Requirements
The VM, the domain and the five ports.
The machine
- A Linux VM with a public address — One vCPU and 512 MB of RAM. The server itself uses a few megabytes and peer traffic never passes through it — the RAM is for Docker, which needs around 150 MB on its own.
- A domain pointing at it — Clients connect over TLS, a certificate is required, and a certificate requires a name.
Ports reachable from the internet
- 80 / TCP — ACME certificate challenge, and the HTTP to HTTPS redirect.
- 443 / TCP — Enrollment, the peer-list WebSocket, ICE signalling and the admin API.
- 8788 / UDP — The NAT reflector.
- 8443 / TCP — Reverse Proxy in HTTP mode. Only needed if you use that feature.
- 8444 / TCP — Reverse Proxy in TLS-passthrough mode. Same.
The UDP port cannot go behind a reverse proxy
The reflector's only job is to report the source address a packet arrived from — which is exactly what a proxy replaces. It has to reach clients directly. Everything else is ordinary HTTP and belongs behind TLS.
Open UDP 8788 at your cloud provider, not just on the VM. Cloud firewalls default to deny and are configured separately from the instance, and every provider's convenient "allow HTTP/HTTPS" option covers only TCP 80 and 443. Nothing prompts you for the UDP rule, and its absence is invisible: TLS works, health checks return 200, devices enroll successfully — and peers then never connect to each other.
gcloud compute firewall-rules create mangofly-reflector \
--allow udp:8788 --source-ranges 0.0.0.0/0