The problem is familiar to anyone who's ever built something locally and needed to show it to someone else: your dev server runs on localhost, and localhost doesn't travel. The commercial answer is ngrok or Cloudflare Quick Tunnels. The self-hosted answer usually means installing yet another daemon. Bernat's answer is: you already have everything you need. The core mechanism is SSH remote port forwarding with port 0, which tells the server to pick an ephemeral port. Nginx then catches wildcard subdomains matching the pattern p{PORT}.ssh.luffy.cx and proxies them to 127.0.0.1:{PORT}. That's the whole trick — two tools, one DNS wildcard, one Let's Encrypt wildcard cert. No new software to install, no new attack surface to maintain. The access control layer is where the craft shows. Rather than leaving the port number as the only secret (trivially enumerable), Bernat uses nginx's ngxhttpsecurelinkmodule to compute an MD5 hash over the port, an expiration timestamp, and a shared secret. The hash gets stuffed into the URL as an HTTP basic auth username — a trick that works because most HTTP clients support the user@host URL form. Expired links return 410 Gone. Bad hashes return 401 with a WWW-Authenticate challenge. It's not OAuth, but it's meaningfully better than nothing. The helper script solves the last ergonomic problem: finding the ephemeral port that SSH allocated. Since OpenSSH doesn't expose this in an environment variable, the script walks the process tree to find ancestor sshd-session PIDs, then queries ss for their listening ports. It's the kind of Unix plumbing that looks obvious in retrospect and would take you an afternoon to figure out from scratch. The NixOS integration is a nice touch — Bernat provides both a standalone script and a .nix module — but the real value is the idea itself. This is infrastructure minimalism as a design philosophy: instead of adding a tool, compose the tools you already run. The tradeoff is real (no dashboard, no request inspection, no team features), but for the use case of 'show someone a draft,' the complexity budget is exactly right. What makes this worth reading isn't any single technique but the composition. Wildcard DNS, wildcard TLS, SSH remote forwarding, nginx regex servername matching, securelinkmodule, process tree walking — each piece is documented individually, but the assembled whole is genuinely useful and not written up elsewhere in this form.