# Zrok Self Host with dynamic ip and cloudns

**URL:** <https://openziti.discourse.group/t/zrok-self-host-with-dynamic-ip-and-cloudns/4206>\
**Category:** zrok\
**Created:** [March 18, 2025, 9:23pm UTC](https://openziti.discourse.group/t/zrok-self-host-with-dynamic-ip-and-cloudns/4206 "2025-03-18T21:23:05Z")\
**Posts on this page:** 4\
**Page:** 3

<div class="post-metadata">

**Author:** ![zebbit](https://avatars.discourse-cdn.com/v4/letter/z/b4bc9f/32.png) [@zebbit](https://openziti.discourse.group/u/zebbit)\
**Post date:** [May 21, 2025, 4:22pm UTC](https://openziti.discourse.group/t/zrok-self-host-with-dynamic-ip-and-cloudns/4206/42 "2025-05-21T16:22:49Z")

</div>

Hi Ken, could you please upload the experimental version again? My ISP allowed me to open those ports.

> curl -sSf [https://get.openziti.io/zrok-instance/fetch.bash](https://get.openziti.io/zrok-instance/fetch.bash) | ZROK\_REPO\_ZIP=[https://github.com/openziti/zrok/archive/refs/heads/docker-instance-set-caddy-port.zip](https://github.com/openziti/zrok/archive/refs/heads/docker-instance-set-caddy-port.zip) bash

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [May 21, 2025, 8:36pm UTC](https://openziti.discourse.group/t/zrok-self-host-with-dynamic-ip-and-cloudns/4206/43 "2025-05-21T20:36:10Z")

</div>

Congrats! No need for the experimental version I referenced. Now, the official version of zrok supports setting the Caddy port to something other than 443. It'll use 443 if you don't set it.

---

<div class="post-metadata">

**Author:** ![zebbit](https://avatars.discourse-cdn.com/v4/letter/z/b4bc9f/32.png) [@zebbit](https://openziti.discourse.group/u/zebbit)\
**Post date:** [June 3, 2025, 8:16pm UTC](https://openziti.discourse.group/t/zrok-self-host-with-dynamic-ip-and-cloudns/4206/44 "2025-06-03T20:16:09Z")

</div>

Hi everyone!

# Service ports

ZROK\_CTRL\_PORT=18080  
ZROK\_FRONTEND\_PORT=8080  
ZROK\_OAUTH\_PORT=8081  
ZITI\_CTRL\_ADVERTISED\_PORT=80  
ZITI\_ROUTER\_PORT=3022

Do these ports have to be open on the router? or only the:

ZITI\_CTRL\_ADVERTISED\_PORT  
CADDY\_HTTPS\_PORT  
ZITI\_ROUTER\_PORT

Thanks for answering

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [June 18, 2025, 11:40pm UTC](https://openziti.discourse.group/t/zrok-self-host-with-dynamic-ip-and-cloudns/4206/45 "2025-06-18T23:40:03Z")

</div>

I assume you're following the zrok self-hosting guide for Docker: [Self-hosting guide for Docker | zrok](https://docs.zrok.io/docs/guides/self-hosting/docker/)

You must publish these secure ports mentioned in the guide. These are "secure ports" because they terminate TLS, and so they must be "open" a.k.a. "published" to the web.

- ZITI\_CTRL\_ADVERTISED\_PORT - Ziti controller's TLS server
- ZITI\_ROUTER\_PORT - Ziti router's TLS server
- CADDY\_HTTPS\_PORT or TRAEFIK\_HTTPS\_PORT - a proxy for the insecure ports (default 443)

You should not publish these insecure ports. zrok controller and zrok frontend listen on these ports locally, and they must be published with a TLS proxy like Caddy or Traefik for security.

- ZROK\_CTRL\_PORT
- ZROK\_FRONTEND\_PORT
- ZROK\_OAUTH\_PORT

[Previous page](https://openziti.discourse.group/t/zrok-self-host-with-dynamic-ip-and-cloudns/4206.md?page=2)
