Protocol fit
HTTP is the core. Everything else needs a deliberate decision.
| Service | Availability and scope | What to check |
|---|---|---|
| HTTP and HTTPS web apps | Available core workflow | External URLs, redirects, cookies and application authentication. |
| REST APIs and webhooks | Available core workflow | Authentication, body fidelity, timeouts and sender retries. |
| WebSockets and SSE | Confirm application and connector compatibility | Upgrade handling, buffering, reconnects and connection lifetime. |
| gRPC | Separate protocol validation | HTTP/2 on the appropriate connections and client behaviour. |
| Device web interfaces | Application-specific fit | Extra ports, media streams, private-address redirects and native clients. |
| Raw TCP: SSH, RDP, databases | Outside initial Publish scope | Use Networks or assess Public IPs. |
| UDP, discovery and broadcast | Outside initial Publish scope | A hostname is not a network bridge or generic UDP relay. |
| TLS passthrough | Outside initial Publish scope | Different certificate ownership and access-control capabilities. |
A hostname works for web routing because HTTP identifies the requested host. Arbitrary TCP and UDP traffic does not always carry that identity. A subdomain alone cannot make every service share the same public IP and port.
Operating limits
A stable name still needs a healthy application.
Connection and capacity
The application, connector and internet path must stay available. Your server’s upload bandwidth, latency and available compute affect visitors. Publish is not application hosting or an automatic backup service.
Usage limits
Publication count, domains, bandwidth, concurrent connections, request size and timeouts need explicit plan limits. No unlimited usage, free tier, fixed price or service-level guarantee is included by product availability.
Regions and resilience
Gateway location affects the request path. Multi-origin balancing, regional failover and automatic high availability need separate implementation and are not included merely because the network is global.
Abuse and application security
Rate limits, target restrictions and account controls belong in the service. They do not replace application updates, authentication or input validation. A managed certificate is not a WAF or a DDoS protection guarantee.
Diagnose the path
Find the failing step before changing the target.
- 01 · AddressDoes the name lead to the right gateway?
- 02 · HTTPSIs the connection’s certificate valid?
- 03 · ConnectorIs the host or Edge device online?
- 04 · ApplicationCan that connector reach the app?
| Symptom | Check first |
|---|---|
| Name does not resolve | Assigned hostname, DNS records and propagation. |
| Certificate warning | Correct hostname, issuance status, renewal and any custom-domain validation. Do not bypass the warning. |
| Connector is offline | Host power, background service, network reachability and permitted WireGuard traffic. |
| Target unavailable | Address and port from the selected connector, application process and local firewall. |
| Wrong application appears | Publication target, host-header expectations and application virtual-host configuration. |
| Login loops or private redirects | Public base URL, cookies, proxy trust and authentication callback URLs. |
| Homepage works but live data fails | WebSockets, SSE, additional protocols and long-request limits. |
| An API sender receives a login page | Browser access policy applied to a machine endpoint; use compatible API authentication. |
| Outgoing IP did not change | Expected: Publish does not configure an outbound identity. |
Support diagnostics should identify the publication and failing stage without including credentials, private keys, authentication headers or request bodies. Logging and retention terms must be established before collecting production traffic data.
Common questions
The details that decide whether it fits.
Does Publish include a server or application hosting?
No. You provide and maintain the application and its host. Publish supplies the connection to that application. Your app’s data, backups and database remain your responsibility.
What will it cost?
Pricing and usage allowances have not been announced. Confirm app count, traffic and connection limits when arranging setup.
Can I publish multiple applications on one machine?
Yes. Each publication selects a service and gets its own hostname; several can share one connector and WireGuard connection. Confirm publication counts and usage limits during setup.
Can an app stay bound to localhost?
Yes, with a connector on that host to perform local forwarding. Localhost means the connector’s own machine. WireGuard alone does not make the remote loopback interface reachable from the public gateway.
Does the visitor need a Fibmesh account or VPN?
Public HTTP visitors need a compatible browser or API client, not a WireGuard connection. A future protected-browser policy may require visitor authentication without requiring network enrollment.
Do I need a static IP or router port forwarding?
The connector establishes the WireGuard path outward, so the origin does not need a dedicated public address or an inbound router port-forward. The network must permit the required UDP traffic. There is no automatic TCP fallback in the current transport direction.
Will it work behind CGNAT?
It can when the connector can establish and maintain its WireGuard connection. Keepalive traffic may be needed to preserve the connection through the router; restrictive firewalls and carrier policies still need testing.
Can I use a domain I already own?
Verified custom domains are a planned extension. They require ownership checks, DNS configuration and certificate management. Publish availability does not release this extension.
Can I put two apps under paths on one domain?
Path routing is technically possible, but applications may need base-path, redirect and cookie changes. The initial model uses a separate hostname per publication. General path routing and rewriting remain outside that initial scope.
Does closing the terminal stop a persistent link?
Persistent publications run through a background connector. Closing the administrative terminal does not stop it, but shutting down or suspending the host can interrupt service. Temporary publication semantics are a separate proposal.
Can I publish a printer, scanner or an NVR?
A compatible HTTP interface may fit. Printing, scanning, discovery, native clients and video streams can use different protocols. Use Networks for private equipment access or assess Public IPs for supported public delivery.
Can Fibmesh see application traffic?
With managed HTTPS termination, the public gateway processes decrypted requests. WireGuard encrypts the connector transport. This model is not opaque browser-to-origin TLS passthrough.
Can I use IPv6?
Public gateway IPv4/IPv6 support and connector-to-origin address families are separate capabilities. An IPv6-only origin is technically possible with a suitable connector path; the released gateway and origin support matrix must establish availability.
Does this expose every port on my server?
No. A publication identifies one selected HTTP application and port. Other services need separate rules. Application vulnerabilities can still expose data through the selected app, so keep its permissions and security controls in place.
