peep

A public address for a private port.

Peep puts a service on your machine at an HTTPS address under peep.noise.cam. peep dials out, so no inbound port is opened, and TLS ends on your machine, where the certificate’s key stays.

curl -fsSL https://peep.noise.cam/install | sh
peep route add tom 3000

Creating tunnels on peep.noise.cam is limited to its operator for now.

peep route add tom 3000 serves 127.0.0.1:3000 at

https://tom.<tunnel-id>.peep.noise.cam

  • tom the route you name
  • <tunnel-id> assigned when your tunnel is created
  • peep.noise.cam the collector

How a visit reaches port 3000

sealed all the way to your machine

opened only here

  1. A browser

    opens https://tom.<tunnel-id>.peep.noise.cam. Cloudflare answers the DNS lookup and does nothing else.

  2. The collector

    reads the hostname from the TLS handshake and passes the still-encrypted connection down your tunnel. It never has your certificate’s private key.

  3. peep on your machine

    dialled out to the collector, so no inbound port is open. It holds the key and completes TLS.

  4. Your service

    receives the decrypted connection on 127.0.0.1:3000, like any local client.

What the installer does

It downloads the peep binary for macOS or Linux on x64 or arm64, checks it against the release’s SHA-256 sums, runs it once to make sure it works on your system, and puts it in ~/.local/bin. Set PEEP_INSTALL to choose another directory or PEEP_VERSION to pin a release. Read the script before you pipe it to a shell.

The first peep route add creates your tunnel and requests its certificate, which can take a few minutes. After that peep runs in the background and starts at login where systemd or launchd is available.

npm, Homebrew, Cargo and AUR packages are planned but not published yet.

Everyday commands