Deploying Zrok on a VPS: A Secure, Self-Hosted Alternative to Ngrok for Exposing Local Services
Introduction: The Evolution of Ingress Tunneling
In modern software development, webhooks, API integrations, and client demonstrations frequently require exposing a service running on a local machine (localhost) to the public internet. For years, Ngrok has been the industry standard for creating these secure ingress tunnels. However, recent shifts in Ngrok’s pricing models, strict bandwidth limitations on free tiers, and the inherent privacy concerns of routing sensitive development data through third-party servers have forced engineering teams to seek self-hosted alternatives.
Enter Zrok—a powerful, open-source, next-generation tunneling platform built on top of OpenZiti. Zrok goes beyond traditional reverse proxies by introducing a zero-trust architecture, native peer-to-peer (P2P) capabilities, and the flexibility of complete self-hosting. By deploying Zrok on your own Virtual Private Server (VPS), you regain absolute control over your data, bypass restrictive commercial limits, and establish a hardened gateway for your internal services.
Why Choose Zrok Over Ngrok?
While Ngrok is undeniably convenient, relying on it for corporate development or sensitive data handling poses significant operational bottlenecks. Deploying Zrok on a dedicated VPS yields several distinct advantages:
- Zero-Trust Security: Built on OpenZiti, Zrok inherently operates on a default-deny security posture. Tunnels are only accessible to authenticated identities, drastically reducing your attack surface.
- Cost Efficiency: Commercial tunneling services charge premium rates for custom domains, static subdomains, and high bandwidth. With Zrok on your own VPS, your only cost is the flat rate of your cloud provider.
- Data Sovereignty: Traffic flowing through Zrok does not pass through external corporate proxies. Your data remains strictly within your self-hosted perimeter, ensuring compliance with strict data protection regulations.
- Peer-to-Peer (P2P) Routing: Zrok supports public shares (via an internet gateway) and private shares, allowing direct machine-to-machine communication without exposing any public endpoints.
Prerequisites for VPS Deployment
Before initiating the installation process, ensure your infrastructure meets the following baseline requirements:
- A VPS running a clean installation of a modern Linux distribution (e.g., Ubuntu 22.04 LTS or Debian 12).
- A fully qualified domain name (FQDN) with access to its DNS management console (e.g.,
zrok.yourcompany.com). - Docker and Docker Compose installed on the host machine.
- Basic familiarity with network protocols, SSH, and command-line interfaces.
Step-by-Step Guide to Deploying Zrok on a VPS
Setting up your self-hosted Zrok environment involves configuring the Zrok controller, setting up the frontend proxy, and registering user identities. Follow this structured execution plan to deploy the platform effectively.
Step 1: Configure DNS Records
To allow Zrok to dynamically allocate subdomains for your active shares, you must configure two specific DNS records pointing to your VPS public IP address:
A Record:zrok.yourcompany.com→YOUR_VPS_IP
Wildcard A Record:*.zrok.yourcompany.com→YOUR_VPS_IP
The wildcard record is critical, as it enables the Zrok infrastructure to route traffic dynamically to individual temporary or permanent endpoints generated by developers.
Step 2: Initialize the Zrok Environment via Docker Compose
The most reliable method for deploying Zrok is utilizing Docker Compose, which encapsulates the Zrok controller, storage backends, and networking requirements into a single, maintainable stack.
Create a dedicated directory and establish your configuration file:
mkdir -p /opt/zrok && cd /opt/zrok
nano docker-compose.yml
Populate the file with the official Zrok self-hosted service definitions, ensuring you define your database credentials, internal secrets, and your primary domain (zrok.yourcompany.com). Ensure that ports 80 and 443 are exposed to handle incoming public requests, and port 18080 is available for the internal controller API.
Step 3: Provision SSL Certificates with Let's Encrypt
Security is paramount when exposing internal services. You must secure the Zrok HTTP frontend using TLS certificates. Use Certbot to obtain a wildcard certificate via DNS validation:
sudo apt install certbot
sudo certbot certonly --manual --preferred-challenges=dns -d zrok.yourcompany.com -d *.zrok.yourcompany.com
Once the DNS TXT records are verified and the certificates are generated, link them directly into your Zrok proxy configuration to enforce HTTPS across all public tunnels.
Step 4: Launch the Services and Create an Account
Execute the Docker Compose stack in detached mode:
docker compose up -d
With the controller active, you can now use the Zrok CLI administrative commands to bootstrap your first user account:
docker compose exec zrok-controller zrok admin create-user [email protected] password123
Connecting Local Clients to Your VPS Zrok Instance
Now that your private Zrok service is running smoothly on your VPS, local developers can connect their environments seamlessly. Here is the operational workflow for your engineering team:
1. Install the Zrok CLI Locally
Developers must download the Zrok binary relevant to their operating system (Linux, macOS, or Windows) and place it within their system path.
2. Authenticate with the Private VPS
Instead of authenticating against Zrok’s public service, developers target your newly deployed corporate VPS controller:
zrok api target [https://zrok.yourcompany.com](https://zrok.yourcompany.com)
zrok login [email protected]
Upon successful authentication, the system generates a persistent token mapping the local machine securely to the remote architecture.
3. Expose a Local Service
To share a local web service running on port 8080 with external stakeholders, the developer executes a simple command:
zrok share public http://localhost:8080
Zrok will instantly output a unique, secure URL (e.g., [https://xyz123.zrok.yourcompany.com](https://xyz123.zrok.yourcompany.com)) accessible anywhere in the world. The traffic is securely tunneled over encrypted channels directly to the developer’s machine.
Advanced Security Hardening for Enterprise Use
To utilize Zrok as a true enterprise-grade alternative to commercial solutions, consider implementing the following security layers:
Implementing Private Sharing (P2P)
For highly confidential services, avoid public URLs entirely. Zrok allows a private share where only authorized clients running the Zrok agent can access the tunnel. The traffic travels directly peer-to-peer, completely bypassing public internet visibility.
Rate Limiting and Firewalls
Configure iptables or ufw on your VPS to restrict access to the Zrok controller administrative ports. Additionally, leverage reverse proxy configurations to rate-limit incoming connections, preventing Distributed Denial of Service (DDoS) attacks from saturating your internal development environments.
Conclusion: Autonomy in Ingress Management
Transitioning from Ngrok to a self-hosted Zrok deployment on a VPS provides software engineering teams with uncompromised privacy, significant long-term financial savings, and robust zero-trust security controls. By investing a brief window of setup time into an open-source architecture, your organization builds an infrastructure asset that scales organically with your development needs, free from arbitrary commercial limits.
