TunnelTug is the public path for your product: start on a laptop, grow into load-balanced fleets and product stacks, then land multi-region anycast β with meshTLS, operator shells, and kernel replication built into the same binary.
Run a client beside your app. Expose a public face for webhooks, mobile clients, and integration work without redesigning how you ship later.
Add load-balanced tunnel capacity on k3s. Rolling updates keep ingress online. Snapshots restore inventory when capacity restarts.
Reconcile product barges from hub images β gateway, hostPort policy, and 0TrustOS provision env β without day-to-day kubectl.
Geo-distributed anycast and multi-PoP edges with kernel real-time sync. Local embeds stay warm; scale ingress, not a single remote DB.
Dev client, fleets, stacks, and global anycast share one control model. You do not outgrow TunnelTug and start over for production.
Control over QUIC; public edges speak modern HTTP so long-lived streams, uploads, SSE, and WebSockets keep working.
Automatic ACME certificates in production. Operator playbooks cover whitelist, dual-ACME bans, and safe re-issue.
Tunnel capacity registers itself behind a load balancer. k3s barges roll without hard-resetting the whole edge.
YAML barges from the hub. Built-in gateway at /apps/{name}/, hostPort policy (products | all | none), and stack dashboard on one port.
Platform Mesh CA leaves for mesh FQDNs β WebAuthn RP ID, DBSC, SNI. Passkey auth_proxy before gonode shell; no localhost WebAuthn.
Stack pods inject OTRUST_* so images layered on gonode provision mesh PKI, publish names, and phone home to the identity plane.
Multi-region announce and withdraw with health gates. Unhealthy PoPs step aside; clients keep the same hostname.
Describe multi-PoP sites in YAML or set language. One config wires domain, stack, anycast, and kernel peers.
HTTPS cluster peer URLs for ultimate_db / keystore. Products AddPeer β local embeds stay primary, not prefer-remote.
Publish and pull from hub.tunneltug.com. Public pull; authenticated push. Config builder on each catalog card.
Fleet configs and image digests are bound so you can verify production capacity is running the build you intended.
Dashboard sign-in via 0Trust identity and passkeys. Cryptographic tunnel tokens only β mint with -gen-token.
Day-2 ACME, vhosts, fleets, hub publish, mesh DNS, anycast, kernel, site config, diagnostics β open source under docs/playbooks.
Fleet HA, multi-PoP mesh, vhost failover, and image integrity β see Architectures with copyable YAML and Tugconf.
1 tunnels registered Β· public haul edge
Visitors hit a public HTTP/3 edge. TunnelTug carries traffic to your development machine, through a load-balanced fleet, into product stacks with meshTLS operator faces, or multi-region anycast β same haul path, larger footprint.

Public face on tunneltug.com Β· control at tunnel.tunneltug.com Β· images at hub.tunneltug.com Β· meshTLS for operator FQDNs
Create an account, take a tunnel secret from the dashboard, and pick a subdomain for your first public face.
Open dashboardtunneltug -mode client \\ -server tunnel.tunneltug.com \\ -domain tunneltug.com \\ -subdomain myapp \\ -local 3000 \\ -token \"$TUNNELTUG_TOKEN\"
Open https://myapp.tunneltug.com, then grow into fleets, product stacks, site config, and anycast when production needs global ingress. Read the docs β Β· Architectures β Β· Hub β Β· Playbooks β