Self-hosting without a public IP (behind CGNAT)
A home or office server behind CGNAT cannot be reached on ports 80/443. How to tell, and the two ways out: open the ports, or go through a tunnel.
Many home ISPs use CGNAT: the IP address you see is shared by many subscribers, so no port on it leads back to your machine. Apps you install still run — nobody outside can reach them, and the machine cannot obtain an HTTPS certificate either.
How to tell
The Keenrig installer tests ports 80 and 443 from outside once it finishes. If nothing answers, it says so plainly instead of leaving you to guess, and lists the usual causes: ports not forwarded, a firewall in the way, or a CGNAT connection.
Way out 1: open the ports
If your ISP gives you a real public IP, forwarding ports 80 and 443 on the router to the machine is enough. Behind CGNAT that does not work — ask your ISP for a dedicated IP, or move to a VPS.
Way out 2: go through a tunnel
When the machine is paired with Keenrig Cloud and still cannot be reached from outside, the installer sets up a Cloudflare tunnel. Traffic goes: browser → Cloudflare → your machine. Nothing listens on a public port, and nothing needs to.
- The tunnel is a Keenrig Cloud service, included from the Standard plan.
- Cloudflare terminates HTTPS at its edge, which means it can read the traffic passing through. If that is not acceptable for your data, use a VPS with a public IP.
- Unplug the cloud and the tunnel stops: apps are reachable only on your local network until you open the ports or move to a server with a public IP.