Connection Principles

Problems with Traditional VPS

When using traditional VPS, you typically need to:

  1. Open ports โ€” Firewall settings to allow external inbound connections (22 for SSH, 80/443 for HTTP)
  2. Fixed IP or domain โ€” To know where to connect
  3. Handle DDoS protection โ€” Public services are vulnerable to attacks
  4. Manage SSL certificates โ€” HTTPS requires regular certificate renewal

This is too high a technical barrier for business owners.


RealVcoโ€™s Solution: Cloudflare Tunnel

RealVco uses Cloudflare Tunnel (formerly Argo Tunnel) to solve these problems.

How It Works

        You (Browser/Phone)
              โ”‚
              โ–ผ HTTPS
    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
    โ”‚   Cloudflare CDN    โ”‚ โ—„โ”€โ”€ SSL termination, DDoS protection
    โ”‚   (Global nodes)    โ”‚
    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
              โ”‚
              โ–ผ Encrypted tunnel
    โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
    โ”‚  Cloudflare Tunnel  โ”‚
    โ”‚   (cloudflared)     โ”‚
    โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜
              โ”‚
              โ–ผ Outbound only
        โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
        โ”‚ Your VPS    โ”‚ โ—„โ”€โ”€ No inbound ports needed
        โ”‚ (mVPS)      โ”‚
        โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Key Features

FeatureDescriptionBenefit
Outbound-onlyVPS actively connects out to CloudflareFirewall doesnโ€™t need any inbound ports open
Encrypted tunnelAll traffic goes through encrypted tunnelCannot be eavesdropped or tampered with
CDN acceleration300+ global nodesFast connections, wherever you are
DDoS protectionBuilt-in Cloudflare protectionProtect your services from attacks
Auto SSLCloudflare manages certificatesNo manual HTTPS setup needed

What This Means for You

โœ… Security Improvements

  • No public ports: Your VPS has no public inbound ports open
  • Hidden real IP: External parties only see Cloudflareโ€™s IP, not your VPS IP
  • Automatic protection: DDoS attacks are absorbed by Cloudflare, not affecting your service

โœ… Convenience Improvements

  • No domain setup needed: RealVco provides *.realvco.com subdomains
  • Automatic HTTPS: SSL certificates auto-renew, no expiration worries
  • Global acceleration: Fast connections whether youโ€™re in Taiwan, US, or Europe

โœ… Simplified Management

  • No firewall setup: No need to configure iptables or UFW
  • No port forwarding: No router or NAT configuration needed
  • No certificate management: No Letโ€™s Encrypt or SSL setup required

Technical Architecture

Inside Your mVPS

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚           Your mVPS                  โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”   โ”‚
โ”‚  โ”‚  Cloudflare Tunnel Agent    โ”‚   โ”‚ โ—„โ”€โ”€ Establishes outbound connection
โ”‚  โ”‚      (cloudflared)          โ”‚   โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜   โ”‚
โ”‚              โ”‚                      โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ผโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”         โ”‚
โ”‚  โ–ผ           โ–ผ           โ–ผ         โ”‚
โ”‚ โ”Œโ”€โ”€โ”€โ”€โ”    โ”Œโ”€โ”€โ”€โ”€โ”    โ”Œโ”€โ”€โ”€โ”€โ”        โ”‚
โ”‚ โ”‚Roseโ”‚    โ”‚Ada โ”‚    โ”‚Vi  โ”‚        โ”‚ โ—„โ”€โ”€ 3 AI partners
โ”‚ โ”‚:80 โ”‚    โ”‚:80 โ”‚    โ”‚:80 โ”‚        โ”‚
โ”‚ โ””โ”€โ”€โ”€โ”€โ”˜    โ””โ”€โ”€โ”€โ”€โ”˜    โ””โ”€โ”€โ”€โ”€โ”˜        โ”‚
โ”‚   โ”‚         โ”‚         โ”‚            โ”‚
โ”‚  โ”Œโ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”          โ”‚
โ”‚  โ”‚   OpenClaw Gateway  โ”‚          โ”‚
โ”‚  โ”‚    (Port 8080)      โ”‚          โ”‚
โ”‚  โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜          โ”‚
โ”‚            โ”‚                       โ”‚
โ”‚  โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ดโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”           โ”‚
โ”‚  โ–ผ                    โ–ผ           โ”‚
โ”‚ โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”       โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”       โ”‚
โ”‚ โ”‚Admin   โ”‚       โ”‚Public  โ”‚       โ”‚
โ”‚ โ”‚Panel   โ”‚       โ”‚Pages   โ”‚       โ”‚
โ”‚ โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜       โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜       โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Access URL Mapping

ServiceInternal PortPublic URL
Admin Panel8080https://xxx-00.realvco.com
Rose18100https://xxx-1.realvco.com
Ada18200https://xxx-2.realvco.com
Vi18300https://xxx-3.realvco.com

All URLs go through Cloudflare CDN for acceleration and protection.


Limitations and Considerations

โš ๏ธ Dependency on Cloudflare

  • If Cloudflare service is interrupted, connections will be affected
  • But your VPS local services continue running normally
  • Can connect directly via SSH (if configured) for maintenance

โš ๏ธ Bandwidth Limitations

  • Cloudflare Tunnel has no limit on HTTP traffic
  • But large file transfers may be slower (through CDN)
  • For large file transfers, use SFTP/SCP to connect directly to VPS

โš ๏ธ Geographic Limitations

  • RealVco service is available globally
  • But some countries/regions may not access Cloudflare (very few)

Further Reading