Operating Away From Home¶
The RigPlane web server has no login. Anyone who can reach its port can control the radio, including transmit: the listener itself is the boundary (see Application authentication removal). Keep that port off the internet and reach it only through a path you control.
Keep the Server Off the Internet¶
- Do not forward the web port (8080 by default) on your router.
rigplane weblistens on all interfaces by default (--host 0.0.0.0), so everyone on the same network (guest Wi-Fi, an office, a dorm) can reach the port and key the transmitter. When you do not need access from the LAN, pass--host 127.0.0.1and come in through an SSH tunnel. When you do, use it only on a network you trust, or let a firewall admit only your own machines.
--host means two things. Before the subcommand it is the radio's address;
after web it is the address the web server listens on:
rigplane --model IC-7610 --host 192.168.1.50 --user USER --pass-file .rigplane-pass \
web --host 127.0.0.1
Here 192.168.1.50 is the radio and 127.0.0.1 is where the web server
listens.
Reach It Over an SSH Tunnel¶
From the remote computer, forward a local port to the station:
Then open http://localhost:8080. The browser treats localhost as a secure
origin, so voice TX from the browser microphone works without a certificate.
Reach It Over Your Own VPN¶
With WireGuard, Tailscale or a similar VPN, open the station by its VPN IP address. Everyone else on that VPN can reach the port too, and with it the radio, including transmit, so use a VPN that only you (and people you trust with your transmitter) are on.
A host name with a dot in it works only if it ends in .localhost, .local,
.home.arpa or .internal, or if you start rigplane web with
--allowed-host <name>; otherwise the server answers
421 Misdirected Request.
A private-network http:// address is not a secure origin, so browser voice
TX needs HTTPS with a certificate the browser trusts: see
Browser microphone requirement.
Keep RigPlane Next to the Radio¶
Run RigPlane at the station, on the same network as a LAN radio, and use the VPN or tunnel only between your browser and RigPlane. The radio's own LAN audio can break over tunnels that drop IP fragments (see LAN Audio Breaks Over WireGuard or Other UDP Tunnels), and browser audio can stutter over a VPN with jitter (see Audio Stutters Over VPN/Tailscale).