- Run the server on a public host. Point DNS at it: an A/AAAA record for the admin host, and one for each frontend domain you'll create. The server checks this at startup — if
SEIKAN_ADMIN_HOSTdoesn't resolve to one of the machine's own network interfaces, it refuses to run rather than starting "successfully" and silently failing to ever get a certificate. Behind Docker/NAT/a reverse proxy, where the local interface address is never the public-facing one, setSEIKAN_SKIP_ADMIN_HOST_CHECK=trueto bypass the check. - Open
:80and:443(both required for ACME;:443also carries the client tunnels, told apart from browser traffic by ALPN) and the TCP frontend range. - Start with
SEIKAN_ACME_STAGING=true; once names resolve and tunnels work, switch to production and restart. - The systemd installer runs the server as an unprivileged user with
CAP_NET_BIND_SERVICEand a hardened unit (ProtectSystem=strict, syscall filtering, namespace/address-family restrictions).
HTTP/2 on :443 is intentionally disabled (keeps websocket handling simple; little benefit given the single multiplexed tunnel).