NodeForEdge

Documentation / Platform

Android Edge Nodes

Inexpensive Android phones used as rooted nodes for telephony, network egress and development, and how they connect back to the VPS.

An Android phone is a small computer with a battery, a mobile modem, a camera and a real SIM. Secondhand ones are cheap. In this lab, phones are the edge: the part that touches the physical world and the mobile network.

The nodes

Node Role What it does
A14 GSM gateway Rooted. Runs the PhoneGate daemon for calls and SMS, and carries crawler traffic through a reverse tunnel.
A51 Development node Target for the development build of JobHunter, reached over a forwarded debug connection.
A06 MCP node Hosts an MCP node and reaches the llmRouter gateway through an authenticated proxy on the VPS.

Phones come and go. They go to sleep, lose signal or get used for something else, which is why the status page treats the dev and MCP nodes as optional. The A14 matters more, because JobHunter and PhoneGate depend on it.

How nodes connect

The nodes sit behind carrier NAT, so nothing connects in to them. Every link is initiated by the phone or runs inside a private network.

  • Tailscale gives each phone a stable private address. It is used for management: debug connections, updates and health checks. It is not used for public traffic.
  • Reverse tunnels over HTTPS carry data the phone provides to the VPS, as described below.
  • A watchdog on the VPS keeps the debug connections to the phones alive and reconnects them when a link drops.

Boot behaviour

A Magisk late_start service script starts the daemon and the proxies after Android has fully booted. Scripts are idempotent, so running one twice never starts a second process.

Direct egress for crawlers

Some job sites block datacenter addresses. JobHunter's crawler traffic therefore leaves through the A14 on its mobile connection:

JobHunter worker ─▶ SOCKS relay on the Docker network ─▶ VPS loopback
      ─▶ reverse tunnel over HTTPS (port 443) ─▶ A14 loopback ─▶ target site

The path is built so that it can only be used for this one purpose:

  • The proxy on the phone listens on loopback only and accepts only loopback clients.
  • It allows CONNECT to port 443 only, and rejects private, carrier-grade NAT, Tailscale, link-local and reserved targets. Domain requests are limited to the target site and its WAF domain.
  • The tunnel client authenticates in three ways: HTTPS through Caddy, a mutual-TLS client certificate, and a username with a pinned server fingerprint.
  • The tunnel server on the VPS listens on loopback only, and its auth file lets the client open exactly one reverse port.
  • The relay on the Docker network is firewalled to the JobHunter network.
  • Tailscale stays out of the data path. It is for management only.

Why a reverse tunnel

The phone sits behind a NAT it does not control, so the phone dials out. The VPS then reaches the phone's proxy as if it were a local port.

Rooted does not mean open

Root is what makes a phone useful as a node, and it is also the main risk. Secrets that live on a phone, such as the device token, are scoped so that losing the phone does not hand over the rest of the lab. See the PhoneGate security model.

Built 2026-10-06. Addresses, tokens and ports are left out on purpose.