Skip to content

Remote access

Remote access lets the apps and shared links reach your server when you’re away from home. There’s no port forwarding to set up, no dynamic DNS to manage and no certificate to renew by hand.

Remote access is part of a Frameleaf Cloud plan and needs your server linked. Turn it on in the Command Center under Frameleaf Cloud, then Remote access.

  1. Your server opens an outgoing connection to a Frameleaf relay. It works behind any router, and nothing on your router needs to change.
  2. Your server gets its own HTTPS certificate and renews it automatically. The certificate’s private key never leaves your server.
  3. The relay passes encrypted traffic to your server by name without decrypting it. It can’t see your photos, your passwords or the pages you open.

The apps pick the fastest route on their own and switch without interrupting what you’re doing:

Route When it’s used
Home You’re on the same network as the server. Always preferred
Direct Your router lets the server accept connections from outside. Faster, and doesn’t count toward your relay allowance
Relay Everything else, including mobile networks and routers that block incoming connections

For a direct connection, your server asks your router to open a port for it, using UPnP or NAT-PMP, on port 2443 by default (set with FRAMELEAF_EDGE_PORT). You can also open the port yourself. Frameleaf Cloud checks from outside that the address really works before the apps use it.

If your internet provider shares one public address among many customers (CGNAT), or your router has UPnP turned off, there’s no direct route. The relay still works.

Each server gets its own name under frameleaf.net, with one certificate that covers all of them:

Address What it’s for
r.<label>.frameleaf.net Your Frameleaf address, through the relay. Share it, or scan its QR code on a phone
192-168-1-10.<label>.frameleaf.net Your server on your home network, with the same certificate
<your public address>.<label>.frameleaf.net A direct connection over the internet, including IPv6

The <label> is a random-looking 16-character name that belongs to your server.

Public server URL in Frameleaf Cloud, then Remote access sets the address used in shared links and emails.

You can publish your server on a name you own, such as photos.example.com, through the relay.

  1. In the Command Center, open Frameleaf Cloud, then Remote access, and add the hostname.

  2. At your DNS provider, create two CNAME records:

    Name Points to
    photos.example.com r.<label>.frameleaf.net
    _acme-challenge.photos.example.com _acme-challenge.<label>.frameleaf.net
  3. Wait for the hostname to show as verified. Your server then gets a certificate for it.

Things to know:

  • It must be a subdomain, like photos.example.com, not example.com itself.
  • Up to 5 hostnames per server for now.
  • Relay only. Custom hostnames don’t use direct connections.
  • Your server holds the certificate. Frameleaf Cloud never issues or holds it. If your domain has a CAA record that doesn’t allow Let’s Encrypt, the hostname can’t be verified.
  • If it stops working, for example after a DNS change, it’s marked as failing and still routed for 7 days while the owner is emailed.
  • A hostname still pending after 7 days fails. Check both records and add it again.

When you remove a hostname, the account site lists the two DNS records you can now delete.

These are the current defaults and may change before launch:

Limit Default
Relay speed 8 Mbps per server
Monthly relay allowance 200 GB. You’re emailed at 80%. At 100% the relay slows to 1 Mbps until the end of the month; it’s never cut off
Connections 500 at a time, with a 10-minute idle timeout

Direct connections don’t count toward the allowance. This month’s relay use is shown on your server and on the account site.

Over the relay, the apps load previews and streamed video. Originals, archives and database backups aren’t downloaded through the relay unless an administrator allows it. Backup uploads of photos still work; the Android app holds videos until it finds a faster route, unless you allow them.

Everyone who connects from outside your home, through the relay or a direct connection, must sign in with a Frameleaf account linked to their account on your server. Your server stays in charge of who can see what, and “trusted network” shortcuts never apply to remote connections.

  • Public shared links still work for people without an account.
  • API keys only work remotely if their owner has linked a Frameleaf account.

To give someone their own access, share the server with them.

  • The relay sees only your server’s name, the encrypted traffic, how much was sent, and the visitor’s IP address, which is shortened in logs and usage counts.
  • The relay can’t show an error page for your name, because it can’t decrypt your traffic.
  • Frameleaf Cloud checks the public certificate logs daily and emails the owner if a certificate for your server’s names appears that your server didn’t request.
  • The launch relays are in North America, in New York and Quebec.
  • Frameleaf Cloud unreachable: an open relay connection keeps working for up to 4 hours. Your server works normally at home.
  • Plan lapsed past its grace period: the relay connection closes and router port mappings are removed. Your server still works at home.
  • Server unlinked: the relay connection is cut within 2 minutes and your Frameleaf addresses are removed after 24 hours.