WEBSITE(7)Miscellaneous Information ManualWEBSITE(7)

website — run httpd, get HTTPS, share it

Every VM has https://name.chroot.run with a valid certificate. The proxy terminates TLS and forwards to one port on the VM, 80 by default. It is private: only you, and the users you add, get through.

Create a VM and run httpd(8) on port 8080:

$ ssh chroot.dev new -n web -w
$ ssh vm+web@chroot.run
web$ printf 'server "web" {\n\tlisten on * port 8080\n}\n' |
    doas tee /etc/httpd.conf >/dev/null
web$ echo 'hi g33ks =]' |
    doas tee /var/www/htdocs/index.html >/dev/null
web$ doas rcctl enable httpd && doas rcctl start httpd

Point the proxy at 8080:

$ ssh chroot.dev share port web 8080

The browser has no ssh key, so it logs in with a one-time link. After that the proxy knows you on every VM you can reach:

$ ssh chroot.dev browser

# one user
$ ssh chroot.dev share add web bob
# everyone, without login
$ ssh chroot.dev share set-public web
# back to you and the users added
$ ssh chroot.dev share set-private web

Requests reach the VM with the logged-in user in ‘X-Fcm-User’, so an application behind the proxy can skip its own login. The proxy removes any ‘X-Fcm-*’ header sent by the client.

browser(1), new(1), share(1), httpd(8)

chroot.devOctober 7, 2026WEBSITE(7)