evertap

Choose how evertap is reached

Until you choose, evertap listens on 127.0.0.1 alone, and no other machine can reach it. You choose with evertap setup on the machine running evertap, from three modes. The mode decides where the UI listens and how browsers and the CLI get there. It never changes connection details: apps connect to ev.internal on each engine's standard port in every mode, so a project's .env stays the same (Connect from your laptop).

localnetworkcloudflare
Setup calls itThis computer onlyYour networkCloudflare Tunnel
Forevertap on the computer you develop onA home server or VPS reached over your LAN, Tailscale, or a proxyA machine reached through Cloudflare, with no open ports
You provideYour password for sudo, onceYour network, or a reverse proxy and its addressA domain on Cloudflare and an API token, once
The UI's addresshttp://ev.internal:8080http://<this machine's address>:8080, or your proxy's addresshttps://evertap.<your domain>, or your own tunnel's address
Apps reach databasesDirectlyThrough evertap connect on each laptopThrough evertap connect on each laptop
The first sign-inSetup opens a signed-in browserSetup prints a one-time link and QR codeSetup prints a one-time link and QR code

Sign-in is required in every mode, wherever a request comes from (Security).

Which one to pick

  • evertap runs on the computer where you run your apps, and only you use it: local.
  • A home server, and your devices are on the same network: network, choosing "Other devices on your network". It serves plain HTTP on your network.
  • You use Tailscale: network. Either listen on the machine's Tailscale address, or put Tailscale Serve in front for HTTPS (below).
  • A VPS: network behind your own reverse proxy with HTTPS, such as Caddy or nginx (Reverse proxies), or cloudflare. Do not have evertap listen on every interface of a VPS: that opens the sign-in page to the internet over plain HTTP, and setup and the log warn about it.
  • A machine that takes no incoming connections, such as one behind a router you do not control, and you want it reachable from anywhere: cloudflare (Cloudflare Tunnel).

local: this computer only

Apps on this computer connect to ev.internal directly. There is no evertap connect and nothing to sign in from elsewhere.

Choosing it in setup points ev.internal at evertap's own loopback address, 127.77.0.1, with one sudo prompt:

  • It adds 127.77.0.1 ev.internal to /etc/hosts.
  • On macOS, which has only 127.0.0.1 on loopback, it adds 127.77.0.1 to lo0, and a startup job (/Library/LaunchDaemons/evertap.loopback.plist) that adds it again after a restart.

If sudo fails, setup saves nothing and prints the changes to make by hand. Choosing another mode in setup, or evertap uninstall, removes them again.

evertap then listens on 127.77.0.1: databases and buckets on their standard ports (5432, 3306, 6379, 9000, 3900) and the UI on 8080. That address is apart from 127.0.0.1, so a database you run yourself on 127.0.0.1:5432 keeps working beside evertap. Something that listens on every address does not:

  • A program or a Compose file with "5432:5432" that is running keeps evertap from listening on that port.
  • While evertap runs, such a Compose file fails to start.

Publish it on 127.0.0.1 instead, as "127.0.0.1:5432:5432". Setup and the Doctor name each Docker container that clashes with evertap.

Only programs on this computer reach evertap in this mode, and not from inside a container on it: an app that runs in Docker keeps its database in its own Compose file. Under WSL, Windows apps do not reach an evertap running inside WSL.

network: your network

Setup asks where browsers come from:

Choiceevertap listens onThe address browsers use
Other devices on your networkEvery interface (0.0.0.0)This machine's address on your network, such as http://192.168.1.20:8080, unless you give another
A proxy on this machine127.0.0.1The address your proxy serves, such as https://evertap.example.com
A proxy run with DockerDocker's bridge address, usually 172.17.0.1 (docker0)The address your proxy serves

Behind a proxy, setup prints a Caddy and an nginx configuration for your answers and checks that the address reaches this evertap (Reverse proxies). "A proxy run with Docker" is for Docker Engine on Linux, where Docker's bridge is an address of the machine itself.

To listen on one address of this machine instead, such as its Tailscale address, pass it as a flag: evertap setup --mode network --listen 100.101.102.103.

The names evertap answers to

evertap answers only to requests that name the address you gave in setup, localhost, an IP address, or its name on your network (EVERTAP_HOST, evertap.local unless set). Any other name gets "evertap does not answer to this address". This stops a web page that points its own name at your machine from talking to evertap. If you open evertap at a name, give that name as its address in setup. evertap does not announce evertap.local itself; it only answers to it when something on your network resolves it.

Plain HTTP on your network

Without a proxy, evertap serves plain HTTP. Anyone who can watch the traffic on that network can read the sign-in cookies and the token evertap login saves, and act as you. evertap login warns about this. Use it on a network you trust, or over Tailscale, which encrypts the traffic, or behind a proxy with HTTPS.

If this machine has an address the internet routes to, listening on every interface opens the sign-in page there too. Setup, Settings, and the log warn about it. Block that port in your firewall, or choose a proxy with HTTPS.

Tailscale

evertap does not set up Tailscale; install it yourself. Then, on the machine running evertap, either:

  • Listen on its Tailscale address, and open evertap there: evertap setup --mode network --listen <its 100.x address>. Tailscale encrypts the traffic, and the UI is not open on your other networks. To open evertap at its MagicDNS name, add --url http://<name>:8080. If evertap starts before Tailscale has its address, it stops with an error; the systemd unit starts it again 5 seconds later.
  • Or put Tailscale Serve in front for HTTPS, and choose "A proxy on this machine" with the address Serve gives, https://<machine>.<tailnet>.ts.net (Reverse proxies).

cloudflare: Cloudflare Tunnel

Setup creates a Cloudflare Tunnel, its DNS record, and the rest from an API token you paste once, and evertap runs cloudflared and opens at https://evertap.<your domain>. evertap does not keep the token. Or you run a tunnel yourself that sends your hostname to http://127.0.0.1:8080, and give setup its address. evertap keeps the UI on 127.0.0.1, so the machine needs no open ports. The CLI goes through the tunnel too, even on the same network. See Cloudflare Tunnel.

Changing the mode later

  • Run evertap setup again on the machine running evertap. The change applies without a restart. If something cannot listen at the new address, evertap keeps the old settings and says why.
  • Or, in the UI, open Settings → Access. It shows the mode, the address, where the UI and the databases listen, and which values environment variables fix. It changes the mode only when the change keeps your browser connected, and otherwise says to run evertap setup. It cannot change or remove a tunnel setup created, which takes a Cloudflare token.
  • EVERTAP_MODE, EVERTAP_PUBLIC_URL, and EVERTAP_LISTEN_HOST win over what setup saved, and setup shows them instead of asking (Configuration).
Edit on GitHub

The evertap name and logo are not licensed with the code (section 6 of the license). You may use them to refer to evertap, but not to name or brand your own product or service, or in a way that suggests evertap made or endorses it, without permission.

evertap is an independent project. It is not affiliated with, endorsed, sponsored, supported, or certified by the owners of the software it runs, and it uses their names only to say which software that is.

  • Postgres, PostgreSQL and the Slonik Logo are trademarks or registered trademarks of the PostgreSQL Community Association of Canada, and used with their permission.
  • MySQL is a registered trademark of Oracle and/or its affiliates.
  • Redis is a registered trademark of Redis Ltd. Any rights therein are reserved to Redis Ltd.
  • RustFS is a trademark of RustFS, Inc.
  • Other names, including Garage, may be trademarks of their respective owners.

On this page