Guides
Agent and CLI
One program, infraflow, runs on the machine whose services you want to reach from outside. It dials out to the edge: nothing is opened on the router.
Guides
One program, infraflow, runs on the machine whose services you want to reach from outside. It dials out to the edge: nothing is opened on the router.
Installing needs no token. Pick whichever is at hand:
npm install -g infraflow # or: npx infraflow <command>
curl -fsSL https://infraflow.app/install.sh | sh
irm https://infraflow.app/install.ps1 | iex
What you sign in with depends on what you want to do. The two are independent: a laptop can deploy without serving tunnels, and a server the other way round.
infraflow auth ifl_… --api https://api.infraflow.app
infraflow login ifm_… --api https://api.infraflow.app
Signing a machine in installs a background service, so its tunnels come back when it restarts. To install and sign a machine in at once:
curl -fsSL https://infraflow.app/install.sh | sh -s -- ifm_…
$env:INFRAFLOW_TOKEN = "ifm_…"; irm https://infraflow.app/install.ps1 | iex
infraflow tunnel http 3000 # https://<random>.http.infraflow.app infraflow tunnel tcp 3810 --name game # game.tcp.infraflow.app:<public port> infraflow tunnel udp 192.168.1.20:27015 # another device on the local network infraflow tunnel list infraflow tunnel delete tcp 3810 # by local port, or by name infraflow delete tcp 3810 # the same
--name the hostname is random. The same command with the same --name and another port points the existing tunnel at the new port; its address does not change.| Command | What it does |
|---|---|
infraflow login <token> | Signs the machine in and installs the background service. --api names another platform; --no-service skips the service. |
infraflow logout | Signs out and removes the service. Tunnels keep their addresses until deleted. |
infraflow status | The machine, its workspace, whether the service runs, and its tunnels. |
infraflow tunnel http|tcp|udp <target> | Exposes a local port, or host:port. --name sets the hostname's first label. |
infraflow tunnel list | This machine's tunnels, with their local service and whether they are online. |
infraflow tunnel delete <protocol> <target or name> | Deletes a tunnel and releases its address. |
infraflow run | Serves the tunnels in the foreground: what the service runs. For containers and systems without a service manager. |
infraflow service install|uninstall|status | Manages the background service. |
Besides its tunnels, the same program works on a workspace: its services, their logs, deployments and variables, and its Workers. It does so as an API token (Settings, then API tokens), kept apart from the machine's own sign-in.
infraflow auth ifl_…
| Command | What it does |
|---|---|
infraflow services | Lists the services with their status and address. |
infraflow logs <service> [--follow] [--search text] | Shows what a service printed; --follow keeps showing new lines. |
infraflow deploy <service> [--no-wait] | Deploys it again and follows the deployment to its end. Fails, with the reason, if the deployment does: usable as a step in CI. |
infraflow env list|set|unset <service> … | Reads the names of its variables; sets NAME=value pairs; removes names. Applied at the next deployment. |
infraflow up [service] [dir] [--project slug] [--port n] | Sends a folder to be built and deployed, without a repository. The service is created if it is new. A Dockerfile is used when there is one; the language is detected otherwise. Dependencies, build output, .git and .env stay on your machine. At most 32 MB once packed. |
| System | How it runs | Its output |
|---|---|---|
| Linux, as root | systemd unit infraflow.service, started at boot | journalctl -u infraflow -f |
| Linux, as a user | systemd user unit; at boot if lingering is allowed, otherwise at login | journalctl --user -u infraflow -f |
| macOS | launchd agent at login; a daemon at boot when installed with sudo | ~/Library/Logs/infraflow.log |
| Windows | Hidden process, started again at each logon; no administrator rights, and the terminal can be closed | %APPDATA%\\infraflow\\agent.log |
In a container, skip the service and make infraflow run the command, with the sign-in mounted or INFRAFLOW_CONFIG_DIR pointing at it.
Regenerate it from the machine's menu in the dashboard. The old token stops working at once and the machine's tunnels go offline; run infraflow login with the new one and they return at the same addresses.
| Variable | Meaning |
|---|---|
INFRAFLOW_API | The platform's API, instead of --api. |
INFRAFLOW_CONFIG_DIR | Where the sign-in is kept, instead of the user's configuration directory. |
INFRAFLOW_TRANSPORT | auto, quic or websocket. |
INFRAFLOW_CA_CERT | A PEM certificate authority to trust besides the public ones, for a platform with a private one. |
infraflow link <service> |
| Remembers which service this folder is (in .infraflow.json), so that up, run, deploy, logs and shell need not be told. |
infraflow run [--service name] -- <command> | Runs a command on your machine with the service's variables: a development server, a migration. Exits with what the command exited with. |
infraflow shell [service] [-- command] | Opens a prompt in the service's container, or runs one command there. |
infraflow worker deploy <name> [dir] [--project slug] | Publishes a folder (worker.js and what it imports) as a Worker, creating it if it is new, and follows the deployment. |
In CI, set INFRAFLOW_API_TOKEN and INFRAFLOW_ORG instead of signing in: nothing is written to disk.