Skip to main content
Every machine gets a domain at name.boxd.sh. The boxd proxy terminates TLS and forwards HTTP requests to your machine.

Getting started

nginx is pre-installed and configured on port 8000, but disabled by default. Start it:
Visit https://myapp.boxd.sh — you will see a welcome page.

Running your own app

Any process that listens on the proxy’s target port (8000 by default) is reachable via HTTPS. No configuration needed.
Node.js is not pre-installed. Install it first: sudo apt install -y nodejs npm or use nvm.

Changing the port

The default proxy forwards to port 8000, but you can change it:

Subdomain proxies

Create additional subdomains pointing to different ports:

WebSockets

WebSocket connections work transparently. The proxy detects the Upgrade: websocket header and forwards the connection.

Non-HTTP traffic

The HTTPS proxy only speaks HTTP — it terminates TLS and routes by domain. To reach a database, an SSH daemon, a game server, or any other raw protocol, expose a raw TCP/UDP port instead:
See Port forwarding.

HTTP to HTTPS

Plain HTTP requests to http://name.boxd.sh are redirected to HTTPS automatically. HSTS headers are included in the response.

DNS

A DNS record is created automatically when your machine boots. The record has a 60-second TTL.
Every machine’s domain points at the proxy’s shared public IP. The proxy routes HTTPS by SNI (the domain in the TLS handshake) and SSH by the machine’s dedicated port — so the same IP fronts every VM.