
Introduction
In my previous post I talked about using Nix and Home Manager on my Pixel 6A. In this article I’ll share how to use a more “traditional” approach, i.e., using Termux with Cloudflare Tunnel. This is my current setup.
Prerequisite
- Installed Termux, Termux:API and Termux:Boot and turn off battery optimization for them
- Enabled termux-setup-storage
- Set up openssh
- Possess a cloudflare domain for cloudflare tunnel
Guide
1. Install cloudflared
pkg update && pkg upgrade
pkg install cloudflared
2. Configure cloudflared
~ is aliased to /data/data/com.termux/files/home- Create the dir:
cd ~
mkdir .cloudflared
cd .cloudflared
- Set up the tunnel
cloudflared tunnel login # follow the on-screen instruction
cloudflared tunnel create pixel # create a tunnel called pixel
cloudflared tunnel route dns pixel pixel.helloworld.com # create a route (`pixel` is the tunnel name; `helloworld.com` is the domain you own.)
You should now have the following files in ~/.cloudflared:
~/.cloudflared $ ls
abcdefgh-abcd-abcd-abcd-abcdefghijkl.json cert.pem
- Create the following
config.ymlin~/.cloudflared:
tunnel: abcdefgh-abcd-abcd-abcd-abcdefghijkl
credentials-file: /data/data/com.termux/files/home/.cloudflared/abcdefgh-abcd-abcd-abcd-abcdefghijkl.json
ingress:
- hostname: helloworld.com
service: ssh://localhost:8022
- service: http_status:404
tunnel requires the UUID, not the name of the tunnel!- Start the tunnel manually to verify that it’s working:
cloudflared tunnel run pixel
Now if you go to your Cloudflare Tunnels Dashboard, you should see your tunnel status being HEALTHY.
3. Create a persistent and reliable SSH connection
- Install
termux-services
pkg install termux-services
- Enable and start the services
sv-enable sshd cloudflared
sv up sshd cloudflared
- Use Termux:Boot to auto start on boot
mkdir ~/.termux/boot
cd ~/.termux/boot
touch start-services
chmod +x ./start-services
start-services:
#!/data/data/com.termux/files/usr/bin/sh
termux-wake-lock
exec runsvdir -P $PREFIX/var/service
The line exec runsvdir -P $PREFIX/var/service means that on boot, I want to start all services specified under /data/data/com.termux/files/usr/var/service:
.../var/service $ ls
cloudflared/ ssh-agent/ sshd/
SSH into your phone through Cloudflare Tunnel
ssh -i ~/.ssh/key -p 8022 -o ProxyCommand='cloudflared access ssh --hostname pixel.helloworld.com' [email protected]
For convenience I have the following in .ssh/config:
Host pixel
HostName pixel.helloworld.com
User u0_a264
Port 8022
ProxyCommand cloudflared access ssh --hostname %h
IdentityFile ~/.ssh/key
So that ssh pixel would just work!
Why Termux over Linux Terminal App?
The Pros:
1. Much, much more resilient and reliable SSH connections
Termux has Termux:Boot for surviving phone reboot and Termux Services for restarting the cloudflared and sshd daemons. This means more resilient and persistent SSH connections. On the other hand, even with battery optimization turned off for the Linux Terminal App, I always had the following experience:
- Run
ssh pixelon my laptop - Connection refused
- Sigh
- Locate my Pixel physically (heaven forbid if it’s not within arm’s reach)
- Open the Linux Terminal App
- Go back to my laptop and run
ssh pixelagain
I’m spoiled and the above is too much work.
2. Full user directories access
With termux-setup-storage, I can access the following directories:
~/storage/shared $ pwd
/data/data/com.termux/files/home/storage/shared
~/storage/shared $ ls
Android DCIM Download Movies Music Pictures
The Linux VM can only access Download dir. I need to back up other dirs like Pictures, and only Termux makes it possible. This means my phone backup script is actually useful.
3. Much faster startup time
The Linux VM takes >= 10 seconds to boot up. I’m spoiled and this is too long. Termux app loads instantly and the prompt is available immediately.
4. Much, much more stable than Linux VM
The Linux Terminal App came out literally only 2 months ago and only on Pixel phones. It’s not even Generally Available and bugs are to be expected. Termux is much more mature and stable.
The Cons
1. Tailscale does not work in Termux
There is no tailscale package in the Termux repository. I tried to build it from source but it just did not work. I had to resort to using Cloudflare Tunnel.
2. Not a real Linux VM
This means that the Termux terminal is a half-baked experience. I could use my laptop Nix dotfiles on the Linux VM but not on Termux.
After SSH, there are a lot of quirks and workarounds and hacks to do what I want. I’m not complaining; just manage your expectations.