Edge FRP
Language
- TOML configuration, Docker build assets, and Go client process integration.
Runtime Context
- FRPS server in Compose deployment.
- FRPC process managed by the Go client on devices.
Purpose
- Provides reverse proxy tunneling for managed devices so remote access can be exposed through server-side infrastructure.
Key Files
deploy/compose/frps/frps.tomldeploy/compose/docker-compose.ymlpackages/frp/Dockerfilepackages/client/internal/frp/manager.gopackages/client/build/root-dir/usr/share/nixstasis/frpc.tomlpackages/server/lib/nixstasis/devices/ssh_client.ex
Public Interfaces
- FRPS published ports from Compose:
${FRPS_BIND_PORT}${FRPS_HTTP_PORT}${FRPS_TCPMUX_PORT}
- FRPS internal dashboard port:
${FRPS_DASHBOARD_PORT}
- FRPS config fields:
bindPortauth.method = "token"auth.tokenwebServer.portwebServer.userwebServer.passwordtcpmuxHTTPConnectPortvhostHTTPPortsubDomainHost
Dependencies
Internal
- Caddy wildcard and dashboard reverse proxying.
- Go client FRPC manager.
- Server SSH terminal client.
External
- FRP
frpsandfrpcbinaries. sshandncatfor terminal sessions.
Client-Server Interaction Details
- The server stores remote-access intent on devices and exposes the active FRPS
token to clients only through heartbeat
remote_access_tokenresponses. - Client polling reads heartbeat
remote_access_tokenvalues and starts/stops FRPC through a transient systemd unit. A missing or empty token means FRPC should stop or remain stopped. - FRPC reads
/usr/share/nixstasis/frpc.tomldirectly; frpc expands runtime{{ .Envs.* }}placeholders from the session environment. - The FRPS auth token from the heartbeat response is passed from the launcher to
frp-sessionas a systemd credential rather than as asystemd-run --setenvvalue. - Caddy proxies wildcard HTTP traffic to FRPS HTTP vhost port.
- Server SSH terminal uses FRP TCP mux through
ncat --proxy-type http.
Traceable references:
deploy/compose/frps/frps.toml:1-15deploy/compose/docker-compose.yml:33-66packages/client/internal/frp/manager.go:47-137packages/server/lib/nixstasis/devices/ssh_client.ex:30-49