How to Access ReClip from an External Network: Flask Host Binding Guide
To access ReClip from an external network, set the HOST environment variable to 0.0.0.0 before starting the Flask server, ensuring port 8899 is open in your firewall.
The averygan/reclip repository runs a Flask web application that defaults to localhost-only access for security. By default, the server binds to 127.0.0.1, which prevents remote machines from reaching the service. Understanding how to modify this binding configuration is essential for deploying ReClip in networked environments or Docker containers.
Understanding ReClip's Default Network Binding
In app.py, the Flask application reads its host configuration from environment variables with a secure default. The specific lines that control network accessibility are:
host = os.environ.get("HOST", "127.0.0.1")
This implementation at app.py#L9-L10 means that without explicit configuration, the server only accepts connections from the local machine. The PORT variable similarly defaults to 8899 but can be overridden to match your network requirements.
Binding to 127.0.0.1 (localhost) is a security feature that prevents accidental exposure during development. To make ReClip accessible from other devices on your network or the internet, you must override this default by setting HOST=0.0.0.0, which instructs Flask to listen on all available network interfaces.
Method 1: Exposing ReClip via Environment Variables (Local Python)
When running ReClip directly with Python, you can expose it externally by exporting the correct environment variables before executing the startup script.
Configuration Steps
- Export the
HOSTvariable set to0.0.0.0to enable all interfaces - Optionally specify a custom
PORT(default is 8899) - Run the
reclip.shconvenience script to start the server
# Example 1 – Run locally and expose to the network
export HOST=0.0.0.0 # bind to all interfaces
export PORT=8899 # optional, defaults to 8899
./reclip.sh # starts the Flask app
# Access from another machine:
# http://<your-host-ip>:8899
The reclip.sh script automatically picks up these environment variables and launches the application with the specified binding configuration. Ensure the chosen port is not blocked by your operating system's firewall before attempting external connections.
Method 2: Docker Deployment with External Access
Containerized deployments require both the Docker port mapping and the Flask host configuration to work together for external accessibility.
Docker Run Command
Use the -p flag to map the container port to your host, and the -e flags to set the internal host binding:
# Example 2 – Docker run with explicit host binding
docker run -d \
-p 8899:8899 \
-e HOST=0.0.0.0 \
-e PORT=8899 \
averygan/reclip
# Visit http://<docker-host-ip>:8899 from any device on the same network
The -p 8899:8899 mapping exposes the container's port to the host machine, while HOST=0.0.0.0 ensures Flask listens on the container's external interface rather than just localhost within the container.
Docker Compose Configuration
When using docker-compose.yml, add the HOST environment variable to ensure external reachability:
# Example 3 – docker-compose.yml snippet (add or verify)
services:
reclip:
build: .
ports:
- "8899:8899"
environment:
- HOST=0.0.0.0 # makes Flask listen on all interfaces
- PORT=8899
After updating the configuration, run docker compose up -d to start the service. Docker automatically forwards the mapped port, and the HOST environment variable ensures the Flask instance accepts connections from outside the container.
Network Security Considerations
Exposing ReClip to external networks requires attention to security infrastructure beyond the application configuration.
Firewall and Security Groups – Open port 8899 (or your custom port) on your host operating system, cloud provider security groups, or network router. Without this step, connection attempts will be blocked before reaching the Flask application.
NAT and Port Forwarding – When the host machine sits behind a residential or corporate router, configure port forwarding to direct external traffic on port 8899 to the internal IP address of your ReClip host.
TLS and Reverse Proxies – For production environments, avoid exposing Flask directly to the internet. Instead, deploy a reverse proxy such as nginx, Caddy, or Traefik in front of ReClip. This architecture provides HTTPS encryption, load balancing, and optional authentication mechanisms that the default Flask development server does not include.
Summary
- Default security: ReClip binds to
127.0.0.1via theHOSTenvironment variable inapp.pyto prevent unauthorized remote access during development - External access: Set
HOST=0.0.0.0to enable listening on all network interfaces before starting the server - Script support: The
reclip.shstartup script automatically uses exported environment variables for configuration - Docker requirements: Both port mapping (
-p 8899:8899) and host binding (-e HOST=0.0.0.0) are necessary for containerized external access - Production hardening: Use a reverse proxy with TLS termination rather than direct external exposure of the Flask development server
Frequently Asked Questions
Why does ReClip default to localhost only?
ReClip defaults to 127.0.0.1 as a security measure implemented in app.py to prevent accidental exposure of the development server to untrusted networks. This default requires explicit action (setting HOST=0.0.0.0) to enable external access, ensuring administrators consciously choose to open the service.
What port does ReClip use by default?
ReClip uses port 8899 by default. This can be modified by setting the PORT environment variable to any available port number before starting the application. Both the reclip.sh script and Docker configurations respect this variable when present.
Is it safe to expose ReClip directly to the internet?
Exposing ReClip directly to the internet is not recommended for production use. The underlying Flask development server is not optimized for production traffic and lacks built-in security features like HTTPS. Instead, place a reverse proxy (nginx, Caddy, or Traefik) in front of ReClip to handle TLS encryption, connection pooling, and access control.
How do I check if the port is accessible externally?
Test external accessibility using telnet or curl from a remote machine: telnet <your-server-ip> 8899. If the connection times out, verify that the HOST environment variable is set to 0.0.0.0, check local firewall rules with sudo iptables -L or ufw status, and confirm any router port forwarding rules are active.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →