Job tlstunnel


Skip to build


This is a MirageOS unikernel accepting TLS connections via the public (service) network interface on frontend-port, and proxying them using TCP via the private network interface to backend-ip and backend-port. A client connecting to TLStunnel has to establish a TLS connection, which payload is forwarded to the backend service via TCP.

TLStunnel can be used for load-balancing - using multiple TLStunnel on the frontend doing expensive crypto operations (asymmetrics TLS handshakes and symmetric cryptography) with a single (or multiple) backend-services which communicate via plain TCP.

Security-wise only the TLStunnel needs access to the private key of the X.509 certificate(s). When TLStunnel is configured to do client authentication, only valid clients can access the backend service, limiting the attack surface drastically.

Installation from source

To install this unikernel from source, you need to have opam (>= 2.0.0) and ocaml (>= 4.07.0) installed. Also, mirage is required (>= 3.10.0). Please follow the installation instructions.

The following steps will clone this git repository and compile the unikernel:

$ git clone
$ mirage configure -t <your-favourite-target>
$ make depend
$ make

Installing as binary

There are not yet any binaries available, but work is underway to provide reproducible binaries.


Please open an issue if you have questions, feature requests, or comments.

Build 2021-11-24 11:50:32Z

Back to readme

Built on platform freebsd-12

Build took 7min17s.

Execution result: exited 0.

Build info

Build artifacts

SHA256:1a48ce65603232cfe2b2c0b2bc5292b2d6c09a0d041082c6895c3beb3d18cb14 (6.2MB)
SHA256:ef47f3373a328099930eb781c9089c667deb0c4f39db8f130a389edec7776881 (384B)
SHA256:912607bd6ec370f31628fd4ad778976a9a0320c883593fd7755606f44756523d (184kB)
SHA256:dae2debc45b633a71e4fad4e919c25a0fbba99723c902869d4ce7592f4133748 (195B)
SHA256:42eeaf9ec77c670052375576ce993aeec773d245c9894e3d45b878023a9c4ad8 (9.19MB)

Reproduced by 2 builds

Comparisons with other builds on the same platform