feat(cli): make connect-url --relay a full anywhere pairing link

- --relay links now carry both routes: direct LAN plus relay fallback,
  matching the UI's Anywhere pairing; devices prefer the direct route
- pairing sessions created by the CLI are marked with usesRelay, and the
  server reconciles relay demand on a timer, so a headless instance
  brings the relay up on its own after connect-url --relay
- warn with LAN_UNREACHABLE when the link's direct route points at
  loopback and other devices cannot use it
- document the --relay flow and the --lan binding caveat in Connect a
  Device and Remote Instances across all locales
This commit is contained in:
Bohdan Triapitsyn
2026-07-10 18:29:15 +03:00
parent de92b8fef4
commit 6ec1797583
21 changed files with 182 additions and 87 deletions
+6 -5
View File
@@ -387,7 +387,7 @@ OPTIONS:
--hostname Alias for --host outside tunnel commands
--lan Bind to 0.0.0.0 for LAN access
--server <url> Public/server URL for connect-url links
--relay connect-url: generate an end-to-end-encrypted relay pairing link
--relay connect-url: also include the end-to-end-encrypted relay transport
--ui-password Protect browser UI with single password
--api-only Start API routes only, without serving browser UI assets
--foreground Run server in foreground (use with systemd/process managers)
@@ -465,10 +465,11 @@ OPTIONS:
--lan Bind to 0.0.0.0 for LAN access when starting
--server <url> Public URL saved into the connection link
--server-url <url> Alias for --server
--relay Generate an end-to-end-encrypted relay pairing link
(no server URL needed; requires the relay enabled on
this instance). Set OPENCHAMBER_RELAY_URL to use a
self-hosted relay.
--relay Also include the end-to-end-encrypted relay transport
so the link works away from the local network. The
device prefers the direct connection when reachable;
the instance brings the relay up on its own. Set
OPENCHAMBER_RELAY_URL to use a self-hosted relay.
--name <label> Label saved with the remote client token
--ui-password <value> Protect browser access when UI routes are enabled
--api-only Start in headless/API-only mode when starting