Back to articles
Technology Insight

Deploying Zrok on a VPS: A Secure, Self-Hosted Alternative to Ngrok for Exposing Local Services

June 2, 2026

Introduction: The Evolution of Ingress Tunneling

In modern software development, webhooks, API integrations, and client demonstrations frequently require exposing a service running on a local machine (localhost) to the public internet. For years, Ngrok has been the industry standard for creating these secure ingress tunnels. However, recent shifts in Ngrok’s pricing models, strict bandwidth limitations on free tiers, and the inherent privacy concerns of routing sensitive development data through third-party servers have forced engineering teams to seek self-hosted alternatives.

Enter Zrok—a powerful, open-source, next-generation tunneling platform built on top of OpenZiti. Zrok goes beyond traditional reverse proxies by introducing a zero-trust architecture, native peer-to-peer (P2P) capabilities, and the flexibility of complete self-hosting. By deploying Zrok on your own Virtual Private Server (VPS), you regain absolute control over your data, bypass restrictive commercial limits, and establish a hardened gateway for your internal services.

Why Choose Zrok Over Ngrok?

While Ngrok is undeniably convenient, relying on it for corporate development or sensitive data handling poses significant operational bottlenecks. Deploying Zrok on a dedicated VPS yields several distinct advantages:

  • Zero-Trust Security: Built on OpenZiti, Zrok inherently operates on a default-deny security posture. Tunnels are only accessible to authenticated identities, drastically reducing your attack surface.
  • Cost Efficiency: Commercial tunneling services charge premium rates for custom domains, static subdomains, and high bandwidth. With Zrok on your own VPS, your only cost is the flat rate of your cloud provider.
  • Data Sovereignty: Traffic flowing through Zrok does not pass through external corporate proxies. Your data remains strictly within your self-hosted perimeter, ensuring compliance with strict data protection regulations.
  • Peer-to-Peer (P2P) Routing: Zrok supports public shares (via an internet gateway) and private shares, allowing direct machine-to-machine communication without exposing any public endpoints.

Prerequisites for VPS Deployment

Before initiating the installation process, ensure your infrastructure meets the following baseline requirements:

  1. A VPS running a clean installation of a modern Linux distribution (e.g., Ubuntu 22.04 LTS or Debian 12).
  2. A fully qualified domain name (FQDN) with access to its DNS management console (e.g., zrok.yourcompany.com).
  3. Docker and Docker Compose installed on the host machine.
  4. Basic familiarity with network protocols, SSH, and command-line interfaces.

Step-by-Step Guide to Deploying Zrok on a VPS

Setting up your self-hosted Zrok environment involves configuring the Zrok controller, setting up the frontend proxy, and registering user identities. Follow this structured execution plan to deploy the platform effectively.

Step 1: Configure DNS Records

To allow Zrok to dynamically allocate subdomains for your active shares, you must configure two specific DNS records pointing to your VPS public IP address:

A Record: zrok.yourcompany.com → YOUR_VPS_IP
Wildcard A Record: *.zrok.yourcompany.com → YOUR_VPS_IP

The wildcard record is critical, as it enables the Zrok infrastructure to route traffic dynamically to individual temporary or permanent endpoints generated by developers.

Step 2: Initialize the Zrok Environment via Docker Compose

The most reliable method for deploying Zrok is utilizing Docker Compose, which encapsulates the Zrok controller, storage backends, and networking requirements into a single, maintainable stack.

Create a dedicated directory and establish your configuration file:

mkdir -p /opt/zrok && cd /opt/zrok
nano docker-compose.yml

Populate the file with the official Zrok self-hosted service definitions, ensuring you define your database credentials, internal secrets, and your primary domain (zrok.yourcompany.com). Ensure that ports 80 and 443 are exposed to handle incoming public requests, and port 18080 is available for the internal controller API.

Step 3: Provision SSL Certificates with Let's Encrypt

Security is paramount when exposing internal services. You must secure the Zrok HTTP frontend using TLS certificates. Use Certbot to obtain a wildcard certificate via DNS validation:

sudo apt install certbot
sudo certbot certonly --manual --preferred-challenges=dns -d zrok.yourcompany.com -d *.zrok.yourcompany.com

Once the DNS TXT records are verified and the certificates are generated, link them directly into your Zrok proxy configuration to enforce HTTPS across all public tunnels.

Step 4: Launch the Services and Create an Account

Execute the Docker Compose stack in detached mode:

docker compose up -d

With the controller active, you can now use the Zrok CLI administrative commands to bootstrap your first user account:

docker compose exec zrok-controller zrok admin create-user [email protected] password123

Connecting Local Clients to Your VPS Zrok Instance

Now that your private Zrok service is running smoothly on your VPS, local developers can connect their environments seamlessly. Here is the operational workflow for your engineering team:

1. Install the Zrok CLI Locally

Developers must download the Zrok binary relevant to their operating system (Linux, macOS, or Windows) and place it within their system path.

2. Authenticate with the Private VPS

Instead of authenticating against Zrok’s public service, developers target your newly deployed corporate VPS controller:

zrok api target [https://zrok.yourcompany.com](https://zrok.yourcompany.com)
zrok login [email protected]

Upon successful authentication, the system generates a persistent token mapping the local machine securely to the remote architecture.

3. Expose a Local Service

To share a local web service running on port 8080 with external stakeholders, the developer executes a simple command:

zrok share public http://localhost:8080

Zrok will instantly output a unique, secure URL (e.g., [https://xyz123.zrok.yourcompany.com](https://xyz123.zrok.yourcompany.com)) accessible anywhere in the world. The traffic is securely tunneled over encrypted channels directly to the developer’s machine.

Advanced Security Hardening for Enterprise Use

To utilize Zrok as a true enterprise-grade alternative to commercial solutions, consider implementing the following security layers:

Implementing Private Sharing (P2P)

For highly confidential services, avoid public URLs entirely. Zrok allows a private share where only authorized clients running the Zrok agent can access the tunnel. The traffic travels directly peer-to-peer, completely bypassing public internet visibility.

Rate Limiting and Firewalls

Configure iptables or ufw on your VPS to restrict access to the Zrok controller administrative ports. Additionally, leverage reverse proxy configurations to rate-limit incoming connections, preventing Distributed Denial of Service (DDoS) attacks from saturating your internal development environments.

Conclusion: Autonomy in Ingress Management

Transitioning from Ngrok to a self-hosted Zrok deployment on a VPS provides software engineering teams with uncompromised privacy, significant long-term financial savings, and robust zero-trust security controls. By investing a brief window of setup time into an open-source architecture, your organization builds an infrastructure asset that scales organically with your development needs, free from arbitrary commercial limits.

Deploying Zrok on a VPS: A Secure, Self-Hosted Alternative to Ngrok for Exposing Local Services | DPTCloud