Building a Unlimited Bandwidth Ngrok Alternative: Self-Hosting Frp and Rathole on a $2 VPS
Introduction: The Cost of Convenience in Local Development
For modern software engineers, web developers, and system administrators, exposing a local development server to the internet is a daily necessity. Whether you are testing webhooks from third-party services like Stripe, demonstrating a work-in-progress to a client, or debugging mobile applications against a local backend, your local machine needs a public URL. For years, Ngrok has been the industry standard for this exact use case.
However, as teams scale and data demands increase, the limitations of Ngrok's free tier become a significant bottleneck. Bandwidth throttling, unpredictable URL changes on restart, and strict limits on concurrent connections quickly push developers toward expensive premium tiers. Fortunately, there is a enterprise-grade, cost-effective alternative: building your own reverse proxy infrastructure. By leveraging lightweight, open-source tools like Frp (Fast Reverse Proxy) or Rathole on a budget-friendly $2 Virtual Private Server (VPS), you can establish a self-hosted tunnel with completely unlimited bandwidth and static domains.
---Why Shift Away from Commercial Tunneling Services?
While commercial SaaS platforms offer one-click convenience, they introduce several constraints that hinder professional workflows:
- Bandwidth Caps: Free and low-tier plans heavily throttle data throughput, making it impossible to test media-heavy applications or large file transfers.
- Data Privacy and Sovereignty: Passing sensitive client data, proprietary source code, or production database streams through a third-party server can violate corporate compliance policies.
- Cost Inefficiency: Paying per-user subscription fees for basic port forwarding scales poorly across growing engineering teams.
By shifting to a self-hosted model, you regain absolute control over your traffic, maximize your network throughput based entirely on your VPS port speed, and maintain strict data privacy—all for the price of a coffee per month.
---The Blueprint: Choosing Your Reverse Proxy Architecture
To implement this solution, we require two components: a public-facing server with a static IP (the VPS) and a lightweight tunneling daemon. For the software layer, two exceptional open-source tools stand out: Frp and Rathole.
Option A: Frp (Fast Reverse Proxy)
Frp is a highly mature, feature-rich reverse proxy written in Go. It supports a wide array of protocols including TCP, UDP, HTTP, HTTPS, and STCP (secret TCP). Frp is ideal for developers who require advanced routing capabilities, web dashboards for monitoring, and multi-user configurations.
Option B: Rathole
Written in Rust, Rathole is a hyper-lightweight, ultra-high-performance alternative focused purely on speed and minimal resource consumption. It is designed to handle thousands of concurrent connections while consuming negligible CPU and RAM, making it the absolute perfect fit for low-spec, ultra-budget $2 VPS instances.
---Step-by-Step Implementation Guide Using Frp
Let us walk through a production-ready deployment utilizing Frp. This setup assumes you have provisioned a basic Linux VPS (Ubuntu/Debian) costing roughly $2/month from providers like RackNerd, Ionos, or LowEndBox, and that you have a domain name pointing to your VPS IP address.
1. Server-Side Configuration (frps)
First, SSH into your VPS to download and configure the Frp server component (frps).
wget [https://github.com/fatedier/frp/releases/download/v0.54.0/frp_0.54.0_linux_amd64.tar.gz](https://github.com/fatedier/frp/releases/download/v0.54.0/frp_0.54.0_linux_amd64.tar.gz)
tar -zxvf frp_0.54.0_linux_amd64.tar.gz
cd frp_0.54.0_linux_amd64Modify the server configuration file (frps.toml) to define your binding ports and authentication tokens. Secure your configuration to prevent unauthorized access:
[common]
bind_port = 7000
vhost_http_port = 8080
auth.method = "token"
auth.token = "YourHighlySecureRandomToken"
Execute the server daemon using systemd to ensure it runs continuously in the background and restarts automatically on boot.
2. Client-Side Configuration (frpc)
On your local development machine (macOS, Windows, or Linux), download the corresponding Frp client binary. Edit the client configuration file (frpc.toml) to bridge your local service to the remote VPS:
[common]
server_addr = "your_vps_public_ip"
server_port = 7000
auth.method = "token"
auth.token = "YourHighlySecureRandomToken"
[local_web_app]
type = "http"
local_ip = "127.0.0.1"
local_port = 3000
custom_domains = "dev.yourdomain.com"
Launch the client binary. Instantly, any traffic hitting dev.yourdomain.com:8080 will be securely tunneled directly to your local application running on port 3000, completely bypassing local firewalls and NAT constraints.
Optimizing Performance and Maximizing Security
Running your own infrastructure requires adherence to basic security engineering practices. To ensure your self-hosted tunnel remains secure and performant, implement the following enhancements:
- Reverse Proxy with Nginx: Do not expose your tunnel ports directly to the public web. Layer an Nginx reverse proxy in front of Frp or Rathole on the VPS. This allows you to route traffic over standard ports (80 and 443).
- Automated TLS/SSL Encryption: Utilize Let's Encrypt alongside Certbot on your Nginx layer to automatically provision and renew SSL certificates. This guarantees that all data traveling between the end-user, your VPS, and your local machine is fully encrypted via HTTPS.
- Implement Transport Encryption: Within your Frp or Rathole configurations, explicitly enable the
transport.encryptionflags to ensure the data within the tunnel itself cannot be intercepted or sniffed mid-transit.
Conclusion: Unlocking True Developer Freedom
Migrating away from restrictive commercial services to a self-hosted Ngrok alternative using Rathole or Frp is a significant milestone for any developer or organization. For the nominal cost of a $2 VPS, you unlock an unthrottled, highly secure, and fully customized tunneling architecture. This not only elevates your local development capabilities but also provides deep architectural insights into networking, reverse proxies, and server management. Take control of your development stack today by deploying your own tunneling infrastructure.
