Remote access on your own
There are two ways to reach your Frameleaf server when you’re away from home:
- Frameleaf Cloud remote access: a relay or direct connection with HTTPS, a stable address and no router changes. See Remote access with Frameleaf Cloud.
- Set it up yourself, with one of the options on this page. Nothing here needs Frameleaf Cloud.
Option 1: a VPN to your home network
Section titled “Option 1: a VPN to your home network”A VPN such as WireGuard or OpenVPN opens an encrypted connection from your phone or laptop to your home network. You then reach Frameleaf by its home address, exactly as you do at home.
Good:
- Simple and very secure. Even if a flaw were found in Frameleaf, it wouldn’t be exposed to the internet.
- WireGuard and OpenVPN have both had independent security audits.
Not so good:
- Without a fixed IP address at home, you need a dynamic DNS service.
- The VPN app has to be installed and on, on every device.
- You need to open a port on your router for the VPN.
Option 2: Tailscale
Section titled “Option 2: Tailscale”If you can’t open a port on your router, Tailscale connects your devices with WireGuard tunnels, even when both ends are behind a home router.
Good:
- Very little setup on the server and on your devices.
- Frameleaf isn’t exposed to the internet.
Not so good:
- The Tailscale app usually runs with full system rights on your devices, which adds a little risk compared with a plain WireGuard server.
- It’s a paid service, with a free tier for personal use.
- It has to be installed and running on the server and every device.
Option 3: your own reverse proxy
Section titled “Option 3: your own reverse proxy”A reverse proxy serves Frameleaf over HTTPS at your own address, such as https://photos.example.com, just like any other website. This makes most sense if you have your own domain; a dynamic DNS name works too. The Frameleaf apps can then connect from anywhere with no VPN app.
You’ll need a certificate. Let’s Encrypt gives free certificates and is what we recommend for anything reachable from the internet. A self-signed certificate also encrypts traffic, but browsers show a warning. A hosted proxy such as Cloudflare can also hide your home IP address, which makes targeted attacks harder.
See Reverse proxy for the headers, upload limits and example configurations.
Good:
- Nothing extra to install on your devices.
- If you only need the web app remotely, you can put an access control service in front of it to shield Frameleaf from the internet.
Not so good:
- More involved to set up.
- Depending on your setup, the web app and API are exposed to the internet, so keep Frameleaf up to date.
After you set it up
Section titled “After you set it up”- Set Public server URL in Settings, then Frameleaf Cloud, then Remote access to the address people use from outside. Shared links, emails and sign-in callbacks use it. It doesn’t need a Frameleaf Cloud link, and shouldn’t end with a slash.
- If you use your own sign-in provider, add the new address to its redirect URIs.
- In the Frameleaf apps, add the outside address so they can connect away from home.