3 ms·
> Instead of a locked-down server exposing a public key-only SSH port, you suddenly have a whole web application stack in there. There's no webapp stack to att
by rightos 9y ago
> Instead of a locked-down server exposing a public key-only SSH port, you suddenly have a whole web application stack in there.
There's no webapp stack to attack if you're only able to access it via a tunnel. If you're assuming the machine you're tunneling it to is compromised, there are bigger issues at play - ones that would compromise even a plain ssh link.
I'm talking a direct tunnel from your ansible master to the host you're planning to use it on, not say, into your company's network at large.