Choose how evertap is reached
Until you choose, evertap listens on 127.0.0.1 alone, and no other machine can reach it. You choose
with evertap setup on the machine running evertap, from three modes. The mode decides where the UI
listens and how browsers and the CLI get there. It never changes connection details: apps connect
to ev.internal on each engine's standard port in every mode, so a project's .env stays the same
(Connect from your laptop).
local | network | cloudflare | |
|---|---|---|---|
| Setup calls it | This computer only | Your network | Cloudflare Tunnel |
| For | evertap on the computer you develop on | A home server or VPS reached over your LAN, Tailscale, or a proxy | A machine reached through Cloudflare, with no open ports |
| You provide | Your password for sudo, once | Your network, or a reverse proxy and its address | A domain on Cloudflare and an API token, once |
| The UI's address | http://ev.internal:8080 | http://<this machine's address>:8080, or your proxy's address | https://evertap.<your domain>, or your own tunnel's address |
| Apps reach databases | Directly | Through evertap connect on each laptop | Through evertap connect on each laptop |
| The first sign-in | Setup opens a signed-in browser | Setup prints a one-time link and QR code | Setup prints a one-time link and QR code |
Sign-in is required in every mode, wherever a request comes from (Security).
Which one to pick
- evertap runs on the computer where you run your apps, and only you use it:
local. - A home server, and your devices are on the same network:
network, choosing "Other devices on your network". It serves plain HTTP on your network. - You use Tailscale:
network. Either listen on the machine's Tailscale address, or put Tailscale Serve in front for HTTPS (below). - A VPS:
networkbehind your own reverse proxy with HTTPS, such as Caddy or nginx (Reverse proxies), orcloudflare. Do not have evertap listen on every interface of a VPS: that opens the sign-in page to the internet over plain HTTP, and setup and the log warn about it. - A machine that takes no incoming connections, such as one behind a router you do not control,
and you want it reachable from anywhere:
cloudflare(Cloudflare Tunnel).
local: this computer only
Apps on this computer connect to ev.internal directly. There is no evertap connect and nothing
to sign in from elsewhere.
Choosing it in setup points ev.internal at evertap's own loopback address, 127.77.0.1, with one
sudo prompt:
- It adds
127.77.0.1 ev.internalto/etc/hosts. - On macOS, which has only 127.0.0.1 on loopback, it adds
127.77.0.1tolo0, and a startup job (/Library/LaunchDaemons/evertap.loopback.plist) that adds it again after a restart.
If sudo fails, setup saves nothing and prints the changes to make by hand. Choosing another mode in
setup, or evertap uninstall, removes them again.
evertap then listens on 127.77.0.1: databases and buckets on their standard ports (5432, 3306,
6379, 9000, 3900) and the UI on 8080. That address is apart from 127.0.0.1, so a database you run
yourself on 127.0.0.1:5432 keeps working beside evertap. Something that listens on every address
does not:
- A program or a Compose file with
"5432:5432"that is running keeps evertap from listening on that port. - While evertap runs, such a Compose file fails to start.
Publish it on 127.0.0.1 instead, as "127.0.0.1:5432:5432". Setup and the Doctor name each Docker
container that clashes with evertap.
Only programs on this computer reach evertap in this mode, and not from inside a container on it: an app that runs in Docker keeps its database in its own Compose file. Under WSL, Windows apps do not reach an evertap running inside WSL.
network: your network
Setup asks where browsers come from:
| Choice | evertap listens on | The address browsers use |
|---|---|---|
| Other devices on your network | Every interface (0.0.0.0) | This machine's address on your network, such as http://192.168.1.20:8080, unless you give another |
| A proxy on this machine | 127.0.0.1 | The address your proxy serves, such as https://evertap.example.com |
| A proxy run with Docker | Docker's bridge address, usually 172.17.0.1 (docker0) | The address your proxy serves |
Behind a proxy, setup prints a Caddy and an nginx configuration for your answers and checks that the address reaches this evertap (Reverse proxies). "A proxy run with Docker" is for Docker Engine on Linux, where Docker's bridge is an address of the machine itself.
To listen on one address of this machine instead, such as its Tailscale address, pass it as a flag:
evertap setup --mode network --listen 100.101.102.103.
The names evertap answers to
evertap answers only to requests that name the address you gave in setup, localhost, an IP
address, or its name on your network (EVERTAP_HOST, evertap.local unless set). Any other name
gets "evertap does not answer to this address". This stops a web page that points its own name at
your machine from talking to evertap. If you open evertap at a name, give that name as its address
in setup. evertap does not announce evertap.local itself; it only answers to it when something on
your network resolves it.
Plain HTTP on your network
Without a proxy, evertap serves plain HTTP. Anyone who can watch the traffic on that network can
read the sign-in cookies and the token evertap login saves, and act as you. evertap login warns
about this. Use it on a network you trust, or over Tailscale, which encrypts the traffic, or behind
a proxy with HTTPS.
If this machine has an address the internet routes to, listening on every interface opens the sign-in page there too. Setup, Settings, and the log warn about it. Block that port in your firewall, or choose a proxy with HTTPS.
Tailscale
evertap does not set up Tailscale; install it yourself. Then, on the machine running evertap, either:
- Listen on its Tailscale address, and open evertap there:
evertap setup --mode network --listen <its 100.x address>. Tailscale encrypts the traffic, and the UI is not open on your other networks. To open evertap at its MagicDNS name, add--url http://<name>:8080. If evertap starts before Tailscale has its address, it stops with an error; the systemd unit starts it again 5 seconds later. - Or put Tailscale Serve in front for HTTPS, and choose "A proxy on this machine" with the address
Serve gives,
https://<machine>.<tailnet>.ts.net(Reverse proxies).
cloudflare: Cloudflare Tunnel
Setup creates a Cloudflare Tunnel, its DNS record, and the rest from an API token you paste once,
and evertap runs cloudflared and opens at https://evertap.<your domain>. evertap does not keep the
token. Or you run a tunnel yourself that sends your hostname to http://127.0.0.1:8080, and give
setup its address. evertap keeps the UI on 127.0.0.1, so the machine needs no open ports. The CLI
goes through the tunnel too, even on the same network. See Cloudflare Tunnel.
Changing the mode later
- Run
evertap setupagain on the machine running evertap. The change applies without a restart. If something cannot listen at the new address, evertap keeps the old settings and says why. - Or, in the UI, open Settings → Access. It shows the mode, the address, where the UI and the
databases listen, and which values environment variables fix. It changes the mode only when the
change keeps your browser connected, and otherwise says to run
evertap setup. It cannot change or remove a tunnel setup created, which takes a Cloudflare token. EVERTAP_MODE,EVERTAP_PUBLIC_URL, andEVERTAP_LISTEN_HOSTwin over what setup saved, and setup shows them instead of asking (Configuration).
The evertap name and logo are not licensed with the code (section 6 of the license). You may use them to refer to evertap, but not to name or brand your own product or service, or in a way that suggests evertap made or endorses it, without permission.
evertap is an independent project. It is not affiliated with, endorsed, sponsored, supported, or certified by the owners of the software it runs, and it uses their names only to say which software that is.
- Postgres, PostgreSQL and the Slonik Logo are trademarks or registered trademarks of the PostgreSQL Community Association of Canada, and used with their permission.
- MySQL is a registered trademark of Oracle and/or its affiliates.
- Redis is a registered trademark of Redis Ltd. Any rights therein are reserved to Redis Ltd.
- RustFS is a trademark of RustFS, Inc.
- Other names, including Garage, may be trademarks of their respective owners.