Calabi edge — self-host an edge for Calabi Cloud (+ an optional mesh relay) on your VPS.
2.2K
calabinet/calabi-edgeCalabi edge — tunnels and mesh relay on your VPS: for Calabi Cloud, or your own Calabi server.
The Calabi edge is the public-facing server you run on a host with a public IP.
Paired with the calabi client, it forwards public HTTP/HTTPS/TCP/UDP traffic to
services on your laptop, LAN, or private network — reverse tunneling over a single
outbound connection, no inbound ports to open on your machine.
This image is configured for Calabi Cloud (Bring-Your-Own-Infrastructure): you run the edge on your own host, and the platform handles identity, domains, and certificates.
With role: both it is also your organization's mesh relay: it helps mesh
devices connect to each other directly, and relays their encrypted traffic when
they cannot.
Without an account: run your own Calabi server, this image together with
calabinet/calabi-coord — see
Your own server below. Open source (Apache-2.0):
https://github.com/calabinet/calabi
The self-hosted-edge wizard in the console is the real setup path: it issues
your edge certificate, generates the complete edge.yaml, and gives you the exact
commands. Full guide → https://calabi.net/docs/self-hosting/your-own-edge
With edge.yaml and the three PEM files from the wizard in one directory
(e.g. /opt/calabi):
# docker-compose.yml
services:
edge:
image: calabinet/calabi-edge:latest
network_mode: host # binds :7443 / :80 / :443 directly
restart: unless-stopped
working_dir: /opt/calabi # so ./edge-tls.crt etc. resolve
volumes:
- /opt/calabi:/opt/calabi # mount the config dir at the SAME path
- /var/lib/calabi/edge:/var/lib/calabi/edge # state.dir — see below
command: ["-config", "/opt/calabi/edge.yaml"]
Open these inbound ports on your firewall:
:7443 — control channel for your daemons
:80 + :443 — visitor traffic (your tunnels, on your own domain)
:3340 (TCP) + :3478/udp — mesh relay, only if your edge.yaml sets role: both
The -config path must be inside the mounted directory. Otherwise the edge
exits at once with load config: read config ...: no such file or directory.
Mount state.dir (/var/lib/calabi/edge in the wizard's config), as
above. It holds the counter behind auto-assigned subdomains (u000001, …) and
the cached self-signed certificate. Without the mount it is lost when the
container is recreated or updated, and new tunnels then fail to come up. To
keep to one mount, point state.dir inside the directory you already mount
(/opt/calabi/state).
No Calabi account: the coordinator and this edge on one machine, from one
.env. Devices join with an invite from the coordinator, which is also what
this edge checks them against.
mkdir calabi && cd calabi
curl -fsSLO https://raw.githubusercontent.com/calabinet/calabi/main/deploy/server/docker-compose.yml
curl -fsSL -o .env https://raw.githubusercontent.com/calabinet/calabi/main/deploy/server/.env.example
# edit .env, then:
docker compose up -d
docker compose exec coord calabi-coord invite --note laptop
Ports, devices, backups: https://github.com/calabinet/calabi/tree/main/deploy/server
latest — most recent releasex.y.z — pinned versionBoth tags are multi-arch (linux/amd64 + linux/arm64); Docker picks the right
one for your VPS.
Keep the edge on the same version as the clients using it. An older edge
misses newer tunnel settings: before 1.10.0, a tunnel that uses an
organization sign-in application is served with no sign-in at all, and
no access records are collected.
Content type
Image
Digest
sha256:362189ef8…
Size
9.7 MB
Last updated
2 days ago
docker pull calabinet/calabi-edge