relay·ssh

Reach devices next to your Pi

A tunnel does not have to end on the Pi. Its target is any host the Pi can reach — a NAS, a printer, a camera, a controller. One agent on one Pi is enough for the whole network, because the devices being reached run nothing at all.

The target is the Pi's choice

Every tunnel has a target: a host and a port, written from the Pi's point of view. The default target host is 127.0.0.1 — the Pi itself, which is how hosting a website from the Pi works. Set it to 192.168.1.50 or printer.local instead, and the relay still delivers every connection to the Pi — but the Pi passes it on, opening a plain TCP connection to that host on its own network.

your laptop :20073 relay reverse tunnel your Pi · agent same network :5000 NAS · no agent

The relay never sees your network. It hands the connection to the Pi through the reverse tunnel, and the Pi makes the local hop. Host names resolve on the Pi too, so printer.local means whatever it means on your network, not on the relay.

What it is for

Devices that cannot run an agent. A printer, an IP camera, a router, a smart plug, a PLC — none of them will ever run your software, and none of them need to. The Pi is the one machine you control, and a tunnel per service is all it takes: 192.168.1.50:5000 for the NAS web UI, printer.local:631 for printing, 192.168.1.1:80 for the router. Each tunnel gets its own stable public port on the relay.

Public tunnel, or SSH forward?

A public tunnel makes the target reachable by anyone who finds the port. That is the point for a website — and the wrong default for a login page. For admin interfaces, management consoles, and anything industrial, forward through the Pi's SSH tunnel instead:

sh
ssh -L 8443:192.168.1.50:8443 -p 20001 pi@relayssh.com

Then open https://localhost:8443. The path is the same — relay, reverse tunnel, Pi, LAN — but it only exists inside your SSH session, and your device checks your key before any of it happens. Nothing is exposed to the internet. If a thing has a password prompt, reach it this way.

Boundaries

A tunnel forwards one TCP port to one target. This is not a VPN: there is no subnet routing, no device discovery, and UDP does not traverse it. Anything that speaks TCP works — HTTP, RTSP over TCP, Modbus TCP, SSH itself. Older agents ignore the target host and forward to the Pi itself, so update the agent before pointing a tunnel at a neighbor — re-running the install command is the upgrade.