04 — Conflux · Quick starts

Expose a service, and only to the machines that should see it

Thirteen recipes for publishing a database or a self-hosted app on the overlay. Each keeps the service on loopback, where it already listens, and publishes it to every machine that shares the server's taint, and to nothing else: no port forward, no firewall rule, nothing on the internet.

On this page

Before you start

Every recipe uses the same two machines: a server running the service, and a client that wants to reach it. If conflux is not installed yet, install it on both.

  1. 01
    On the server, publish the port

    The first run mints a taint and asks nothing else, because --ipv4 answers the one question it would.

    $ sudo conflux proxy 5432=127.0.0.1:5432 --ipv4 10.128.0.5/24
    Minted a taint for this network:
    
        brhk-2mq9-tzva-6pjs-k4xe-nw7d-qf
  2. 02
    On each client, join with that taint
    $ sudo conflux up --taint brhk-2mq9-tzva-6pjs-k4xe-nw7d-qf
  3. 03
    Connect to the server's overlay address

    The recipes use 10.128.0.5, the IPv4 from the first step. The server's IPv6 address works as well, bracketed in a URL. sudo conflux peers lists both for every peer, and peers take fifteen to sixty seconds to find each other.

  • A client runs conflux up. A machine running conflux proxy has no interface to connect out from.
  • Leave the service on loopback. In Docker, publish to 127.0.0.1: conflux dials from the host, where container names do not resolve.
  • The service sees every connection come from loopback. Keep its own authentication on: the overlay decides who can connect, not who may sign in.
  • Server already running conflux up? Then there is no proxy: bind the service to the overlay address instead. Each recipe says how.

Choose a service

PostgreSQL

Databases · overlay 5432

Reach a database from laptops, CI runners and app servers without opening 5432 to anything else.

On the server
# PostgreSQL listens on localhost by default; leave it there
$ sudo conflux proxy 5432=127.0.0.1:5432 --ipv4 10.128.0.5/24
Or, in Docker
$ docker run -d --name postgres -e POSTGRES_PASSWORD='change-me' \
    -p 127.0.0.1:5432:5432 postgres:17
$ sudo conflux proxy 5432=127.0.0.1:5432 --ipv4 10.128.0.5/24
From another machine
$ psql "postgresql://app@10.128.0.5:5432/app"
$ psql "postgresql://app@[fd80:c4b9:99ae:4411:c531:fd4f:754f:f08a]:5432/app"
If the server runs conflux up instead
# postgresql.conf
listen_addresses = 'localhost,10.128.0.5'

# pg_hba.conf: the client's own overlay IPv6, which is bound to its identity
host  app  app  fd80:c4b9:99ae:df9b:5261:d178:18f1:783c/128  scram-sha-256

Have clients connect to the server's IPv6 address, so that pg_hba.conf sees who each one is. Over IPv4 they arrive from the shared 198.18.0.0/15 range.

Several services on one machine

Each run of conflux proxy sets the machine's whole list of published ports, so several services are one command with every spec in it.

$ sudo conflux proxy 5432=127.0.0.1:5432 6379=127.0.0.1:6379 80=127.0.0.1:3000

The list is kept in proxies in the configuration file, which can be edited by hand and applied with sudo conflux start. To try a port without keeping it, sudo conflux anchorctl proxy -add 9000=127.0.0.1:9000 serves it until the anchor next restarts.

When it does not connect

SymptomCheck
Refused, or times out at oncesudo conflux anchorctl proxy on the server lists what the anchor serves, with live and failed connections and the backend's last error.
Nothing at all from the clientThe DATA column in sudo conflux peers on the client. A no there is a taint set that is not contained. A no on every peer can also mean the client is blocked.
The page loads, then sends you to localhostThe app's own external address setting, named in its recipe: root_url, ROOT_URL, trusted_domains and the like.
Works on the server, not from a clientThe service listens somewhere the backend spec does not name, or a Docker port is published somewhere other than 127.0.0.1.

The rest is in conflux troubleshooting.