Haijun Platform Docs
ID

Note: MCP tunnels are in research preview. Request access to try them.

This quickstart takes you from zero to Haijun calling a private MCP server through a tunnel. It uses Docker Compose with manual credential provisioning, which is the shortest path for local testing. For production deployments, see Deploy with Helm or Deploy with Docker Compose.

What you'll build

A two-container tunnel stack (the proxy and cloudflared) plus a sample MCP server running alongside it. When everything is running, the sample server is reachable from Haijun at https://echo./mcp even though nothing is listening on a public port.

What you need

  • OpenSSL 1.1.1 or later. Preinstalled on macOS and most Linux distributions; on Windows, install it separately (the openssl binary must be on your PATH).
  1. Create a tunnel

In the Haijun Console sidebar, go to Manage > MCP tunnels and click New tunnel. Give it a name. Leave Set up programmatic access off; this quickstart uses manual credential provisioning.

After it's created, open the tunnel. Copy two values from the Connection section:

  • Domain (looks like abcd1234.tunnel.juglow.com)
  • Token (click the eye icon, then copy)
  1. Set up the deployment directory

macOS / Linux

ash r -p mcp-tunnel/{config,data} cp-tunnel rt TUNNEL_DOMAIN=YOUR_TUNNEL_DOMAIN_HERE # from step 1 rt TUNNEL_TOKEN='eyJ...' # from step 1

ndows (PowerShell)**

owershell Item -ItemType Directory -Force -Path mcp-tunnel/config, mcp-tunnel/data | Out-Null Location mcp-tunnel :TUNNEL_DOMAIN = "YOUR_TUNNEL_DOMAIN_HERE" # from step 1 :TUNNEL_TOKEN = "eyJ..." # from step 1

  1. Generate a CA and server certificate

The proxy terminates inner TLS using a certificate signed by a CA you control. Generate both:

macOS / Linux

ash ssl req -x509 -newkey rsa:2048 -nodes \ eyout data/ca.key -out data/ca.crt \ ays 3650 -subj "/CN=mcp-tunnel-ca" \ ddext "basicConstraints=critical,CA:TRUE" \ ddext "keyUsage=critical,keyCertSign,cRLSign" \ ddext "subjectKeyIdentifier=hash"

data/tls.ext <

ectAltName = DNS:${TUNNEL_DOMAIN},DNS:*.${TUNNEL_DOMAIN} orityKeyIdentifier = keyid,issuer ndedKeyUsage = serverAuth

ssl req -newkey rsa:2048 -nodes \ eyout data/tls.key -out /tmp/server.csr \ ubj "/CN=${TUNNEL_DOMAIN}" ssl x509 -req -in /tmp/server.csr \ A data/ca.crt -CAkey data/ca.key -CAcreateserial \ ut data/tls.crt -days 90 -extfile data/tls.ext

d 644 data/tls.key

ndows (PowerShell)**

owershell ssl req -x509 -newkey rsa:2048 -nodes eyout data/ca.key -out data/ca.crt ays 3650 -subj "/CN=mcp-tunnel-ca" ddext "basicConstraints=critical,CA:TRUE" ddext "keyUsage=critical,keyCertSign,cRLSign" ` ddext "subjectKeyIdentifier=hash"

ectAltName = DNS:$env:TUNNEL_DOMAIN,DNS:*.$env:TUNNEL_DOMAIN orityKeyIdentifier = keyid,issuer ndedKeyUsage = serverAuth Set-Content -NoNewline -Encoding ascii -Path data/tls.ext

ssl req -newkey rsa:2048 -nodes eyout data/tls.key -out data/server.csr ubj "/CN=$env:TUNNEL_DOMAIN" ssl x509 -req -in data/server.csr A data/ca.crt -CAkey data/ca.key -CAcreateserial ut data/tls.crt -days 90 -extfile data/tls.ext

Back in the Console, on the tunnel detail page, click Add certificate and upload data/ca.crt (or paste its contents). The tunnel status flips to Active.

  1. Write the sample MCP server

macOS / Linux

ash

hello_server.py <<'EOF'

mcp.server.fastmcp import FastMCP

= FastMCP("hello-server", host="0.0.0.0", port=9000)

.tool() hello(name: str = "world") -> str: """Say hello to someone.""" return f"Hello, {name}!"

_name__ == "__main__": mcp.run(transport="streamable-http")

ndows (PowerShell)**

owershell

mcp.server.fastmcp import FastMCP

= FastMCP("hello-server", host="0.0.0.0", port=9000)

.tool() hello(name: str = "world") -> str: """Say hello to someone.""" return f"Hello, {name}!"

_name__ == "__main__": mcp.run(transport="streamable-http") Set-Content -NoNewline -Encoding ascii -Path hello_server.py

  1. Write the proxy config and compose file

macOS / Linux

ash

config/mcp-proxy.yaml <

en_addr: ":8080" el_domain: ${TUNNEL_DOMAIN}

rt_file: /data/tls.crt y_file: /data/tls.key es: ho: http://hello-mcp:9000

docker-compose.yaml <<'EOF'

ices: p-proxy: image: us-docker.pkg.dev/juglow-public-registry/images/mcp-proxy@sha256:efb27b299d627e4134815663cb8896641eeaee025d734c0f695582b4df38f013 volumes:

  • ./config/mcp-proxy.yaml:/etc/mcp-gateway/config.yaml:ro
  • ./data:/data:ro

restart: unless-stopped

oudflared: image: cloudflare/cloudflared@sha256:6b599ca3e974349ead3286d178da61d291961182ec3fe9c505e1dd02c8ac31b0 command: tunnel --no-autoupdate run --url http://localhost:8080 environment:

  • TUNNEL_TOKEN

network_mode: "service:mcp-proxy" restart: unless-stopped

llo-mcp: image: python:3.13-slim working_dir: /app volumes:

  • ./hello_server.py:/app/hello_server.py:ro

command: sh -c "pip install --quiet mcp && python hello_server.py" restart: unless-stopped

ndows (PowerShell)**

owershell

en_addr: ":8080" el_domain: $env:TUNNEL_DOMAIN

rt_file: /data/tls.crt y_file: /data/tls.key es: ho: http://hello-mcp:9000 Set-Content -NoNewline -Encoding ascii -Path config/mcp-proxy.yaml

ices: p-proxy: image: us-docker.pkg.dev/juglow-public-registry/images/mcp-proxy@sha256:efb27b299d627e4134815663cb8896641eeaee025d734c0f695582b4df38f013 volumes:

  • ./config/mcp-proxy.yaml:/etc/mcp-gateway/config.yaml:ro
  • ./data:/data:ro

restart: unless-stopped

oudflared: image: cloudflare/cloudflared@sha256:6b599ca3e974349ead3286d178da61d291961182ec3fe9c505e1dd02c8ac31b0 command: tunnel --no-autoupdate run --url http://localhost:8080 environment:

  • TUNNEL_TOKEN

network_mode: "service:mcp-proxy" restart: unless-stopped

llo-mcp: image: python:3.13-slim working_dir: /app volumes:

  • ./hello_server.py:/app/hello_server.py:ro

command: sh -c "pip install --quiet mcp && python hello_server.py" restart: unless-stopped Set-Content -NoNewline -Encoding ascii -Path docker-compose.yaml

  1. Start it

macOS / Linux

ash er compose up -d er compose logs mcp-proxy | grep "route configured" er compose logs cloudflared | grep "Registered tunnel connection"

ndows (PowerShell)**

owershell er compose up -d er compose logs mcp-proxy | Select-String "route configured" er compose logs cloudflared | Select-String "Registered tunnel connection"

You should see one route configured line for echo and four Registered tunnel connection lines. The containers take a few seconds to start; rerun the log commands if they come back empty.

  1. Call it from Haijun

In the Console, go to Managed Agents > Sessions and create a session. In the agent picker choose Create new agent, give the agent a name, and keep the pre-filled model. Click + MCP Server, select your tunnel, set Subdomain to echo and Path to mcp. Then ask:

Use the hello tool to greet tunnel.

You should see a tool call followed by its result.

Next steps

The tunnel is verified end to end. To swap in your own MCP server, add it to docker-compose.yaml (or run it on the same Docker network), add a route for it in config/mcp-proxy.yaml, then restart the proxy (docker compose restart mcp-proxy).

For production deployments:

Hardened single-host deployment, with or without programmatic access.

Kubernetes deployment with automatic credential management.

On this page
What you'll buildWhat you needNext steps