.. /OpenTunnel
Star

Install
Access
Persistence

OpenTunnel is an end-to-end encrypted (“blind”) TLS tunnel hosted on Cloudflare by Anomaly. Each client receives a unique .opentunnel.xyz hostname and terminates TLS locally, so the relay only reads the SNI from the TLS handshake and never sees plaintext traffic. A background service (systemd/launchd or a plain background process) keeps subdomain routes connected to local ports, which makes it suitable for persistent access to internal services.

Paths:

Resources:

Detections:

Install

  1. Downloads and runs the install script, which fetches the prebuilt opentunnel binary from GitHub releases. The CLI is also available via npm (npm install -g opentunnel), Homebrew (brew install anomalyco/tap/opentunnel), AUR (opentunnel-bin) and Cargo (cargo install opentunnel-cli).

    curl -fsSL https://opentunnel.xyz/install | sh
    Use case
    Installing the OpenTunnel CLI on a host.
    Privileges required
    User
    Operating systems
    Linux, MacOS

Access

  1. Creates the tunnel on first use, routes <SUBDOMAIN>.<id>.opentunnel.xyz to 127.0.0.1:<PORT> and starts the background service.

    opentunnel route add <SUBDOMAIN> <PORT>
    Use case
    Exposing a local service or application over the internet.
    Privileges required
    User
    Operating systems
    Linux, MacOS
  2. Routes the tunnel's root hostname (<id>.opentunnel.xyz) to an arbitrary host and port reachable from the machine, such as another internal system.

    opentunnel route add @ <HOST>:<PORT>
    Use case
    Exposing internal network services through a compromised host.
    Privileges required
    User
    Operating systems
    Linux, MacOS
  3. Runs the tunnel in the foreground instead of as a registered service, for containers or environments without systemd/launchd.

    opentunnel serve
    Use case
    Running a tunnel inside a container or without leaving a service registration.
    Privileges required
    User
    Operating systems
    Linux, MacOS

Persistence

  1. Creates the tunnel if needed and starts the background service. Where available it registers as a systemd user service (opentunnel-<profile>.service) or launchd agent (xyz.opentunnel.<profile>) that starts at login.

    opentunnel up
    Use case
    Persistent tunnel that survives logoff and reboot.
    Privileges required
    User
    Operating systems
    Linux, MacOS