Skip to content

Add tunnel option to app.run - #4028

Closed
ndrezn wants to merge 5 commits into
plotly:devfrom
ndrezn:feature/run-tunnel
Closed

ndrezn wants to merge 5 commits into
plotly:devfrom
ndrezn:feature/run-tunnel

Conversation

@ndrezn

@ndrezn ndrezn commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Adds app.run(tunnel=True) (or DASH_TUNNEL=1) to share a locally running app on a public trycloudflare.com URL through a Cloudflare quick tunnel. No account or login needed. For development only.

  • Uses cloudflared from the PATH, otherwise downloads the latest release once into ~/.cache/dash/cloudflared.
  • The public URL is logged next to the local one and stays the same across hot reloads.
  • If the tunnel fails to start, the app still runs locally.
  • cloudflared is stopped on exit, including SIGTERM.
  • Warns when debug is on, since dev tools and tracebacks become public.

Closes #4029

@robertclaus

Copy link
Copy Markdown
Contributor

This PR is missing an issue to discuss the problem you're running into. Tsk tsk tsk @ndrezn. ;)

Note, this type of developer tooling should probably go into the plotly CLI, not core Dash. We should also be careful automatically downloading, installing, and executing executables without confirming with the user. Realistically, it probably also needs some additional research to see what other tunnel services folks prefer (ex. ngrok).

@ndrezn

ndrezn commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor Author

Ticket opened. ngrok isn't an option unfortunately as you need an account to spin up a tunnel. This design isn't original, there's a good similar no-config example in langchain linked in the ticket, if you're curious about whether this design is adopted in other frameworks.

Feel free to move this over to the plotly CLI, it's closed source though, so I won't be able to help. I do think it would be useful in core Dash, and then the CLI could expose this as a flag as it does for run commands etc. This way the solution is implemented further upstream.

Also stop the tunnel on SIGHUP so closing the terminal does not leave it running.
@ndrezn

ndrezn commented Sep 30, 2026

Copy link
Copy Markdown
Contributor Author

Added download confirmation if the binary doesn't exist & version pin for the binary for good measure

@sonarqubecloud

Copy link
Copy Markdown

@T4rk1n

T4rk1n commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

I am not sure we want this baked in the framework, it's convenient, but then I can just ask an agent to open a tunnel for me for the same result.
There's also a risk about exposing a development app to the public the user should know about before starting these, these cloudflared apps get scanned almost instantly.
It's also tied to a third party who may decide to change the service, it happened with ngrok, it was free for a while but now requires an account and limit usages.

@ndrezn

ndrezn commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

Fair on possible vendor shifts; I've found it super handy as a built-in in general for development. Even if an agent can do this I suspect many developers haven't tried these tools with Dash, which makes discoverability low. I could refactor to make this less locked to Cloudflare and therefore easier to swap out in the future.

@ndrezn

ndrezn commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor Author

Discussed between the Dash maintainers and we don't think the current implementation is secure enough to recommend to Dash developers in Enterprise settings. We're going to look into adding a docs page to recommend it and investigate adding a tunnel relay server in Plotly Cloud + Dash Enterprise so we can provide end-to-end encryption.

From @robertclaus in #4028

Looking forward to seeing the implementation from Plotly folks!

@ndrezn ndrezn closed this Oct 1, 2026
@ndrezn
ndrezn deleted the feature/run-tunnel branch October 1, 2026 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature Request] Share a locally running app on a public URL with app.run(tunnel=True)

3 participants