What is BelaRemoteUI?
BelaRemoteUI is a community project by Bittersweet1987 for self-hosted remote access to one or more BELABOX web interfaces. Each BELABOX only ever opens an outbound Chisel connection to your own VPS. No inbound port has to be opened on the BELABOX for this.
The official BELABOX remote key is neither used nor overwritten. The project does not replace the BELABOX or its local user interface. It makes the interface reachable through a relay server that you run yourself.
In this guide
1. Self-hosted or official access?
| Solution | Upside | Effort |
|---|---|---|
| Official remote access | The path BELABOX intends | Depends on the official offering and its terms |
| BelaRemoteUI | Your own VPS, fixed links, and multiple profiles | Server costs, maintenance, and hardening on you |
| Local web interface | No extra internet service | Only reachable on the BELABOX's local network |
2. Requirements
- A VPS running Ubuntu 24.04 or Ubuntu 26.04.
- Root or sudo access on the VPS and the BELABOX.
- Terminal or SSH access to the BELABOX.
- On the VPS: TCP port 80 or the fallback port the script picks, plus TCP 9090 for Chisel.
- For HTTPS: your own domain or subdomain with a DNS A record pointing to the VPS, and TCP ports 80 and 443 reachable from outside.
- The VPS's SSH management port reachable only for trusted administrators.
- A strong password for the BELABOX web interface.
Existing Nginx and RTMP configurations are taken into account. If port 80 is taken, the script looks for a free HTTP port starting at 8088, according to the project documentation. You can set a specific port on purpose with --public-port PORT.
3. Setup and required ports
| Port | Direction | Purpose |
|---|---|---|
| 80/TCP | Browser/Let's Encrypt → VPS | HTTP, certificate validation, and redirect to HTTPS |
| 443/TCP | Browser → VPS | Encrypted remote web interface and WSS |
| 9090/TCP | BELABOX → VPS | Outbound Chisel tunnel |
| SSH port | Administrator → VPS | Maintenance; not part of the BELABOX tunnel |
| 18080 and up | internal on the VPS | Separate internal port for each BELABOX profile |
BelaRemoteUI does not enable UFW automatically. If UFW is already active, the script adds the BelaRemoteUI rules it needs. With cloud providers, this local rule often is not enough, though: the security group, security list, or provider firewall must also allow TCP 80, 443, and 9090. Without HTTPS, the fallback port the script prints can apply instead of port 80.
4. Installing BelaRemoteUI on the VPS
First switch to a root shell. That way the following VPS commands don't need sudo every time:
sudo -i
exit.Install the download tools
apt update && \
apt install ca-certificates curl less -y
Download the current server script
The file is loaded straight from the official BelaRemoteUI repository into /usr/local/sbin:
curl -fsSL --retry 3 https://raw.githubusercontent.com/Bittersweet1987/BelaRemoteUI/main/belabox-vps-remote-server.sh -o /usr/local/sbin/belabox-vps-remote-server && \
chown root:root /usr/local/sbin/belabox-vps-remote-server && \
chmod 0750 /usr/local/sbin/belabox-vps-remote-server
Read the downloaded script before you run it for the first time. Leave the viewer with q:
less /usr/local/sbin/belabox-vps-remote-server
Start the setup
belabox-vps-remote-server
- Update the VPS and document the existing Nginx, firewall, and port usage.
- Review the server script from the official repository and run it.
- Pick a unique profile name such as
rucksack,kamera1, oreventbox. - Store the remote URL, widget/API URL, WebSocket URL, tunnel port, tunnel token, and the printed BELABOX command somewhere safe.
- With several devices, add more profiles when the script asks.
5. Connecting the BELABOX to the VPS
- Match the complete client command that the VPS script printed to the right BELABOX.
- Run the command in the BELABOX terminal. Never show the token or secret URL in screenshots, on stream, or in chat.
- If needed, the printed command first installs
curl, then sets up the local proxy, the Chisel client, and persistent system services. - After the suggested reboot, check that the tunnel and proxy started automatically.
systemctl --no-pager --full status belabox-vps-remote-ui-tunnel.service belabox-vps-remote-ui-proxy.service
6. Using the Remote UI on the go
For everyday browser use, open the long, fixed remote URL from the VPS output. The secret path first sets a cookie and then redirects to /. According to the project documentation, this redirect is intentional so that CSS, JavaScript, and WebSockets work the way they do on belabox.local.
Widget, API, and WebSocket addresses use a token. These URLs are credentials and do not belong in public OBS configurations or support screenshots.
7. Managing multiple BELABOXes
Each profile gets its own link, token, and internal VPS port. This management command lists the existing profiles:
belabox-remote-vps-status
This is how you generate a new secret link for an existing profile; the script then asks for the profile name:
belabox-vps-remote-server --regenerate-link
If you suspect the URL or token was exposed, renew the access and then update it on every device you use.
8. Securing BelaRemoteUI with HTTPS and WSS
Since the GitHub commit of August 29, 2026, BelaRemoteUI has its own optional HTTPS feature. The server script installs Certbot, requests a Let's Encrypt certificate, sets up automatic renewal, and changes the printed addresses to https:// and wss://.
bela.example.de. That way your regular website and BelaRemoteUI can share ports 80 and 443 on the same VPS, while Nginx tells them apart by domain name.1. Create the subdomain in DNS
Create a DNS A record with your domain provider. The target is the VPS's public IPv4 address. Replace the example values with your own:
Typ: A
Name: bela
Ziel: YOUR_VPS_IPV4
After the DNS change, it can take a while, depending on the provider, until the record is available everywhere. Check the resolution on the VPS:
getent ahostsv4 bela.example.de
2. Open the ports in both firewalls
For the complete setup, the rules have to be right on the VPS and in the cloud provider's firewall:
80/TCPfor the Let's Encrypt validation and the later HTTPS redirect.443/TCPfor the encrypted website and secure WebSockets.9090/TCPfor the BELABOX's outbound Chisel tunnel.
server_name.3. Set the public BelaRemoteUI port to 80
The built-in HTTPS setup currently only works if BelaRemoteUI is set up publicly on port 80. If the first install automatically picked a fallback port such as 8088, run the current server script again with your subdomain and port 80:
belabox-vps-remote-server --domain bela.example.de --public-port 80 --no-reboot
/etc/nginx and the BelaRemoteUI configuration, or take a VPS snapshot.4. Turn on HTTPS with Let's Encrypt
Once the DNS A record is correct and port 80 is reachable from outside, start the new HTTPS feature:
belabox-vps-remote-server --setup-https --domain bela.example.de
Optionally, pass an email address for certificate notices with --email name@example.de. Without --domain, the script asks for the domain interactively.
5. Check the result
nginx -t && \
systemctl is-active nginx && \
ss -ltnp | grep -E ':80 |:443 |:9090 ' && \
certbot certificates && \
belabox-remote-vps-status
After that, open only the newly printed address with https://. In the browser developer tools, the WebSocket connection should use wss://. Then test sign-in, status values, and controls once over cellular instead of your home network.
6. Turn HTTPS off again if needed
belabox-vps-remote-server --disable-https
According to the project documentation, existing certificates are kept and can be reused if you set HTTPS up again.
9. Checking security after setup
- Treat the remote link, token, and URLs like passwords.
- Use separate access for each BELABOX profile.
- Also protect the BELABOX web interface with a strong, unique password.
- Update the VPS, Nginx, Chisel, and the operating system regularly.
- Restrict SSH access and check the logs for unknown requests.
- Back up your Nginx and firewall configuration before making changes.
HttpOnly and SameSite=Lax, but still without the Secure attribute. HTTPS and WSS work anyway. The IRL4YOU compatibility fix below lets you add it to the generated Nginx configuration in a controlled way.Using the IRL4YOU secure cookie fix
The fix is not part of the BelaRemoteUI project. It works only with /etc/nginx/conf.d/belabox-remote-ui.conf, requires an active HTTPS configuration, and makes a dated backup before every change. If an Nginx test or reload fails, the backup is restored automatically.
Download the secure cookie fix
Download the fix straight from IRL4YOU into /usr/local/sbin and set safe owner and file permissions:
curl -fsSL --retry 3 https://irl4you.de/downloads/belaremoteui-secure-cookie-fix.sh -o /usr/local/sbin/irl4you-belaremoteui-secure-cookie-fix && \
chown root:root /usr/local/sbin/irl4you-belaremoteui-secure-cookie-fix && \
chmod 0750 /usr/local/sbin/irl4you-belaremoteui-secure-cookie-fix
Read the file before you run it, then start it separately:
less /usr/local/sbin/irl4you-belaremoteui-secure-cookie-fix
irl4you-belaremoteui-secure-cookie-fix
Afterwards, check that Nginx is running and that the cookie lines contain the Secure attribute:
nginx -t && \
systemctl is-active nginx && \
grep -n 'SameSite=Lax; Secure' /etc/nginx/conf.d/belabox-remote-ui.conf
Secure itself in the future, the fix exits without changing anything.Also check that HTTP really redirects to HTTPS and that the certificate belongs to the subdomain you use:
curl -I http://bela.example.de && \
curl -I https://bela.example.de
The first request should return a redirect to HTTPS. The second must not show a certificate warning. Never share full remote, widget, API, or WebSocket URLs in screenshots or support posts, because they can contain access tokens.
10. Troubleshooting
| Problem | Check | Fix |
|---|---|---|
| Web port not reachable | UFW and the external cloud firewall | Open the TCP port that was actually printed in both places. |
| 502 Bad Gateway | Is the BELABOX tunnel connected? | Check the tunnel and proxy services on the BELABOX and the Chisel service on the VPS. |
| Only the Nginx welcome page | Was the BelaRemoteUI configuration loaded? | Run the server script again with --no-reboot as described in the repository and check Nginx. |
| UI loads but nothing works | WebSocket connection and browser console | Check the proxy, token, port, and any HTTPS configuration in front. |
| Certificate is not issued | DNS A record, port 80, and cloud firewall | The domain must point to this VPS and the ACME validation must be reachable from outside. |
| HTTPS loads, controls don't respond | Check the browser console for a failed wss:// | Use the current client script and check the Nginx WebSocket forwarding. |
Check the BelaRemoteUI profiles first:
belabox-remote-vps-status
Then show the services involved without the interactive pager:
systemctl --no-pager --full status belabox-remote-ui-chisel.service nginx
11. Removal, recovery, and backup
The repository documents separate functions for deleting a profile, uninstalling the whole VPS setup, and removing the BELABOX client. According to the project, these only remove their own files, services, Nginx entries, and firewall rules they added themselves. Still, take a VPS snapshot and a configuration backup first.
For any removal, use only the currently documented commands in the management section of the GitHub project. Double-check the profile name and the target system.
Leaving the root shell
When the installation and checks are done, switch back to your normal user:
exit
12. Common questions
Do I have to open a port on the BELABOX?
No. According to the project description, the BELABOX only opens an outbound Chisel connection to your VPS. TCP 9090 has to be reachable, and that applies to the VPS. On the BELABOX, every inbound port stays closed. The section Setup and ports gives an overview.
Does BelaRemoteUI change the official BELABOX remote key?
No. The official remote key is left alone: it is not used and not overwritten. BelaRemoteUI is a community project, not an official BELABOX service. It only makes the local web interface reachable through your own server.
What does it cost?
BelaRemoteUI is released under the GPLv3 and is free. The VPS can carry a monthly fee, though, and that varies by provider. Operation, updates, hardening, and backups are up to you.
Do I need my own domain for HTTPS?
Yes, for the built-in HTTPS feature with Let's Encrypt. You need your own domain or subdomain with a DNS A record pointing to the VPS. TCP ports 80 and 443 also have to be reachable from outside. Without HTTPS, a fallback port that the script prints can replace port 80. The steps are in the section Setting up HTTPS and WSS.
What do I do if the remote link or token became public?
Treat the link and token like passwords. If you suspect a leak, generate a new secret link for the profile (see Managing multiple BELABOXes). Then enter it again on every device you use.
Several cameras in one picture
For the BELABOX, the IRL4YOU BOX is a free add-on for picture-in-picture with up to four cameras. It is a beta.
Project, privacy, and more guides
BelaRemoteUI is provided by Bittersweet1987 as a community project under the GPLv3. IRL4YOU does not embed the project automatically and gets no access to your VPS, BELABOX, tokens, or remote URLs. When you open GitHub, its privacy terms apply. When you self-host, you are responsible for server logs, access rights, and hardening.
Thanks to Bittersweet1987 and the BelaRemoteUI project
A heartfelt thank you goes to Bittersweet1987 and everyone who contributes to BelaRemoteUI. Their work gives the IRL streaming community an open, self-hosted way to reach one or more BELABOX web interfaces through your own VPS.
The project publishes the scripts, the source code, and the technical documentation openly on GitHub. There you can follow the current state of development, review changes, and report possible bugs.
Visit the official BelaRemoteUI project on GitHub
Direct contact: Bittersweet1987 is also in the IRL4YOU Discord and happy to be approached there with questions about the project. Please don't share passwords, tunnel tokens, or full remote URLs in public channels.
Contact Bittersweet1987 in the IRL4YOU Discord
IRL4YOU is an independent information site. It did not develop BelaRemoteUI and is not officially affiliated with the project or BELABOX.
BELABOX Remote UI setup service
We help with the VPS, ports, profiles, Nginx, tunnel checks, and a safe test run. Credentials, secret links, and tokens stay with the operator and do not belong in public support messages.