Android Edge Nodes
Inexpensive Android phones used as rooted nodes for telephony, network egress and development, and how they connect back to the VPS.
An Android phone is a small computer with a battery, a mobile modem, a camera and a real SIM. Secondhand ones are cheap. In this lab, phones are the edge: the part that touches the physical world and the mobile network.
The nodes
| Node | Role | What it does |
|---|---|---|
| A14 | GSM gateway | Rooted. Runs the PhoneGate daemon for calls and SMS, and carries crawler traffic through a reverse tunnel. |
| A51 | Development node | Target for the development build of JobHunter, reached over a forwarded debug connection. |
| A06 | MCP node | Hosts an MCP node and reaches the llmRouter gateway through an authenticated proxy on the VPS. |
Phones come and go. They go to sleep, lose signal or get used for something else, which is why the status page treats the dev and MCP nodes as optional. The A14 matters more, because JobHunter and PhoneGate depend on it.
How nodes connect
The nodes sit behind carrier NAT, so nothing connects in to them. Every link is initiated by the phone or runs inside a private network.
- Tailscale gives each phone a stable private address. It is used for management: debug connections, updates and health checks. It is not used for public traffic.
- Reverse tunnels over HTTPS carry data the phone provides to the VPS, as described below.
- A watchdog on the VPS keeps the debug connections to the phones alive and reconnects them when a link drops.
Boot behaviour
A Magisk late_start service script starts the daemon and the proxies after Android has fully booted. Scripts are idempotent, so running one twice never starts a second process.
Direct egress for crawlers
Some job sites block datacenter addresses. JobHunter's crawler traffic therefore leaves through the A14 on its mobile connection:
JobHunter worker ─▶ SOCKS relay on the Docker network ─▶ VPS loopback
─▶ reverse tunnel over HTTPS (port 443) ─▶ A14 loopback ─▶ target site
The path is built so that it can only be used for this one purpose:
- The proxy on the phone listens on loopback only and accepts only loopback clients.
- It allows
CONNECTto port 443 only, and rejects private, carrier-grade NAT, Tailscale, link-local and reserved targets. Domain requests are limited to the target site and its WAF domain. - The tunnel client authenticates in three ways: HTTPS through Caddy, a mutual-TLS client certificate, and a username with a pinned server fingerprint.
- The tunnel server on the VPS listens on loopback only, and its auth file lets the client open exactly one reverse port.
- The relay on the Docker network is firewalled to the JobHunter network.
- Tailscale stays out of the data path. It is for management only.
Why a reverse tunnel
The phone sits behind a NAT it does not control, so the phone dials out. The VPS then reaches the phone's proxy as if it were a local port.
Rooted does not mean open
Root is what makes a phone useful as a node, and it is also the main risk. Secrets that live on a phone, such as the device token, are scoped so that losing the phone does not hand over the rest of the lab. See the PhoneGate security model.