
Sometimes we need a service on a laptop or local VPS to be reachable from the internet — demos for friends, webhooks, or a personal dashboard. With no public IP, an SSH reverse tunnel is the answer.
The basic command is one line: ssh -R 80:localhost:3000 user@server. The server forwards its port 80 to port 3000 on your local machine. The problem: SSH connections can drop at any time.
The tidiest solution on Linux is systemd. Create a service unit with Restart=always and a growing RestartSec (backoff), so the tunnel retries automatically on every failure.
[Unit] Description=Reverse tunnel to server After=network-online.target [Service] ExecStart=/usr/bin/ssh -N -R 80:127.0.0.1:3000 user@server Restart=always RestartSec=10 [Install] WantedBy=multi-user.target
Enable it with systemctl enable --now tunnel.service, and the tunnel lives across reboots and revives itself on drops. Add a small script to log the public URL to a file, so you always know its latest address.
I use this pattern to expose a local dashboard — simple, no extra software, and proven stable for days.

