# Host a website from a Pi in your bedroom

A website served by a Raspberry Pi on your home network, reachable from
anywhere — no public IP,
[no port forwarding](https://relayssh.com/docs/ssh-without-port-forwarding/).
You need a Pi that is
already connected to RelaySSH; if yours is not, start with
[getting started](https://relayssh.com/docs/getting-started/).

## Put a web server on the Pi

Install nginx. It serves a default page immediately, which is all you need to test the plumbing:

```sh
sudo apt install -y nginx
```

Confirm it answers locally:

```
$ curl -s localhost | grep title
<title>Welcome to nginx!</title>
```

## Open a tunnel to port 80

On the device's detail page in the dashboard, add a tunnel with device
port `80`. The relay assigns the site its own public port
(20000–29999) and the agent opens a reverse tunnel to it within a
heartbeat.

> **Tip:** The target host defaults to 127.0.0.1 — the Pi itself. Point it at another machine on your network instead, and the Pi publishes something it can reach but you cannot: a NAS web UI, a printer, a second server.

## Open it from anywhere

Your site is live at the relay's hostname on your assigned port. Replace the port with yours:

```text
http://relayssh.com:20002
```

Every visitor's request arrives at the relay, travels down the reverse
tunnel, and is answered by nginx on the Pi. The Pi stays behind your
home router the whole time.

## Replace the default page

nginx serves `/var/www/html`. Put your site there:

```sh
echo 'Served from my bedroom' | sudo tee /var/www/html/index.html
```

Reload the public URL — the change is live immediately. No deploy step: editing files on the Pi is the deploy.

## What this is, and what it is not

This setup is plain HTTP on a numbered port. The address carries the port,
browsers label the page "not secure", and traffic between visitor and relay
is unencrypted — unlike SSH, HTTP brings no encryption of its own. That is
fine for a hobby project, a demo, a dashboard you share with friends. It is
the wrong tool for logins, payments, or anything private — put those behind
SSH, or terminate HTTPS on the Pi with your own domain and certificate. If
you want your own domain with HTTPS handled for you, Cloudflare Tunnel is
the better tool for the website part —
[RelaySSH vs Cloudflare Tunnel](https://relayssh.com/docs/relayssh-vs-cloudflare-tunnel/)
says where each one fits.

## Where next

Anything that speaks TCP works the same way — a Home Assistant dashboard on
port 8123, a camera stream, a game server. Add a tunnel to its port and the
relay does the rest. The tunnel does not even have to end on the Pi:
[reach devices next to
your Pi](https://relayssh.com/docs/reach-lan-devices/) the same way.
