ProxyCTL logo

ProxyCTL

Host your game servers and web apps on the public internet — securely, without opening a single port at home. One GUI for Cloudflare Tunnels, WireGuard game-port DNAT and Kubernetes app ingress.

Public beta · v0.6.17
Web trafficbrowsers, players, clients
ProxyCTLtunnels · DNAT · rules
Your appsK8s Services, game pods
curl -fsSL https://proxyctl.cc/install.sh | bash

Cloudflare Tunnel for web apps. WireGuard + iptables for game ports. One UI for both. Runs on k3s (or any Kubernetes).

Why ProxyCTL

Stop hand-editing wg0.conf, iptables and cloudflared YAML. Click an app, click a target, click apply.

Cloudflare Tunnels, click-not-YAML

Hostname → app, one click. Cloudflare terminates TLS; cloudflared dials out from home. No public ports. No certs to renew.

WireGuard game DNAT

Players hit a public droplet ($4/mo is plenty); ProxyCTL renders the droplet wg0.conf and the in-cluster wg-gateway rules so packets land on the right Service.

Domains managed in-app

Hook up a scoped Cloudflare API token and ProxyCTL writes the DNS itself — A records for game servers, proxied CNAMEs for web apps. Associate domains to servers in one app.

Live Kubernetes picker

Browse namespaces and Services in your cluster, see ports + pod readiness, pick a target — no ClusterIP copy-paste.

Made for GameCTL

Running servers with GameCTL? ProxyCTL sees the Services it creates — pick one, pick the ports, Apply. Live per-tunnel counters show players connecting.

No inbound home ports

Your home network never exposes anything. The droplet and Cloudflare are the front door; everything dials out.

One Go binary

API + embedded UI in a single container. Stdlib HTTP, no plugin runtime, no agent to install on the target.

No stored credentials

Apply uses your ambient ssh-agent and kubectl context. Private keys are never read, rendered, or held in memory.

See it

A real control plane — live tunnels with traffic counters, and a setup wizard that preps the droplet for you.

ProxyCTL tunnels dashboard
The Tunnels dashboard — live entries with per-tunnel traffic counters, plus the guided add-entry form: DNS, cluster target picker, ports.
Live target Service picker
The live target picker — browse your cluster's real Services with ports and pod readiness, click one, and the tunnel binds directly to the in-cluster Service. No NodePort, no port-forward hops.
First-run setup wizard
First-run setup — ProxyCTL SSHes into your $4 droplet and installs WireGuard, iptables and sysctls itself. Idempotent, one time.

How it fits together

Two real paths, one control plane: web traffic via Cloudflare, game traffic via WireGuard. ProxyCTL is the GUI that drives both.

Web traffic

Browser
Cloudflare edge
TLS, DNS, DDoS
▼ tunnel (outbound from home)
ProxyCTL
renders & applies
cloudflared · wg0.conf · wg-gateway

Your apps

K8s web Services
HTTP/HTTPS
Game Services
UDP/TCP, ClusterIP
▲ via wg-gateway pod (10.8.0.2)

Use cases

Anything you want online but don't want to expose at home.

Self-hosted web appsInternal dashboardsHTTP APIs Game servers (UDP/TCP)WebSocket servicesSSH bastions

On the roadmap

Per-app access policyOne-click Cloudflare Access Multi-droplet failoverLive conntrack viewer Audit log export

Need the servers too?

ProxyCTL's sibling, GameCTL, deploys and manages the game servers themselves — 13 games with guided wizards, live status, RCON controls and scheduled backups, on your own Kubernetes cluster. Deploy with GameCTL, publish with ProxyCTL.

curl -fsSL https://gamectl.cc/install.sh | bash

gamectl.cc ↗ — same single-binary design, same one-command install.