Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 18 additions & 11 deletions src/frontend/src/content/docs/integrations/devtools/dev-tunnels.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,9 @@ Dev tunnels are useful for:

- Sharing a running local service (for example, a Web API) with teammates, mobile devices, or webhooks
- Testing incoming callbacks from external SaaS systems (GitHub / Stripe / etc.) without deploying
- Quickly publishing a temporary, TLS-terminated endpoint during development
- Sharing a running local service (for example, a Web API) with teammates, mobile devices, or webhooks.
- Testing incoming callbacks from external SaaS systems (GitHub / Stripe / etc.) without deploying.
- Quickly publishing a temporary, TLS-terminated endpoint during development.
Comment on lines +32 to +34

<Aside type="note">
By default tunnels require authentication and are available only to the user
Expand Down Expand Up @@ -107,7 +109,7 @@ When you run the AppHost, the dev tunnel is created to expose the web applicatio

### Allow anonymous access

To allow anonymous (public) access to the entire tunnel, chain a call to the `WithAnonymousAccess` method:
To allow anonymous, public access to the entire tunnel, chain a call to the `WithAnonymousAccess` method:

<Tabs syncKey="aspire-lang">
<TabItem id="csharp" label="C#">
Expand Down Expand Up @@ -206,7 +208,8 @@ const tunnel = await builder.addDevTunnel("mixed-access")
The preceding code exposes:

- The `public` endpoint of the `api` project with anonymous access
- The `admin` endpoint of the `api` project that requires authentication
- The `public` endpoint of the `api` project with anonymous access.
- The `admin` endpoint of the `api` project that requires authentication.

### Show tunnel URLs

Expand Down Expand Up @@ -246,7 +249,7 @@ This lets downstream resources use the tunneled address exactly like any other A
</Aside>

## Configuration

Use the following properties to configure you dev tunnels:
### Dev tunnel options

The `DevTunnelOptions` class provides several configuration options:
Expand Down Expand Up @@ -274,39 +277,43 @@ The `DevTunnelPortOptions` class provides configuration for individual tunnel po
| `Labels` | Labels to apply to this port |
| `AllowAnonymous` | Whether to allow anonymous access to this specific port |

### Security considerations
## Security recommendations

- Prefer authenticated tunnels during normal development
- Only enable anonymous access for endpoints that are safe to expose publicly
- Treat public tunnel URLs as temporary & untrusted (rate limit / validate input server-side)

### Tunnel lifecycle
## Tunnel lifecycle

Dev tunnels automatically:

- Install the devtunnel CLI if not already available
- Ensure the user is logged in to the dev tunnels service
- Create and manage tunnel lifecycle
- Clean up unmodeled ports from previous runs
- Provide detailed logging and diagnostics
- Install the devtunnel CLI if not already available.
- Ensure the user is logged in to the dev tunnels service.
- Create and manage tunnel lifecycle.
- Clean up unmodeled ports from previous runs.
- Provide detailed logging and diagnostics.

Tunnels will expire after not being hosted for 30 days by default, so they won't be forcibly deleted when the resource or AppHost is stopped.

### Troubleshooting
## Troubleshooting

#### Authentication required
### Authentication required

If you see authentication errors, ensure you're logged in to the dev tunnels service:

```bash
devtunnel user login
```

#### Port conflicts
### Port conflicts

If you encounter port binding issues, check that no other processes are using the same ports, or configure different ports for your endpoints.

#### Tunnel not accessible
### Tunnel not accessible

Verify that:

Expand Down
Loading