For this stuff, I'm most excited about https over iroh.
- https://github.com/aflin/iroh-webproxy
- https://github.com/n0-computer/iroh-proxy-utils
No port forwarding. No public IP required. No special proxy to set up.
Iroh already runs public relays. Your two computers will signal through those, and then port-knock and form a direct connection to each other, perfectly encrypted.
We just need to define a new https:// url, like ... let's call it "irohttps://" maybe, so then you could contact my laptop with "irohttps://<hash>/path?query".
iroh-ssh works today: https://github.com/rustonbsd/iroh-ssh
Not perfectly, but good enough for port forwarding web interfaces through cgnat
>and then port-knock and form a direct connection to each other, perfectly encrypted.
so... ICE/TURN/STUN ? Sorry I forgot which one of them actually works, but they do work