Sign inSign up

calabinet/calabi-edge

By calabinet

•Updated 2 days ago

Calabi edge — self-host an edge for Calabi Cloud (+ an optional mesh relay) on your VPS.

Image
Networking
Developer tools
0

2.2K

calabinet/calabi-edge repository overview

⁠Docker Hub page — calabinet/calabi-edge

⁠Short description

Calabi edge — tunnels and mesh relay on your VPS: for Calabi Cloud, or your own Calabi server.

⁠Overview

⁠Calabi Edge

The Calabi edge is the public-facing server you run on a host with a public IP. Paired with the calabi client, it forwards public HTTP/HTTPS/TCP/UDP traffic to services on your laptop, LAN, or private network — reverse tunneling over a single outbound connection, no inbound ports to open on your machine.

This image is configured for Calabi Cloud (Bring-Your-Own-Infrastructure): you run the edge on your own host, and the platform handles identity, domains, and certificates.

With role: both it is also your organization's mesh relay: it helps mesh devices connect to each other directly, and relays their encrypted traffic when they cannot.

Without an account: run your own Calabi server, this image together with calabinet/calabi-coord⁠ — see Your own server⁠ below. Open source (Apache-2.0): https://github.com/calabinet/calabi⁠

⁠Setup (BYOI)

The self-hosted-edge wizard in the console is the real setup path: it issues your edge certificate, generates the complete edge.yaml, and gives you the exact commands. Full guide → https://calabi.net/docs/self-hosting/your-own-edge⁠

With edge.yaml and the three PEM files from the wizard in one directory (e.g. /opt/calabi):

# docker-compose.yml
services:
  edge:
    image: calabinet/calabi-edge:latest
    network_mode: host          # binds :7443 / :80 / :443 directly
    restart: unless-stopped
    working_dir: /opt/calabi    # so ./edge-tls.crt etc. resolve
    volumes:
      - /opt/calabi:/opt/calabi # mount the config dir at the SAME path
      - /var/lib/calabi/edge:/var/lib/calabi/edge   # state.dir — see below
    command: ["-config", "/opt/calabi/edge.yaml"]

Open these inbound ports on your firewall:

  • :7443 — control channel for your daemons

  • :80 + :443 — visitor traffic (your tunnels, on your own domain)

  • :3340 (TCP) + :3478/udp — mesh relay, only if your edge.yaml sets role: both

  • The -config path must be inside the mounted directory. Otherwise the edge exits at once with load config: read config ...: no such file or directory.

  • Mount state.dir (/var/lib/calabi/edge in the wizard's config), as above. It holds the counter behind auto-assigned subdomains (u000001, …) and the cached self-signed certificate. Without the mount it is lost when the container is recreated or updated, and new tunnels then fail to come up. To keep to one mount, point state.dir inside the directory you already mount (/opt/calabi/state).

⁠Your own server

No Calabi account: the coordinator and this edge on one machine, from one .env. Devices join with an invite from the coordinator, which is also what this edge checks them against.

mkdir calabi && cd calabi
curl -fsSLO https://raw.githubusercontent.com/calabinet/calabi/main/deploy/server/docker-compose.yml
curl -fsSL -o .env https://raw.githubusercontent.com/calabinet/calabi/main/deploy/server/.env.example
# edit .env, then:
docker compose up -d
docker compose exec coord calabi-coord invite --note laptop

Ports, devices, backups: https://github.com/calabinet/calabi/tree/main/deploy/server⁠

⁠Tags

  • latest — most recent release
  • x.y.z — pinned version

Both tags are multi-arch (linux/amd64 + linux/arm64); Docker picks the right one for your VPS.

Keep the edge on the same version as the clients using it. An older edge misses newer tunnel settings: before 1.10.0, a tunnel that uses an organization sign-in application is served with no sign-in at all, and no access records are collected.

Tag summary

Content type

Image

Digest

sha256:362189ef8…

Size

9.7 MB

Last updated

2 days ago

docker pull calabinet/calabi-edge