What visitors see
A visitor who hits a sleeping machine sees a short “This machine is asleep” page with a Cloudflare Turnstile check. Most of the time the check passes on its own without the visitor clicking anything. Once it passes, the page reloads, the machine wakes, and your app answers the request. A passed check lasts 24 hours in that browser, for every machine on the same domain. Visiting another sleeping machine underboxd.sh in that time doesn’t ask again.
When the check applies
The check only runs when all of these are true:- The machine is asleep (in standby or hibernated). A running machine is never checked, since there’s nothing to wake.
- The request is for the machine’s main address,
myvm.boxd.shorwww.myvm.boxd.sh. If your org has a wildcard domain,myvm.vms.mysaas.comandwww.myvm.vms.mysaas.comare covered too. - Bot protection is on for the machine.
- Named proxies such as
api.myvm.boxd.sh. - Custom domains pointed at a single machine.
- Traffic over your org’s Tailscale network. Only your tailnet can reach it, so bot protection is off there whatever the machine’s setting.
- SSH. It already requires your key, so it wakes machines as before.
Webhooks and API clients
Only a browser can pass the check. A webhook sender, API client,curl or uptime monitor that hits a sleeping machine gets the check page with a 503 instead of your app, and the machine doesn’t wake.
If a machine needs to be woken by something other than a browser, either turn bot protection off for it, or send that traffic to a named proxy (for example hooks.myvm.boxd.sh), which is never checked.
Turning it off or on
boxd takes the same machine config set <name> bot-protection off command.
Forks keep the setting of the machine they came from, and a machine restored from a snapshot keeps the setting the snapshot was taken with.