Choosing an External Access Method
SetFN SpaceBuilder can be used right away on the same network immediately after installation. To access it from outside the office or over a mobile network, you need to establish a secure connection path between the server and the outside internet.
This may sound complicated at first, but the goal is simple.
https://space.example.com
↓
External access connection method
↓
http://localhost:8510
Using Cloudflare Tunnel, you can set up this connection relatively easily. You don't need to expose the server's port directly to the internet, and Cloudflare handles the HTTPS certificate and domain connection for you.
First, check whether you actually need external access
If you'll only use it within the same office or Wi-Fi network, you don't need to configure external access. Connect using the internal IP address as described in Checking Your Space Access Address.
External access configuration is needed in the following situations.
- Accessing your space from home or while traveling
- Accessing it over mobile data
- Sharing a link with external partners or customers
- Using a single space across multiple business locations or networks
Which method should you choose?
| Method | Recommended for | Advantages | What you manage directly |
|---|---|---|---|
| Cloudflare Tunnel (recommended) | Users configuring external access for the first time, environments without a fixed public IP | No need to open router ports, keeps the origin server IP private, easy HTTPS and domain connection | Cloudflare account, domain, cloudflared service |
| Caddy reverse proxy | Users running their own server who want to keep the setup simple | Simple configuration, automatic HTTPS certificate issuance and renewal | DNS, public IP, firewall, port forwarding, Caddy |
| NGINX reverse proxy | Organizations with existing NGINX infrastructure or a need for fine-grained control | Highly flexible configuration, easy integration with existing web infrastructure | DNS, certificates, firewall, port forwarding, NGINX |
| Router port forwarding | Test environments, or users who can manage their network directly | Direct connection without a separate tunneling service | Public IP, router, firewall, HTTPS, security updates |
| VPN/private network | Organizations that want to allow access only to their own members privately | Doesn't expose the service to the public internet | VPN server and client device configuration |
Understanding tunneling and reverse proxying
Tunneling
A Connector running inside the server first establishes a secure connection to an external service. Incoming requests then reach the server by following this connection in reverse.
With Cloudflare Tunnel, cloudflared creates an outbound connection from the server to Cloudflare. As a result, in a typical setup you don't need to open ports 80, 443, or 8510 on your router to the outside.
User → Cloudflare → Already-established Tunnel → SetFN :8510
Reverse proxying
Caddy or NGINX first receives external requests and then forwards them to the internal SetFN service. Users connect via https://space.example.com without needing to know about port 8510.
User → Caddy or NGINX :443 → SetFN :8510
A reverse proxy has the advantage of letting you manage HTTPS termination, domain routing, access logs, and rate limiting all in one place.
Recommended method: Cloudflare Tunnel
Cloudflare Tunnel connects an internal service to a public domain without requiring the origin server to have a publicly routable IP address. Because cloudflared initiates the connection to the Cloudflare network, it also reduces paths for direct bypass access to the origin server.
Here's what you can expect when setting it up for the first time.
- No need to configure port forwarding in your router's admin screen
- Relatively unaffected by dynamic public IPs or ISP network conditions
- Use an address in the form
https://space.example.com - Reduced burden of issuing and renewing external certificates
- Optionally restrict allowed users or email domains with Cloudflare Access
- A single Connector can connect multiple internal web services via separate subdomains
Cloudflare Tunnel configuration flow
- Connect the domain you want to use to Cloudflare.
- Create a Tunnel in the Cloudflare dashboard.
- Install
cloudflaredon the SpaceBuilder server. - Run the Connector using the command shown in the dashboard.
- Connect the domain and SetFN address in the Published application.
- Add a Cloudflare Access policy if needed.
- Verify access from an external network.
Use the following values for the Service URL of the Published application.
| Field | Example |
|---|---|
| Public hostname | space.example.com |
| Service type | HTTP |
| Service URL | http://localhost:8510 |
If you changed the SetFN port, enter the actual service port instead of 8510.
Official Cloudflare guides
Cloudflare's screens and installation commands may change, so also check the following official documentation when setting things up.
- Cloudflare Tunnel overview
- Creating a Tunnel from the dashboard
- Installing
cloudflaredby operating system - Connecting a local service to a public domain
- Adding user authentication with Cloudflare Access
Running your own reverse proxy
If you already operate a public IP and server infrastructure, you can connect directly using Caddy or NGINX.
Caddy
Caddy can automatically issue and renew HTTPS certificates once your domain's DNS points to the server and ports 80/443 reach the server, making it a good fit for small self-hosted setups.
space.example.com {
reverse_proxy 127.0.0.1:8510
}
For detailed configuration, see Caddy's reverse proxy quick start.
NGINX
If you're already using NGINX, you can forward HTTPS requests to SetFN's local port.
server {
listen 443 ssl;
server_name space.example.com;
location / {
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_pass http://127.0.0.1:8510;
}
}
The example above shows only the core structure of the proxy. In actual production use, you should also review certificates, WebSocket support, upload size limits, timeouts, and access logging. For details, see the official NGINX reverse proxy guide.
Router port forwarding
This method forwards external ports 80/443 from your router to a reverse proxy server. Rather than exposing SetFN's 8510 port directly to the internet, configure Caddy or NGINX to receive HTTPS requests on port 443 and forward them internally to 8510.
The following conditions are required.
- An internet connection with a publicly accessible public IP
- Router administrator privileges
- A static IP or DHCP reservation so the server's internal IP doesn't change
- A DNS record pointing to the public IP
- Only the necessary ports allowed through the server firewall
- HTTPS certificate issuance and automatic renewal configured
On connections where the ISP uses CGNAT, the WAN IP shown on the router may differ from the actual public IP, which can prevent port forwarding from working. In that case, use Cloudflare Tunnel or a VPN instead.
Preparing a domain
If you have a company domain, it's a good idea to use a subdomain such as space.example.com. If you don't have a domain, you can purchase one from a domain registrar.
To use Cloudflare Tunnel, that domain must be connected as an active Zone in your Cloudflare account. If you're using a reverse proxy directly, point the DNS A or AAAA record to your server's public IP.
Verifying access
After configuration, verify access in the following order.
- Access
http://localhost:8510from the server - Access
http://<server IP>:8510from the same network - Access via the domain over HTTPS
- Access from a mobile data connection with Wi-Fi turned off
- Verify login, file upload, and real-time notification or chat behavior
If internal access fails first, check the SetFN service status first. If internal access works but only the domain access fails, check in this order: Tunnel, DNS, reverse proxy, firewall.
Operations checklist
- Use long, unique passwords for administrators and users
- Disable unnecessary accounts and share links
- Register the Tunnel Connector or reverse proxy as a system service
- Regularly update the Connector, operating system, and proxy
- Check HTTPS certificate expiration and DNS status
- Review external access and administrator activity logs
- Prepare an operating procedure for connecting via the internal address in case of an outage