssh some day, because the SSH tunnel keeps dyeing.
- aussieguy1234 4y agoBy the sounds of it Ngroks pricing is out of control. They used to allow commerical use for individual developer subscriptions, why not now? I recently launched Tunnelmole, an open source alternative. You can just run the client and then you don't need to worry about NAT/CG-NAT, port forwarding or running your own server unless you want to self host, which is possible because the service layer is also open source. You can get it from https://github.com/robbie-cahill/tunnelmole-client https://github.com/robbie-cahill/tunnelmole-client