# Zrok self hosted instance

**URL:** <https://openziti.discourse.group/t/zrok-self-hosted-instance/4653>\
**Category:** Uncategorized\
**Created:** [May 28, 2025, 6:09am UTC](https://openziti.discourse.group/t/zrok-self-hosted-instance/4653 "2025-05-28T06:09:35Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tino](https://avatars.discourse-cdn.com/v4/letter/t/9dc877/32.png) [@Tino](https://openziti.discourse.group/u/Tino)\
**Post date:** [May 28, 2025, 6:09am UTC](https://openziti.discourse.group/t/zrok-self-hosted-instance/4653/1 "2025-05-28T06:09:35Z")

</div>

Hi there,

I am trying to setup a self hosted Zrok intance following this video guide: [YouTube](https://www.youtube.com/embed/70zJ_h4uiD8)  
I have successfully started and tested the non TLS variant in a couple of minutes. I have added my custom DNS and made a successful test on a remote machine by sharing the web server on port 80. Then i tried to setup a TLS variant using Caddy. Since i do not want to use plugin for Caddy since i do not have DNS\_PLUGIN\_TOKEN i use the caddy self generated certificate feature. I start the containers ok. I can even do zrok enable on a remote machine using [https://zrok.my.dns.com](https://zrok.my.dns.com). I did the zrok reserve public [http://localhost:80](http://localhost:80) with correct reply: [https://uvqc73ewh1sh.my.dns.com:443](https://uvqc73ewh1sh.my.dns.com:443). The problem is when i do zrok share reserved --headless token i get this error: "[ERROR]: unable to create 'proxy' backend (error listening: failed to listen: no apiSession, authentication attempt failed: Post "[https://ziti.my.dns.com:80/edge/client/v1/authenticate?method=cert](https://ziti.my.dns.com:80/edge/client/v1/authenticate?method=cert)": http: server gave HTTP response to HTTPS client)" i know that https and then port 80 is not valid. This is my .env: "# Required settings  
ZROK\_DNS\_ZONE=[my.dns.com](http://my.dns.com)  
[ZROK\_USER\_EMAIL=emial@something.me](mailto:ZROK_USER_EMAIL=emial@something.me)  
ZROK\_USER\_PWD=zrokuserpw  
ZITI\_PWD=zitiadminpw  
ZROK\_ADMIN\_TOKEN=zroktoken

# Expose services only on localhost (default)

ZROK\_INSECURE\_INTERFACE=0.0.0.0

# Service ports

ZROK\_CTRL\_PORT=18080  
ZROK\_FRONTEND\_PORT=8080  
ZROK\_OAUTH\_PORT=8081  
ZITI\_CTRL\_ADVERTISED\_PORT=80  
ZITI\_ROUTER\_PORT=3022

CADDY\_INTERFACE=0.0.0.0  
CADDY\_HTTPS\_PORT=443

# 🌍 ACME provider (Let's Encrypt default)

CADDY\_ACME\_API=[https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)  
" If i chnage the ZITI\_CTRL\_ADVERTISED\_PORT to 443 containers wont start. Please i need some help with this since it seems it is some wrong config but i can not find it. I have used the compose.yaml from the link and also some custom CaddyFile which looks like this: {  
email {$ZROK\_USER\_EMAIL}  
acme\_ca {$CADDY\_ACME\_API}  
admin {$CADDY\_INTERFACE}:2019  
}

# Ziti Admin Console

ziti.{$ZROK\_DNS\_ZONE} {  
log {  
output stdout  
format console  
level INFO  
}

```
reverse_proxy ziti-quickstart:1280 {
   transport http {
        tls_insecure_skip_verify
    }
}

```

}

# OAuth Frontend

oauth.{$ZROK\_DNS\_ZONE} {  
log {  
output stdout  
format console  
level INFO  
}

```
reverse_proxy zrok-frontend:{$ZROK_OAUTH_PORT}

```

}

# Zrok Controller

zrok.{$ZROK\_DNS\_ZONE} {  
log {  
output stdout  
format console  
level INFO  
}

```
reverse_proxy zrok-controller:{$ZROK_CTRL_PORT}

```

}

# Default frontend (used for tunneling or frontend UI)

frontend.{$ZROK\_DNS\_ZONE} {  
log {  
output stdout  
format console  
level INFO  
}

```
reverse_proxy zrok-frontend:{$ZROK_FRONTEND_PORT} {
    header_up Host {http.request.host}
}

```

}

and compose.override.yml for Caddy: services:  
caddy:  
image: caddy:latest  
restart: unless-stopped  
environment:  
ZROK\_USER\_EMAIL: ${ZROK\_USER\_EMAIL}  
CADDY\_ACME\_API: ${CADDY\_ACME\_API:-[https://acme-v02.api.letsencrypt.org/directory](https://acme-v02.api.letsencrypt.org/directory)}  
ZROK\_DNS\_ZONE: ${ZROK\_DNS\_ZONE}  
ZROK\_CTRL\_PORT: ${ZROK\_CTRL\_PORT:-18080}  
ZROK\_FRONTEND\_PORT: ${ZROK\_FRONTEND\_PORT:-8080}  
ZROK\_OAUTH\_PORT: ${ZROK\_OAUTH\_PORT:-8081}  
ZITI\_CTRL\_ADVERTISED\_PORT: ${ZITI\_CTRL\_ADVERTISED\_PORT}  
CADDY\_INTERFACE: ${CADDY\_INTERFACE}  
expose:  
- ${CADDY\_HTTPS\_PORT:-443}/tcp  
- ${CADDY\_HTTPS\_PORT:-443}/udp  
- 2019/tcp  
ports:  
- ${CADDY\_INTERFACE:-0.0.0.0}:${CADDY\_HTTPS\_PORT:-443}:${CADDY\_HTTPS\_PORT:-443}  
- ${CADDY\_INTERFACE:-0.0.0.0}:80:80  
volumes:  
- ./Caddyfile:/etc/caddy/Caddyfile  
- caddy\_data:/data  
- caddy\_config:/config  
networks:  
zrok-instance:

zrok-frontend:  
environment:  
ZROK\_FRONTEND\_SCHEME: https  
ZROK\_FRONTEND\_PORT: ${CADDY\_HTTPS\_PORT:-443}

volumes:  
caddy\_data:  
caddy\_config:  
Thanks a lot in advance!

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [May 28, 2025, 10:59am UTC](https://openziti.discourse.group/t/zrok-self-hosted-instance/4653/2 "2025-05-28T10:59:24Z")

</div>

hI @Tino, welcome to the comunity and to zrok (and OpenZiti)!

> [@Tino](#):
>
> http: server gave HTTP response to HTTPS client)" i know that https and then port 80 is not valid.

I see below you set `ZITI_CTRL_ADVERTISED_PORT=80`. Is this the actual port your OpenZiti controller is running on? It looks like it to me since that's where your `authenticate` call is going. Did you try to put the controller behind caddy? You can't do that if that's what you did?

It's hard to know exactly where it went wrong, but that's my best guess right now.

---

<div class="post-metadata">

**Author:** ![Tino](https://avatars.discourse-cdn.com/v4/letter/t/9dc877/32.png) [@Tino](https://openziti.discourse.group/u/Tino)\
**Post date:** [May 28, 2025, 12:13pm UTC](https://openziti.discourse.group/t/zrok-self-hosted-instance/4653/3 "2025-05-28T12:13:33Z")

</div>

Hi @TheLumberjack Thank you for your reply! Let me check my config and will get back to you. My idea was: since it was pretty easy to start it without Caddy (no TLS) i got stuck to TLS version. I dont have valid DNS token nor certificate so wanted to use it with Caddy's own generated certificate (without using cloudflare plugin nor any other). If you have some guide for this would appreciate it. In fact i want to setup self host on my office ubuntu pc. Thanks again

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [May 28, 2025, 12:42pm UTC](https://openziti.discourse.group/t/zrok-self-hosted-instance/4653/4 "2025-05-28T12:42:27Z")

</div>

> [@Tino](#):
>
> I dont have valid DNS token nor certificate so wanted to use it with Caddy's own generated certificate

Personally, I use cert-bot and docker and obtain a wildcard cert for my own zrok that way. Once you have a wildcard cert, you can use it for the OpenZiti overlay and also for zrok (or anything). I find that to be the simplest way, for me. There's no 'right' way, but if you want to see how I have done it in the past you can have a peek at this [openziti-scripts/letsencrypt/get\_cert.sh at main · dovholuknf/openziti-scripts · GitHub](https://github.com/dovholuknf/openziti-scripts/blob/main/letsencrypt/get_cert.sh)

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [May 28, 2025, 4:27pm UTC](https://openziti.discourse.group/t/zrok-self-hosted-instance/4653/5 "2025-05-28T16:27:07Z")

</div>

I see that you're following the zrok self-hosting guide for Docker: [Self-hosting guide for Docker | zrok](https://docs.zrok.io/docs/guides/self-hosting/docker/)

You must obtain trusted certs, e.g., from LetsEncrypt. Otherwise, you won't be able to enable your zrok account or create any shares, because zrok enforces certificate trust when communicating with the zrok controller.

A wildcard certificate obtained via the DNS-01 solver is recommended because it vastly simplifies satisfying this requirement. While it is technically possible obtain trusted certs for each domain name, including all zrok public shares you will create, without a wildcard certificate, which requires a DNS-01 solver and DNS provider token in Caddy, it is substantially more difficult and fragile.

* * *

You may choose any TCP ports you wish for your ziti and zrok ports. However, changing the ports will break the zrok environments you already enabled with your zrok account token. Though 80/TCP is not the default port for HTTPS, it is perfectly valid. 🙂 This is the port used in the zrok self-hosting guide for Docker for the ziti controller because it is usually allowed egress from networks where you might wish to create zrok shares.
