DOCUMENTATION / REMOTE ACCESS
Your server.
Any distance.
Publish MiniPilot itself through your own Cloudflare Tunnel. Your domain routes to the MiniPilot service on port 8765.
127.0.0.1:8765For local or Wi-Fi access
Keep the default local configuration and use an SSH port forward. No Cloudflare account or internet access is needed for local inspection.
ssh -L 8765:127.0.0.1:8765 ubuntu-user@server-ip1. Point your tunnel at the service
Install cloudflared on the same machine using Cloudflare’s Tunnel instructions. Add a published application route for the same public hostname with service URL http://127.0.0.1:8765. Leave the HTTP Host Header override unset so MiniPilot receives its public hostname.
You do not need to change MiniPilot’s listener to 0.0.0.0 or open a router port. Configure cloudflared as a service if you want remote access to return after a reboot.
2. Sign in through your domain
Open your HTTPS address and sign in with your Ubuntu username and password. Your Ubuntu permissions determine what you can inspect. No Cloudflare Access application, team slug, AUD tag, or MiniPilot domain configuration is required by default.
Use package revision 0.2.0-3 or newer. If you installed an older download, rerun the install command to upgrade. Local browser access and the terminal remain available alongside your domain.
Optional: disable domain access
sudo minipilot configure --local
sudo systemctl restart minipilot.serviceRemove the tunnel route too. If you previously chose local-only mode or configured a different hostname, restore automatic domain access with:
sudo minipilot configure --auto
sudo systemctl restart minipilot.serviceWhere the data goes
Cloudflare terminates the browser’s HTTPS connection and handles tunnel traffic, including credentials submitted through it. MiniPilot makes no external identity-provider requests. Nothing is sent to a MiniPilot or Retailetics backend. If you do not want an intermediary, use the SSH method.