Deploy ech-tls-tunnel + ssserver on a Linux VPS (port 443, ACME auto-renew, optional unowned cover name) and the matching sslocal client as a macOS LaunchAgent HTTP/HTTPS proxy. Use when the user asks to set up, redeploy, rotate keys, or change the cover name for the SIP003 tunnel.
2026-05-09