9 ms·
Show HN: Local development with .local domains and HTTPS
Hi HN! I'm Jarek, and I've built this tool that allows publishing .local domains on the local network using mDNS.
It also has a reverse proxy that handles HTTPS termination and port forwarding.
I'm working on adding more features, like an index page with all available domains or allowing proxy redirects, so you could redirect from HTTP to HTTPS.
Let me know if you have any questions or feedback!
- manuelfcreis 3y agoReally like what this does and the look of it! Congrats
- jarekceborski 3y agoThanks, glad you find it useful!
- drekipus 3y agoIs this something like how ".local" is already a mDNS standard but OSX and android won't support it yet? (Unless they buy your app) I can already access "myserverhost.local" from everything but android and OSX. Windows and Linux work fine automatically.
- rascul 3y agoAndroid supports it now. https://source.android.com/docs/core/ota/modular-system/dns-resolver#mdns-local-resolution https://source.android.com/docs/core/ota/modular-system/dns-...
- j1elo 3y agoDo you mean that this issue report can now be considered as resolved? https://issuetracker.google.com/issues/140786115 https://issuetracker.google.com/issues/140786115 I'd love to update my notes if that's the case.
- rascul 3y agoI don't know anything more than the docs I linked to.
- j1elo 3y agoOk checked some info and, in summary: Your linked article (the official source from Google) states "November 2021" [1], which by date would correspond to API Level 32 aka. Android 12.1. Android 12.0 might also have the feature backported on some devices, according to some reports such as seen in the issue report for the feature [2]. Finally, the feature has apparently not been backported to Android 10 or 11, according to a blog post I found about this topic [3]. [1]: https://source.android.com/docs/core/ota/modular-system/dns-resolver#mdns-local-resolution https://source.android.com/docs/core/ota/modular-system/dns-... [2]: https://issuetracker.google.com/issues/140786115 https://issuetracker.google.com/issues/140786115 [3]: https://www.esper.io/blog/android-dessert-bites-26-mdns-local-47912385 https://www.esper.io/blog/android-dessert-bites-26-mdns-loca...
- wiredfool 3y agoIt’s been on osx since it saw called osx and not MacOS.
- WorldMaker 3y agoThe FAQ admits that it is just configuring mDNS advertisements.
- thenonameguy 3y agoThis looks really great! When do you expect to add Linux support? Until then, I'm using a devenv.sh Nix-based setup (without mDNS), with something like this: https://github.com/cachix/devenv/blob/main/examples/mkcert/devenv.nix https://github.com/cachix/devenv/blob/main/examples/mkcert/d...
- capableweb 3y agoLooks like an interesting project. What I guess is not really clear is why you'd want to do TLS for local only connections? Are the services published with the .local domain accessible from outside as well so it's like a ngrok alternative? I'm pretty sure I'm misunderstanding the value-add of having TLS for localhost connections...
- plorntus 3y agoCertain browser features/apis are only available when in a secure context https://www.digicert.com/blog/https-only-features-in-browsers https://www.digicert.com/blog/https-only-features-in-browser... so I imagine this might be a reason you would want it. That being said I don't know why you would pay for an application that does this but I guess I'm not the target market.
- ceejayoz 3y agoYep. A lot of OAuth integrations will refuse to work on HTTP, too. Some have a `localhost` exception to that restriction, but not all.
- lostmsu 3y agoThis long article helpfully forgets to mention, that localhost/loopback addresses are considered secure without https. https://developer.mozilla.org/en-US/docs/Web/Security/Secure_Contexts https://developer.mozilla.org/en-US/docs/Web/Security/Secure...
- WorldMaker 3y agoSome features have still moved to TLS-only even for localhost. "Considered secure" is somewhat orthogonal to "requires TLS". You can only use HTTP/2 with TLS, for instance, whether or not you are in a "secure context".
- mcny 3y ago> I'm pretty sure I'm misunderstanding the value-add of having TLS for localhost connections... It often feels like the noose is tightening tbh. There are things that contemporary "evergreen" web browsers just flat out refuse to do without https. I think this is where they document this... https://www.chromium.org/Home/chromium-security/prefer-secure-origins-for-powerful-new-features/ https://www.chromium.org/Home/chromium-security/prefer-secur... which I got from this stack overflow answer https://stackoverflow.com/a/34161385 https://stackoverflow.com/a/34161385
- mdev23 3y agois it secure?
- rickette 3y agoCan recommend https://github.com/FiloSottile/mkcert https://github.com/FiloSottile/mkcert for this purpose (local development certs).
- bsnnkv 3y agoI'm a big fan of mkcert for local HTTPS cert generation.
- bavell 3y agoI just setup a local https dev domain wildcard (*.internal) with mkcert and caddy a few days ago - working great on all my devices and only took a few hours to figure out and get working.
- francislavoie 3y agoFYI if you're using Caddy, you don't need mkcert. Caddy has smallstep built-in which does the same thing, automatically. If you're not using .local or .localhost, just add `tls internal` to your config to make Caddy issue certs using its local CA. Caddy attempts to auto-install its root CA cert, just like mkcert (almost identical code, in fact; see https://github.com/smallstep/truststore https://github.com/smallstep/truststore).
- redder23 3y agoI feels this is something that should NOT be a payable service at all. I am sure its not rocket science, not even Linux support? Probably some open source tools for this to set it up your self for free.
- rcarmo 3y agoThe mDNS broadcast thing is pretty easy, I've used pybonjour for that for a while. The SSL part, well, it's a bigger hassle.
- harrygeez 3y agoBigger yes but valuable knowledge for anyone. The good thing is once you understand it only takes little effort to repeat it.
- rcarmo 3y agoI automated that away a long time ago: https://github.com/piku/piku/blob/master/piku.py#L814 https://github.com/piku/piku/blob/master/piku.py#L814
- jasonlotito 3y agoI'm curious about the license requirements. Is it 1 license per install, or 1 per install that is currently serving? I have two devices, but I will never use them at the same time (and if I do by accident, I'd expect your software to stop working).
- jarekceborski 3y agoIt's perpetual license. So you can enter the license key on a new device and it will automatically deactivate previous device.
- francislavoie 3y agoYou can do this with Caddy already, with Automatic HTTPS. Caddy will automatically set up its own CA and use it to issue certs (using smallstep) with .local and .localhost domains. We don't do anything with mDNS though but we've thought about it; none of us use macs anymore but PRs are welcome to make that work. I don't have enough expertise with mDNS to confidently implement it myself, and especially less-so because the implementation would be different on every OS (needs build flags to change the implementation depending on the build target). And this would be free and open source, rather than this paid product.
- throwawaymobule 3y ago<hostname>.local is usually setup if you have an mDNS daemon running. I think Ubuntu does this ootb, and if you still have an old windows install, you may have a copy of 'bonjoir' that was bundled with iTunes. You could probably lean on existing software to do most of the work.
- francislavoie 3y agoI agree that reaching out to systemd-resolved on Linux and Bonjour on Mac/Windows is probably the way to go, but I don't have the time/energy to learn these APIs and test it right now, hence why I'm asking for help! :)
- WorldMaker 3y agoWindows has had built-in mDNS (and DNS-SD) support built-in since Windows 10, I wouldn't recommend using Bonjour on Windows today. That said, the tricky part to Windows' mDNS support is that the APIs to work with it are WinRT-only and you'll need a WinRT projection of one sort or another to use them.
- qbasic_forever 3y agoOn modern systemd-based Linux systems that use its systemd-resolved DNS resolver it automatically forwards all *.localhost traffic to your local host. It works great with caddy for local development and testing of services.
- waithuh 3y agoRisky target audience. Maybe useful for people that hop networks regularly.
- kohanz 3y agoWe use puma-dev for this https://github.com/puma/puma-dev https://github.com/puma/puma-dev
- Alifatisk 3y agoWow! Didn't know about this one.
- mijoharas 3y agoRegarding the certs. Does this do something special to trust the self-signed root certificate that you add? or do you need to manually trust it on any device that you use to connect to this? I assume that's the case, but want to check I understand correctly.
- jarekceborski 3y agoYou need to manually trust on each device. There is a button for that in the app, that shows the Trust certificate dialog. For other devices it quit easy, e.g. you can AirDrop RootCA.pem into the iPhone or iPad.
- EspressoGPT 3y ago> Forget editing /etc/hosts or typing 192.168.0.12! Instead, pay $19 (instead of $29!) excl. VAT for a service that does this for you! God damn, I hate this industry.
- raincole 3y agoWhen I read this comment I knew it must be targeting MacOS users. The only reason I clicked the link is to confirm my assumption. Edit: I'm not trying to shame MacOS users. I'm just saying that Linux and MacOS users (Windows users don't use /etc/hosts so out of discussion) have very different behaviour regarding paying for software.
- EspressoGPT 3y agoI mean, the creator's personal website exactly looks like the Apple website and he's selling clones of Apple wallpapers, too.
- louzell 3y agoWhy are you trying to dismiss this guy? I don't understand it. If you don't like the product or feel that $19 is too much money, then move along. God forbid someone tries to make a living by selling software. I've personally struggled to test https locally [1], and I'm sure others have too. The next time I have the problem, though, I'll save myself the configuration and spend $19. [1] https://www.louzell.com/notes/serve_https_on_localhost.html https://www.louzell.com/notes/serve_https_on_localhost.html
- deleted 3y ago[deleted]
- Zetice 3y agoThere is an /etc/hosts on Windows, just fyi.
- ninju 3y ago
- hobofan 3y agoOr you could just use Tailscale with their Tunnel feature, and you get most of those things with their free tier (up to 3 users with up to 100 devices) and at a cheaper per-user pricing after that. And it also works cross-platform.
- deleted 3y ago[deleted]
- a_imho 3y agoForget editing /etc/hosts Why?
- Thoeu388 3y agoLets introduce proprietary service with a payment plan. That will simplify things LOL. Just switch to Linux and you will never ever had to deal with this weird stuff agian!
- leonheld 3y agoJust to be fair: it seems it has no "payment plan", but a one-time payment.
- EspressoGPT 3y agoThat "one-time payment" will only give you updates for a year.
- j1elo 3y agoThis is my poor man's, do-it-yourself, LAN development with HTTPS method: https://doc-kurento.readthedocs.io/en/latest/knowledge/selfsigned_certs.html https://doc-kurento.readthedocs.io/en/latest/knowledge/selfs... Should probably be a blog post. Would be happy to get comments on improvements or updates to the explained process. For now, I already gathered that Android seems to have finally added mDNS resolution support, which is nice as a whole Note banner can then be removed from that page. I also took note that maybe the whole thing can be simplified greatly with Caddy, albeit I think that getting into explaining mkcert is useful for readers who are new to that stuff and don't know how to generate their own SSL certs (like myself a month before writing all that).
- mkl95 3y agoIsn't that just a sidecar? Maybe Kubernetes is hard enough that some engineers are willing to pay $19 to avoid using it.
- lapcat 3y agoThis submission violates the HN guidelines: "Please don't use HN primarily for promotion. It's ok to post your own stuff part of the time, but the primary use of the site should be for curiosity." https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html The https://news.ycombinator.com/user?id=jarekceborski https://news.ycombinator.com/user?id=jarekceborski account was created 1 day ago, the only submission is this one https://news.ycombinator.com/user?id=jarekceborski https://news.ycombinator.com/user?id=jarekceborski and the only comments are on this submission https://news.ycombinator.com/threads?id=jarekceborski https://news.ycombinator.com/threads?id=jarekceborski
- nathell 3y agoI’d give the OP the benefit of doubt. I’ve always read that rule as discouraging excessive self-promotion, not a ban on one-off ones, and I think that should apply even when that one-off happens to be the very first submission by the account in question.
- lapcat 3y agoI'm not saying that the account should be banned, or that self-promotion should never be allowed. Nonetheless, the account creation date and lack of other comments clearly shows that it was created for the purpose of selling the submitter's product. I think it's fair to flag this submission dead and then see what else the person does with their account, if anything.
- manuelmoreale 3y agoNot entirely sure why you're getting downvoted. One might disagree with the guidelines but since they clearly say that it's ok to post your work "part of the time", an account created only to post personal content is clrealy going against the spirit of the guidelines. Do I personally care? No. Am I bothered by the submission? Also no. Still, downvoting you doesn't seem all that fair since you do raise a valid point.
- ehPReth 3y agoAlso from those exact same guidelines: “Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data.”
- moondev 3y agofoo-192-168-1-1.traefik.me bar-192-168-1-1.traefik.me http://traefik.me/fullchain.pem http://traefik.me/fullchain.pem http://traefik.me/privkey.pem http://traefik.me/privkey.pem
- lxgr 3y agoThis is neat! However, given that allowing private IP resolution from a public DNS subdomain facilitates DNS rebinding attacks, it (and all equivalent approaches) will unfortunately be blocked by quite a few of the more sophisticated home routers out there, including a quite common brand in Germany. Also, doesn't publishing a privkey for a public TLS certificate theoretically require it to be revoked under common browser CA standards...? Let's Encrypt seems to support it, at least: https://letsencrypt.org/docs/revoking/#using-the-certificate-private-key https://letsencrypt.org/docs/revoking/#using-the-certificate...
- 8organicbits 3y agoThe certificate is revoked, your browser must not be checking for revocation. Browser support for revocation is pretty poor, unfortunately. https://crt.sh/?id=9497801989&opt=ocsp https://crt.sh/?id=9497801989&opt=ocsp
- lxgr 3y agoHm, are these automatically revoked then as part of the service, or did somebody just revoke it? Update: Seems to have just happened – after restarting, Firefox now does not accept it anymore!
- andrewmackrodt 3y agoNice, thanks for sharing this. I use sslip.io but they do not provide TLS certificates, so acme v1 validation is required using a wan IP address and ensuring router port forwarding or cloudflare tunnel etc is running. This magic domain is so much easier.
- 3y ago
- blacklight 3y ago"Forget editing /etc/hosts!" Right. Why would you edit a local file (or create a record on your own local DNS), generate your own self-signed certificate, and immediately get a website that can be tested on your machine, on your local network or on your VPN, when you can pay someone $19 per device (MacOS only) for something less powerful? I understand that everybody needs to make money for a living, but this seems like the digital equivalent of bottling tap water and asking people to pay for it.
- 8organicbits 3y ago> digital equivalent of bottling tap water That's intended as a criticism, but bottled water is a $300B market in the US alone. Most of which is tap water. https://www.latimes.com/business/story/2021-09-28/bottled-water-is-really-just-tap-water https://www.latimes.com/business/story/2021-09-28/bottled-wa...
- Zetice 3y agoYou know you’re onto something when you get HN comments that say, “this can easily be done by just <list half a dozen tools and processes>”… Very clever, if I weren’t leaving the industry I would for sure grab a copy.
- rado 3y agoInteresting. Does it have gzip and HTTP/2? Thanks
- jarekceborski 3y agoCurrently only http 1.1 and no compression. But these could be added in the future.
- pratio 3y agoWe use mkcert for this, it works wonderfully. https://github.com/FiloSottile/mkcert https://github.com/FiloSottile/mkcert
- 8organicbits 3y agoGreat work! Public CAs have done a wonderful job making HTTPS easy for public websites, but private networks feel under-supported and we're often stuck with legacy tools. I'm really happy to see people building here. I've been working on getlocalcert[1] which explores this problem from the other end; how can we make TLS certificate management and trust root distribution easier? There's lots of interest in using certificates issued by public CAs for private domains. Especially the free ones from Let's Encrypt. This completely avoids trust root distribution challenges and concerns about trust roots being used to MITM traffic. My local DNS management story is admittedly currently a hand-wave[2], but I really like your approach. I was hoping we could pair our tools, but I think mDNS is for .local only, so we won't be compatible. I'm curious about the trust root you're using. Lots of tools will create these without any nameConstraints, which is reasonable as client-side support has historically been poor[3], but restricting the root and any intermediaries to *.local can reduce the risk that a stolen trust root is used to MITM unrelated sites like google.com. [1] https://www.getlocalcert.net/ https://www.getlocalcert.net/ [2] https://docs.getlocalcert.net/dns/ https://docs.getlocalcert.net/dns/ [3] https://alexsci.com/blog/name-non-constraint/ https://alexsci.com/blog/name-non-constraint/
- 8organicbits 3y agoHmm, I may need to look at this some more. Avahi supports[1] changing the default domain, so I think you could in principal use mDNS for domains other than .local. But that's a config change, so it wouldn't have that out-of-the-box zero-config benefit. [1] https://linux.die.net/man/5/avahi-daemon.conf https://linux.die.net/man/5/avahi-daemon.conf
- jareklupinski 3y agohad a mini-heart attack reading the intro; we don't see enough of each others' names on here :) been waiting for something like this to come along: when i set up microcontrollers that expose a mini-server, i would like to use the Geolocation API built into mobile browsers so users can tell the gadget where it is, but they block access to the API unless your site starts with 'https:// https://' ( a silly barrier but whatever )
- emadda 3y agoLooks very nice. Side note: I released https://tabserve.dev https://tabserve.dev a few months ago. It uses a browser tab and web workers as a reverse proxy to get a https url to localhost.
- AlexJuca 3y agoVery cool tool! This can be done using other means but I like how easy it is with this tool and the app has a decent looking UI. Congrats on releasing the tool.