Secure control plane

PortLoom

Enter the server administrator token. It is sent as a Bearer token and kept only for this browser session.

Desired route

Add route

HTTP/HTTPS routes use domains with optional path prefixes and shared ports; TCP routes publish an explicit VPS port after the Agent converges, and UDP rides the tunnel through a datagram relay.

Second Docker host

Add an Agent

Enter the address this Agent can use to reach the Server. PortLoom will generate one command for the NAS or internal host.

Run on the internal host

Agent install command

Copy this command to the NAS or internal Docker host. It installs only the Agent, not the Server.

The command contains a one-time credential. It expires automatically and is removed from the Agent configuration after enrollment.

Confirm action

Delete token?

Enrolled agents are not affected; an unused token can no longer be used to enroll.

Confirm action

Delete route?

The agent will remove the corresponding remote forward after it receives the new revision.