Diagram: the BELABOX opens an outbound connection on port 9090 to your own VPS. Chisel, an internal profile port, and Nginx run there. The browser connects over HTTPS and WSS on port 443. Token and remote URL are credentials.

What is BelaRemoteUI?

BelaRemoteUI is a community project by Bittersweet1987 for self-hosted remote access to one or more BELABOX web interfaces. Each BELABOX only ever opens an outbound Chisel connection to your own VPS. No inbound port has to be opened on the BELABOX for this.

The official BELABOX remote key is neither used nor overwritten. The project does not replace the BELABOX or its local user interface. It makes the interface reachable through a relay server that you run yourself.

Signal path: phone or browser → your own VPS with Nginx → Chisel tunnel → local BELABOX web interface.
Putting the cost in perspective: BelaRemoteUI is free to use as a GPLv3 project. A VPS can still cost money every month. Operation, updates, hardening, and backups are your own responsibility.

In this guide

1. Self-hosted or official access?

Ways to reach the BELABOX UI
SolutionUpsideEffort
Official remote accessThe path BELABOX intendsDepends on the official offering and its terms
BelaRemoteUIYour own VPS, fixed links, and multiple profilesServer costs, maintenance, and hardening on you
Local web interfaceNo extra internet serviceOnly reachable on the BELABOX's local network
Community project: BelaRemoteUI is not an official BELABOX service. Review the repository, the scripts, and current notes yourself before you install or update.

2. Requirements

Existing Nginx and RTMP configurations are taken into account. If port 80 is taken, the script looks for a free HTTP port starting at 8088, according to the project documentation. You can set a specific port on purpose with --public-port PORT.

3. Setup and required ports

Network access
PortDirectionPurpose
80/TCPBrowser/Let's Encrypt → VPSHTTP, certificate validation, and redirect to HTTPS
443/TCPBrowser → VPSEncrypted remote web interface and WSS
9090/TCPBELABOX → VPSOutbound Chisel tunnel
SSH portAdministrator → VPSMaintenance; not part of the BELABOX tunnel
18080 and upinternal on the VPSSeparate internal port for each BELABOX profile

BelaRemoteUI does not enable UFW automatically. If UFW is already active, the script adds the BelaRemoteUI rules it needs. With cloud providers, this local rule often is not enough, though: the security group, security list, or provider firewall must also allow TCP 80, 443, and 9090. Without HTTPS, the fallback port the script prints can apply instead of port 80.

4. Installing BelaRemoteUI on the VPS

First switch to a root shell. That way the following VPS commands don't need sudo every time:

sudo -i
Use the root shell deliberately: Check every command before you paste it and use this session only for the setup. When all checks are done, end it with exit.

Install the download tools

apt update && \
apt install ca-certificates curl less -y

Download the current server script

The file is loaded straight from the official BelaRemoteUI repository into /usr/local/sbin:

curl -fsSL --retry 3 https://raw.githubusercontent.com/Bittersweet1987/BelaRemoteUI/main/belabox-vps-remote-server.sh -o /usr/local/sbin/belabox-vps-remote-server && \
chown root:root /usr/local/sbin/belabox-vps-remote-server && \
chmod 0750 /usr/local/sbin/belabox-vps-remote-server

Read the downloaded script before you run it for the first time. Leave the viewer with q:

less /usr/local/sbin/belabox-vps-remote-server

Start the setup

belabox-vps-remote-server
Check first: The script gets far-reaching administrator rights. Use only the documented original address and review new versions before you run it again.
  1. Update the VPS and document the existing Nginx, firewall, and port usage.
  2. Review the server script from the official repository and run it.
  3. Pick a unique profile name such as rucksack, kamera1, or eventbox.
  4. Store the remote URL, widget/API URL, WebSocket URL, tunnel port, tunnel token, and the printed BELABOX command somewhere safe.
  5. With several devices, add more profiles when the script asks.

5. Connecting the BELABOX to the VPS

  1. Match the complete client command that the VPS script printed to the right BELABOX.
  2. Run the command in the BELABOX terminal. Never show the token or secret URL in screenshots, on stream, or in chat.
  3. If needed, the printed command first installs curl, then sets up the local proxy, the Chisel client, and persistent system services.
  4. After the suggested reboot, check that the tunnel and proxy started automatically.
systemctl --no-pager --full status belabox-vps-remote-ui-tunnel.service belabox-vps-remote-ui-proxy.service

6. Using the Remote UI on the go

For everyday browser use, open the long, fixed remote URL from the VPS output. The secret path first sets a cookie and then redirects to /. According to the project documentation, this redirect is intentional so that CSS, JavaScript, and WebSockets work the way they do on belabox.local.

Widget, API, and WebSocket addresses use a token. These URLs are credentials and do not belong in public OBS configurations or support screenshots.

Field test: Open the remote link in a private browser window first, sign in to the BELABOX UI, and only change status on a test device. Then test over cellular instead of your home Wi-Fi.

7. Managing multiple BELABOXes

Each profile gets its own link, token, and internal VPS port. This management command lists the existing profiles:

belabox-remote-vps-status

This is how you generate a new secret link for an existing profile; the script then asks for the profile name:

belabox-vps-remote-server --regenerate-link

If you suspect the URL or token was exposed, renew the access and then update it on every device you use.

8. Securing BelaRemoteUI with HTTPS and WSS

Since the GitHub commit of August 29, 2026, BelaRemoteUI has its own optional HTTPS feature. The server script installs Certbot, requests a Let's Encrypt certificate, sets up automatic renewal, and changes the printed addresses to https:// and wss://.

Recommended setup: Use your own subdomain such as bela.example.de. That way your regular website and BelaRemoteUI can share ports 80 and 443 on the same VPS, while Nginx tells them apart by domain name.

1. Create the subdomain in DNS

Create a DNS A record with your domain provider. The target is the VPS's public IPv4 address. Replace the example values with your own:

Typ:  A
Name: bela
Ziel: YOUR_VPS_IPV4

After the DNS change, it can take a while, depending on the provider, until the record is available everywhere. Check the resolution on the VPS:

getent ahostsv4 bela.example.de

2. Open the ports in both firewalls

For the complete setup, the rules have to be right on the VPS and in the cloud provider's firewall:

Important with existing services: RTMP on port 1935, a stats page, and other applications stay separate. Nginx may use port 80, but the BelaRemoteUI subdomain must not collide with an existing server_name.

3. Set the public BelaRemoteUI port to 80

The built-in HTTPS setup currently only works if BelaRemoteUI is set up publicly on port 80. If the first install automatically picked a fallback port such as 8088, run the current server script again with your subdomain and port 80:

belabox-vps-remote-server --domain bela.example.de --public-port 80 --no-reboot
Check before you run it: Open the current script in the GitHub repository first and review the changes. Also back up /etc/nginx and the BelaRemoteUI configuration, or take a VPS snapshot.

4. Turn on HTTPS with Let's Encrypt

Once the DNS A record is correct and port 80 is reachable from outside, start the new HTTPS feature:

belabox-vps-remote-server --setup-https --domain bela.example.de

Optionally, pass an email address for certificate notices with --email name@example.de. Without --domain, the script asks for the domain interactively.

5. Check the result

nginx -t && \
systemctl is-active nginx && \
ss -ltnp | grep -E ':80 |:443 |:9090 ' && \
certbot certificates && \
belabox-remote-vps-status

After that, open only the newly printed address with https://. In the browser developer tools, the WebSocket connection should use wss://. Then test sign-in, status values, and controls once over cellular instead of your home network.

6. Turn HTTPS off again if needed

belabox-vps-remote-server --disable-https

According to the project documentation, existing certificates are kept and can be reused if you set HTTPS up again.

Open the project's current HTTPS documentation on GitHub

9. Checking security after setup

Current cookie note: In the project version we tested, the access cookies are created with HttpOnly and SameSite=Lax, but still without the Secure attribute. HTTPS and WSS work anyway. The IRL4YOU compatibility fix below lets you add it to the generated Nginx configuration in a controlled way.

Using the IRL4YOU secure cookie fix

The fix is not part of the BelaRemoteUI project. It works only with /etc/nginx/conf.d/belabox-remote-ui.conf, requires an active HTTPS configuration, and makes a dated backup before every change. If an Nginx test or reload fails, the backup is restored automatically.

Download the secure cookie fix

Download the fix straight from IRL4YOU into /usr/local/sbin and set safe owner and file permissions:

curl -fsSL --retry 3 https://irl4you.de/downloads/belaremoteui-secure-cookie-fix.sh -o /usr/local/sbin/irl4you-belaremoteui-secure-cookie-fix && \
chown root:root /usr/local/sbin/irl4you-belaremoteui-secure-cookie-fix && \
chmod 0750 /usr/local/sbin/irl4you-belaremoteui-secure-cookie-fix

Read the file before you run it, then start it separately:

less /usr/local/sbin/irl4you-belaremoteui-secure-cookie-fix
irl4you-belaremoteui-secure-cookie-fix

Afterwards, check that Nginx is running and that the cookie lines contain the Secure attribute:

nginx -t && \
systemctl is-active nginx && \
grep -n 'SameSite=Lax; Secure' /etc/nginx/conf.d/belabox-remote-ui.conf
Check again after BelaRemoteUI updates: The official server script regenerates its Nginx file and can overwrite the addition. After every new script run, check first and apply the fix again only if needed. If the project adds Secure itself in the future, the fix exits without changing anything.

Also check that HTTP really redirects to HTTPS and that the certificate belongs to the subdomain you use:

curl -I http://bela.example.de && \
curl -I https://bela.example.de

The first request should return a redirect to HTTPS. The second must not show a certificate warning. Never share full remote, widget, API, or WebSocket URLs in screenshots or support posts, because they can contain access tokens.

10. Troubleshooting

Common BelaRemoteUI problems
ProblemCheckFix
Web port not reachableUFW and the external cloud firewallOpen the TCP port that was actually printed in both places.
502 Bad GatewayIs the BELABOX tunnel connected?Check the tunnel and proxy services on the BELABOX and the Chisel service on the VPS.
Only the Nginx welcome pageWas the BelaRemoteUI configuration loaded?Run the server script again with --no-reboot as described in the repository and check Nginx.
UI loads but nothing worksWebSocket connection and browser consoleCheck the proxy, token, port, and any HTTPS configuration in front.
Certificate is not issuedDNS A record, port 80, and cloud firewallThe domain must point to this VPS and the ACME validation must be reachable from outside.
HTTPS loads, controls don't respondCheck the browser console for a failed wss://Use the current client script and check the Nginx WebSocket forwarding.

Check the BelaRemoteUI profiles first:

belabox-remote-vps-status

Then show the services involved without the interactive pager:

systemctl --no-pager --full status belabox-remote-ui-chisel.service nginx

11. Removal, recovery, and backup

The repository documents separate functions for deleting a profile, uninstalling the whole VPS setup, and removing the BELABOX client. According to the project, these only remove their own files, services, Nginx entries, and firewall rules they added themselves. Still, take a VPS snapshot and a configuration backup first.

For any removal, use only the currently documented commands in the management section of the GitHub project. Double-check the profile name and the target system.

Leaving the root shell

When the installation and checks are done, switch back to your normal user:

exit

12. Common questions

Do I have to open a port on the BELABOX?

No. According to the project description, the BELABOX only opens an outbound Chisel connection to your VPS. TCP 9090 has to be reachable, and that applies to the VPS. On the BELABOX, every inbound port stays closed. The section Setup and ports gives an overview.

Does BelaRemoteUI change the official BELABOX remote key?

No. The official remote key is left alone: it is not used and not overwritten. BelaRemoteUI is a community project, not an official BELABOX service. It only makes the local web interface reachable through your own server.

What does it cost?

BelaRemoteUI is released under the GPLv3 and is free. The VPS can carry a monthly fee, though, and that varies by provider. Operation, updates, hardening, and backups are up to you.

Do I need my own domain for HTTPS?

Yes, for the built-in HTTPS feature with Let's Encrypt. You need your own domain or subdomain with a DNS A record pointing to the VPS. TCP ports 80 and 443 also have to be reachable from outside. Without HTTPS, a fallback port that the script prints can replace port 80. The steps are in the section Setting up HTTPS and WSS.

What do I do if the remote link or token became public?

Treat the link and token like passwords. If you suspect a leak, generate a new secret link for the profile (see Managing multiple BELABOXes). Then enter it again on every device you use.

Several cameras in one picture

For the BELABOX, the IRL4YOU BOX is a free add-on for picture-in-picture with up to four cameras. It is a beta.

Project, privacy, and more guides

BelaRemoteUI is provided by Bittersweet1987 as a community project under the GPLv3. IRL4YOU does not embed the project automatically and gets no access to your VPS, BELABOX, tokens, or remote URLs. When you open GitHub, its privacy terms apply. When you self-host, you are responsible for server logs, access rights, and hardening.

Thanks to Bittersweet1987 and the BelaRemoteUI project

A heartfelt thank you goes to Bittersweet1987 and everyone who contributes to BelaRemoteUI. Their work gives the IRL streaming community an open, self-hosted way to reach one or more BELABOX web interfaces through your own VPS.

The project publishes the scripts, the source code, and the technical documentation openly on GitHub. There you can follow the current state of development, review changes, and report possible bugs.

Visit the official BelaRemoteUI project on GitHub

Direct contact: Bittersweet1987 is also in the IRL4YOU Discord and happy to be approached there with questions about the project. Please don't share passwords, tunnel tokens, or full remote URLs in public channels.

Contact Bittersweet1987 in the IRL4YOU Discord

IRL4YOU is an independent information site. It did not develop BelaRemoteUI and is not officially affiliated with the project or BELABOX.

BELABOX Remote UI setup service

We help with the VPS, ports, profiles, Nginx, tunnel checks, and a safe test run. Credentials, secret links, and tokens stay with the operator and do not belong in public support messages.

Last technically reviewed: · Updated: · Published by IRL4YOU