Your own relay
Put Link's relay on your Cloudflare account in one command, for networks where no direct path forms.
Most of the time the phone reaches your computer without a relay. A relay is for the networks where it can't: strict mobile carriers, guest Wi-Fi, office networks. Link puts the relay on your own Cloudflare account (the free plan is enough), so nobody else runs a server in your path.
Deploy it
Make a Cloudflare API token. In the Cloudflare dashboard, open My Profile → API Tokens, choose Create Token, and use the Edit Cloudflare Workers template.
Deploy the relay:
link-host relay deployIt asks for the token without showing it (or reads CLOUDFLARE_API_TOKEN), uploads the relay as a Worker named link-relay, waits for its workers.dev address to answer, and prints it:
Your relay is running at wss://link-relay.you.workers.dev
Pair your phone through it:
link-host ssh setup --relay wss://link-relay.you.workers.devIf the token can see several Cloudflare accounts, choose one with --account ACCOUNT_ID.
Pair through it with the command it printed. The relay address is remembered, so later link-host ssh setup runs use it too.
Link Host keeps the token only for the deploy; it isn't stored.
What the relay sees
- Ciphertext. The phone's SSH connection is encrypted to your computer's SSH server; the relay splices bytes it can't read.
- Who's connecting, and when. It admits only phones whose token your computer registered at pairing, and holds only hashes of those tokens.
- Addresses, to introduce the two sides. When both sides can punch a direct path, the relay hands each the other's addresses and steps out; the session then doesn't pass through it.
TURN, for the strictest networks
When both the phone and the computer sit behind NATs that defeat punching, a Cloudflare Realtime TURN key on the relay gives the computer short-lived TURN credentials. It then offers a TURN address as one more way in, still carrying only encrypted SSH. Create a TURN key in the dashboard (Realtime → TURN Server) and deploy with it:
LINK_TURN_KEY_ID=… LINK_TURN_KEY_API_TOKEN=… link-host relay deployA later deploy without these variables keeps the key already on the relay.
Updating or removing it
Run link-host relay deploy again after updating Link Host to update the relay's code. To remove it, delete the Worker in the Cloudflare dashboard; phones paired through it then need pairing again without --relay.