Host your game servers and web apps on the public internet — securely, without opening a single port at home. One GUI for Cloudflare Tunnels, WireGuard game-port DNAT and Kubernetes app ingress.
curl -fsSL https://proxyctl.cc/install.sh | bash
Cloudflare Tunnel for web apps. WireGuard + iptables for game ports. One UI for both. Runs on k3s (or any Kubernetes).
Stop hand-editing wg0.conf, iptables and cloudflared YAML. Click an app, click a target, click apply.
Hostname → app, one click. A web route is published as a Cloudflare Tunnel ingress rule — nothing is dropped next to your app. Cloudflare terminates TLS; cloudflared dials out from your cluster. No public ports. No certs to renew.
Players hit a public droplet ($4/mo is plenty); ProxyCTL renders the droplet wg0.conf and the in-cluster wg-gateway rules so packets land on the right Service.
Hook up a scoped Cloudflare API token and ProxyCTL writes the DNS itself — A records for game servers, proxied CNAMEs for web apps. Associate domains to servers in one app.
Browse namespaces and Services in your cluster, see ports + pod readiness, pick a target — no ClusterIP copy-paste.
Running servers with GameCTL? ProxyCTL sees the Services it creates — pick one, pick the ports, Apply. Live per-tunnel counters show players connecting. GameCTL can also drive it from the server's own manage screen.
Your home network never exposes anything. The droplet and Cloudflare are the front door; everything dials out.
API + embedded UI in a single container. Stdlib HTTP, no plugin runtime, no agent to install on the target.
ProxyCTL generates its own ed25519 droplet key at setup — the private half stays 0600 on its PVC, is never returned by an API, logged, or sent to the browser. It never holds your ssh-agent or your kubeconfig, and each WireGuard gateway self-generates its keypair so only the public half is ever read back.
Cluster-scoped access is read-only — namespaces, Services, Pods, Endpoints for the target picker, node IPs for the NFS export line. Everything ProxyCTL deploys lives in its own namespace.
There is no reconcile loop. SSH and kubectl fire when you click Apply, and Apply is scoped to the half you're looking at — proxy entries or web apps.
A real control plane — live tunnels with traffic counters, and a setup wizard that preps the droplet for you.



Two real paths, one control plane: web traffic via Cloudflare, game traffic via WireGuard. ProxyCTL is the GUI that drives both.
Anything you want online but don't want to expose at home.
On the roadmap
GameCTLProxyCTL's sibling deploys and manages the game servers themselves — 24 games with guided wizards, live status, live RCON control panels and scheduled backups, on your own Kubernetes cluster. Deploy with GameCTL, publish with ProxyCTL; GameCTL's manage screen drives ProxyCTL directly, so publishing is a button on the server.
curl -fsSL https://gamectl.cc/install.sh | bash
gamectl.cc ↗ — same single-binary design, same one-command install.