termux.png

TL;DR
Why not Linux VM? Termux is way more reliable for keeping the SSH connection alive and it allows accessing other directories.

Introduction

In my previous post I talked about using Nix and Home Manager on my Pixel 6A. In this article I’ll share how to use a more “traditional” approach, i.e., using Termux with Cloudflare Tunnel. This is my current setup.

Prerequisite

Guide

1. Install cloudflared

pkg update && pkg upgrade
pkg install cloudflared

2. Configure cloudflared

Note
~ is aliased to /data/data/com.termux/files/home
  1. Create the dir:
cd ~
mkdir .cloudflared
cd .cloudflared
  1. Set up the tunnel
cloudflared tunnel login # follow the on-screen instruction
cloudflared tunnel create pixel # create a tunnel called pixel
cloudflared tunnel route dns pixel pixel.helloworld.com # create a route (`pixel` is the tunnel name; `helloworld.com` is the domain you own.)

You should now have the following files in ~/.cloudflared:

~/.cloudflared $ ls
 abcdefgh-abcd-abcd-abcd-abcdefghijkl.json   cert.pem
  1. Create the following config.yml in ~/.cloudflared:
tunnel: abcdefgh-abcd-abcd-abcd-abcdefghijkl

credentials-file: /data/data/com.termux/files/home/.cloudflared/abcdefgh-abcd-abcd-abcd-abcdefghijkl.json

ingress:
  - hostname: helloworld.com
    service: ssh://localhost:8022
  - service: http_status:404
Note
tunnel requires the UUID, not the name of the tunnel!
  1. Start the tunnel manually to verify that it’s working:
cloudflared tunnel run pixel

Now if you go to your Cloudflare Tunnels Dashboard, you should see your tunnel status being HEALTHY.

3. Create a persistent and reliable SSH connection

  1. Install termux-services
pkg install termux-services
  1. Enable and start the services
sv-enable sshd cloudflared
sv up sshd cloudflared
  1. Use Termux:Boot to auto start on boot
mkdir ~/.termux/boot
cd ~/.termux/boot
touch start-services
chmod +x ./start-services

start-services:

#!/data/data/com.termux/files/usr/bin/sh

termux-wake-lock
exec runsvdir -P $PREFIX/var/service

The line exec runsvdir -P $PREFIX/var/service means that on boot, I want to start all services specified under /data/data/com.termux/files/usr/var/service:

.../var/service $ ls
 cloudflared/   ssh-agent/   sshd/

SSH into your phone through Cloudflare Tunnel

ssh -i ~/.ssh/key -p 8022 -o ProxyCommand='cloudflared access ssh --hostname pixel.helloworld.com' [email protected]

For convenience I have the following in .ssh/config:

Host pixel
  HostName   pixel.helloworld.com
  User       u0_a264
  Port       8022
  ProxyCommand cloudflared access ssh --hostname %h
  IdentityFile ~/.ssh/key

So that ssh pixel would just work!

Why Termux over Linux Terminal App?

The Pros:

1. Much, much more resilient and reliable SSH connections

Termux has Termux:Boot for surviving phone reboot and Termux Services for restarting the cloudflared and sshd daemons. This means more resilient and persistent SSH connections. On the other hand, even with battery optimization turned off for the Linux Terminal App, I always had the following experience:

  1. Run ssh pixel on my laptop
  2. Connection refused
  3. Sigh
  4. Locate my Pixel physically (heaven forbid if it’s not within arm’s reach)
  5. Open the Linux Terminal App
  6. Go back to my laptop and run ssh pixel again

I’m spoiled and the above is too much work.

2. Full user directories access

With termux-setup-storage, I can access the following directories:

~/storage/shared $ pwd
/data/data/com.termux/files/home/storage/shared

~/storage/shared $ ls
Android  DCIM  Download  Movies  Music  Pictures

The Linux VM can only access Download dir. I need to back up other dirs like Pictures, and only Termux makes it possible. This means my phone backup script is actually useful.

3. Much faster startup time

The Linux VM takes >= 10 seconds to boot up. I’m spoiled and this is too long. Termux app loads instantly and the prompt is available immediately.

4. Much, much more stable than Linux VM

The Linux Terminal App came out literally only 2 months ago and only on Pixel phones. It’s not even Generally Available and bugs are to be expected. Termux is much more mature and stable.

The Cons

1. Tailscale does not work in Termux

There is no tailscale package in the Termux repository. I tried to build it from source but it just did not work. I had to resort to using Cloudflare Tunnel.

2. Not a real Linux VM

This means that the Termux terminal is a half-baked experience. I could use my laptop Nix dotfiles on the Linux VM but not on Termux.

After SSH, there are a lot of quirks and workarounds and hacks to do what I want. I’m not complaining; just manage your expectations.