sish
HTTP(S)/WS(S)/TCP tunnels to localhost using only SSH (serveo/ngrok alternative).
Activity has dropped noticeably. Check the repository before committing to it.
Commit activity more than 7% of tracked projects; popularity more than 66%. How this is calculated.
Commits, last 11 months
| Stars | 4.7k |
|---|---|
| Latest release | v2.23.0 · 5 Jun 2026 |
| Repo updated | 25 Jun 2026 |
| Licence | MIT |
| Built with | Go, Docker |
Is sish actively maintained?
Development is ongoing. The repository recorded 12 commits over the same window, and the last three months alone account for 4 of them.
The most recent tagged release, v2.23.0, is about 4 months old.
Of the 9 projects we track in Proxy, sish ranks #3 by health score — in the top quarter of its category.
What sish actually does
sish is an open-source tool that lets you expose local services behind NAT or firewalls to the public internet via HTTP, HTTPS, WebSockets, or raw TCP. It relies entirely on standard SSH connections, removing the need for a dedicated client agent on the target machine. This provides a self-hosted alternative to proprietary tunneling services.
Best fit: It suits developers and system administrators who want to host their own tunneling infrastructure on a private server without depending on external third-party services.
Worth knowing: Development activity has slowed down recently, and you may find that it lacks the extensive ecosystem or community support found in more widely adopted alternatives like ngrok.
Deployment notes
As a Go application packaged for Docker, it typically requires a public-facing server with appropriate port forwarding for SSH and tunnel traffic, along with a reverse proxy to handle TLS termination.
Links
Alternatives to sish
Projects in the same categories, ordered by health score.
Fast and secure standalone server for resizing and converting remote images.
Proxy for Git that applies rules and workflows to all outgoing git push operations and ensures they are compliant. It supports both HTTP/HTTPS and SSH protocols with security scanning and validation.
Light-weight HTTP/HTTPS proxy daemon.
A proxy server that runs a Shadowsocks instance for each access key and a REST API to manage the access keys.
SOCKS5 proxy server with built-in authentication and Telegram-bot for user management and user statistics on data spent (handy when you pay per GB of data). It is dockerised and simple to install.
Forward proxy server supporting proxy chaining, protocol inspection, MITM Interception, ICAP adaptation and transparent proxy.