Kepos P2P Tunnel Makes Remote Services Appear Local Without Port Exposure
A developer has built Kepos, an end-to-end encrypted peer-to-peer tunnel that makes remote TCP services appear as local loopback connections on the subscriber's machine. The tool uses HyperDHT and UDX for peer connections, with Protomux multiplexing registry, heartbeat, and per-service channels over a single authenticated connection. A practical use case demonstrated is DeepSeek Harness (dsh), a local-first coding agent that restricts settings access to loopback addresses as a DNS rebinding defense — a restriction Kepos satisfies by terminating the tunnel on a local port. Access control is enforced through publisher and per-service allowlists tied to subscriber public keys, meaning unknown devices cannot reach the service. Kepos remains in developer preview, with limitations including sideload-only Android support, an unsigned macOS build, and no UDP transport.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in