Choosing an External Access Method

SetFN SpaceBuilder can be used right away on the same network immediately after installation. To access it from outside the office or over a mobile network, you need to establish a secure connection path between the server and the outside internet.

This may sound complicated at first, but the goal is simple.

https://space.example.com
        ↓
External access connection method
        ↓
http://localhost:8510

Using Cloudflare Tunnel, you can set up this connection relatively easily. You don't need to expose the server's port directly to the internet, and Cloudflare handles the HTTPS certificate and domain connection for you.

First, check whether you actually need external access

If you'll only use it within the same office or Wi-Fi network, you don't need to configure external access. Connect using the internal IP address as described in Checking Your Space Access Address.

External access configuration is needed in the following situations.

  • Accessing your space from home or while traveling
  • Accessing it over mobile data
  • Sharing a link with external partners or customers
  • Using a single space across multiple business locations or networks

Which method should you choose?

MethodRecommended forAdvantagesWhat you manage directly
Cloudflare Tunnel (recommended)Users configuring external access for the first time, environments without a fixed public IPNo need to open router ports, keeps the origin server IP private, easy HTTPS and domain connectionCloudflare account, domain, cloudflared service
Caddy reverse proxyUsers running their own server who want to keep the setup simpleSimple configuration, automatic HTTPS certificate issuance and renewalDNS, public IP, firewall, port forwarding, Caddy
NGINX reverse proxyOrganizations with existing NGINX infrastructure or a need for fine-grained controlHighly flexible configuration, easy integration with existing web infrastructureDNS, certificates, firewall, port forwarding, NGINX
Router port forwardingTest environments, or users who can manage their network directlyDirect connection without a separate tunneling servicePublic IP, router, firewall, HTTPS, security updates
VPN/private networkOrganizations that want to allow access only to their own members privatelyDoesn't expose the service to the public internetVPN server and client device configuration

Understanding tunneling and reverse proxying

Tunneling

A Connector running inside the server first establishes a secure connection to an external service. Incoming requests then reach the server by following this connection in reverse.

With Cloudflare Tunnel, cloudflared creates an outbound connection from the server to Cloudflare. As a result, in a typical setup you don't need to open ports 80, 443, or 8510 on your router to the outside.

User → Cloudflare → Already-established Tunnel → SetFN :8510

Reverse proxying

Caddy or NGINX first receives external requests and then forwards them to the internal SetFN service. Users connect via https://space.example.com without needing to know about port 8510.

User → Caddy or NGINX :443 → SetFN :8510

A reverse proxy has the advantage of letting you manage HTTPS termination, domain routing, access logs, and rate limiting all in one place.

Cloudflare Tunnel connects an internal service to a public domain without requiring the origin server to have a publicly routable IP address. Because cloudflared initiates the connection to the Cloudflare network, it also reduces paths for direct bypass access to the origin server.

Here's what you can expect when setting it up for the first time.

  • No need to configure port forwarding in your router's admin screen
  • Relatively unaffected by dynamic public IPs or ISP network conditions
  • Use an address in the form https://space.example.com
  • Reduced burden of issuing and renewing external certificates
  • Optionally restrict allowed users or email domains with Cloudflare Access
  • A single Connector can connect multiple internal web services via separate subdomains

Cloudflare Tunnel configuration flow

  1. Connect the domain you want to use to Cloudflare.
  2. Create a Tunnel in the Cloudflare dashboard.
  3. Install cloudflared on the SpaceBuilder server.
  4. Run the Connector using the command shown in the dashboard.
  5. Connect the domain and SetFN address in the Published application.
  6. Add a Cloudflare Access policy if needed.
  7. Verify access from an external network.

Use the following values for the Service URL of the Published application.

FieldExample
Public hostnamespace.example.com
Service typeHTTP
Service URLhttp://localhost:8510

If you changed the SetFN port, enter the actual service port instead of 8510.

Official Cloudflare guides

Cloudflare's screens and installation commands may change, so also check the following official documentation when setting things up.

Running your own reverse proxy

If you already operate a public IP and server infrastructure, you can connect directly using Caddy or NGINX.

Caddy

Caddy can automatically issue and renew HTTPS certificates once your domain's DNS points to the server and ports 80/443 reach the server, making it a good fit for small self-hosted setups.

space.example.com {
    reverse_proxy 127.0.0.1:8510
}

For detailed configuration, see Caddy's reverse proxy quick start.

NGINX

If you're already using NGINX, you can forward HTTPS requests to SetFN's local port.

server {
    listen 443 ssl;
    server_name space.example.com;

    location / {
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
        proxy_set_header X-Forwarded-Proto $scheme;
        proxy_pass http://127.0.0.1:8510;
    }
}

The example above shows only the core structure of the proxy. In actual production use, you should also review certificates, WebSocket support, upload size limits, timeouts, and access logging. For details, see the official NGINX reverse proxy guide.

Router port forwarding

This method forwards external ports 80/443 from your router to a reverse proxy server. Rather than exposing SetFN's 8510 port directly to the internet, configure Caddy or NGINX to receive HTTPS requests on port 443 and forward them internally to 8510.

The following conditions are required.

  • An internet connection with a publicly accessible public IP
  • Router administrator privileges
  • A static IP or DHCP reservation so the server's internal IP doesn't change
  • A DNS record pointing to the public IP
  • Only the necessary ports allowed through the server firewall
  • HTTPS certificate issuance and automatic renewal configured

On connections where the ISP uses CGNAT, the WAN IP shown on the router may differ from the actual public IP, which can prevent port forwarding from working. In that case, use Cloudflare Tunnel or a VPN instead.

Preparing a domain

If you have a company domain, it's a good idea to use a subdomain such as space.example.com. If you don't have a domain, you can purchase one from a domain registrar.

To use Cloudflare Tunnel, that domain must be connected as an active Zone in your Cloudflare account. If you're using a reverse proxy directly, point the DNS A or AAAA record to your server's public IP.

Verifying access

After configuration, verify access in the following order.

  1. Access http://localhost:8510 from the server
  2. Access http://<server IP>:8510 from the same network
  3. Access via the domain over HTTPS
  4. Access from a mobile data connection with Wi-Fi turned off
  5. Verify login, file upload, and real-time notification or chat behavior

If internal access fails first, check the SetFN service status first. If internal access works but only the domain access fails, check in this order: Tunnel, DNS, reverse proxy, firewall.

Operations checklist

  • Use long, unique passwords for administrators and users
  • Disable unnecessary accounts and share links
  • Register the Tunnel Connector or reverse proxy as a system service
  • Regularly update the Connector, operating system, and proxy
  • Check HTTPS certificate expiration and DNS status
  • Review external access and administrator activity logs
  • Prepare an operating procedure for connecting via the internal address in case of an outage