* feat(server): support configurable hostname for managed OpenCode server spawn Allow the managed OpenCode server bind hostname to be configured via OPENCHAMBER_OPENCODE_HOSTNAME environment variable (default: 127.0.0.1). This enables LAN/Tailscale access without a reverse proxy by setting the hostname to 0.0.0.0. Closes #597 * fix: address review feedback — input validation, port probe hostname, security docs - Add defensive parsing for OPENCHAMBER_OPENCODE_HOSTNAME with trim/empty check and warning log, matching OPENCODE_HOST validation pattern - Pass configured hostname to resolveManagedOpenCodePort() so port availability is probed on the actual bind address, avoiding EADDRINUSE - Add security note in README docs warning about 0.0.0.0 exposure on untrusted networks
8.4 KiB

@openchamber/web
Run OpenCode in your browser. Install the CLI, open localhost:3000, done. Works on desktop browsers, tablets, and phones as a PWA.
Full project overview, screenshots, and all features: github.com/btriapitsyn/openchamber
Install
curl -fsSL https://raw.githubusercontent.com/btriapitsyn/openchamber/main/scripts/install.sh | bash
Or install manually: bun add -g @openchamber/web (or npm, pnpm, yarn).
Prerequisites: OpenCode CLI installed, Node.js 20+.
Usage
openchamber # Start on port 3000
openchamber --port 8080 # Custom port
openchamber --ui-password secret # Password-protect UI
openchamber tunnel help # Tunnel lifecycle commands
openchamber tunnel providers # Show provider capabilities
openchamber tunnel profile add --provider cloudflare --mode managed-remote --name prod-main --hostname app.example.com --token <token>
openchamber tunnel start --profile prod-main
openchamber tunnel start --provider cloudflare --mode quick --qr
openchamber tunnel start --provider cloudflare --mode managed-local --config ~/.cloudflared/config.yml
openchamber tunnel status --all # Show tunnel state across instances
openchamber tunnel stop --port 3000 # Stop tunnel only (server stays running)
openchamber logs # Follow latest instance logs
OPENCODE_PORT=4096 OPENCODE_SKIP_START=true openchamber # Connect to external OpenCode server
OPENCODE_HOST=https://myhost:4096 OPENCODE_SKIP_START=true openchamber # Connect via custom host/HTTPS
openchamber stop # Stop server
openchamber update # Update to latest version
Tunnel behavior notes
- One active tunnel per running OpenChamber instance (port).
- Starting a different tunnel mode/provider on the same instance replaces the active tunnel.
- Replacing or stopping a tunnel revokes existing connect links and invalidates remote tunnel sessions.
- Connect links are one-time tokens; generating a new link revokes the previous unused link.
Connect to external OpenCode server
OPENCODE_PORT=4096 OPENCODE_SKIP_START=true openchamber
OPENCODE_HOST=https://myhost:4096 OPENCODE_SKIP_START=true openchamber
| Variable | Description |
|---|---|
OPENCODE_HOST |
Full base URL of external server (overrides OPENCODE_PORT) |
OPENCODE_PORT |
Port of external server |
OPENCODE_SKIP_START |
Skip starting embedded OpenCode server |
OPENCHAMBER_OPENCODE_HOSTNAME |
Bind hostname for managed OpenCode server (default: 127.0.0.1, use 0.0.0.0 for LAN/remote access — trusted networks only) |
Bind managed OpenCode to LAN / Tailscale
OPENCHAMBER_OPENCODE_HOSTNAME=0.0.0.0 openchamber --port 3000
Security note: binding to 0.0.0.0 exposes the server on all network interfaces — use only on trusted networks and protect with firewall rules or --ui-password.
Optional env vars:
environment:
UI_PASSWORD: your_secure_password
OPENCHAMBER_TUNNEL_MODE: quick # quick | managed-remote | managed-local
OPENCHAMBER_TUNNEL_PROVIDER: cloudflare
For managed-remote mode, also set:
environment:
OPENCHAMBER_TUNNEL_MODE: managed-remote
OPENCHAMBER_TUNNEL_HOSTNAME: app.example.com
OPENCHAMBER_TUNNEL_TOKEN: <token>
For managed-local mode, you can set:
environment:
OPENCHAMBER_TUNNEL_MODE: managed-local
OPENCHAMBER_TUNNEL_CONFIG: /home/openchamber/.cloudflared/config.yml
Managed-local path note: OPENCHAMBER_TUNNEL_CONFIG must use a container path under /home/openchamber/.... If the config file references credentials-file, ensure that JSON path is also mounted and reachable inside the container.
Data directory: mount data/ for persistent storage. Ensure permissions:
mkdir -p data/openchamber data/opencode/share data/opencode/config data/ssh
chown -R 1000:1000 data/
Background & daemon mode
openchamber # Runs in background by default
openchamber stop # Stop background server
What makes the web version special
-
Remote access - Cloudflare tunnel with QR onboarding. Scan from your phone, start coding.
-
Mobile-first PWA - optimized chat controls, keyboard-safe layouts, drag-to-reorder projects
-
Background notifications - know when your agent finishes, even from another tab
-
Self-update - update and restart from the UI, server settings stay intact
-
Cross-tab tracking - session activity stays in sync across browser tabs
-
Cloudflare tunnel access with quick, managed-remote, and managed-local modes
-
One-scan onboarding with tunnel QR + password URL helpers
-
Mobile-first experience: optimized chat controls, keyboard-safe layouts, and attachment-friendly UI
-
Background notifications plus reliable cross-tab session activity tracking
-
Built-in self-update + restart flow that keeps your server settings intact
License
MIT