9 ms·
Autossh – automatically restart SSH sessions and tunnels
- vincentpants 2y agoCurious what advantages this has over mosh? https://mosh.org/ https://mosh.org/
- deleted 2y ago[deleted]
- mjw1007 2y agomosh is for interactive sessions, to keep them working when the connection is flaky. autossh is for keeping unattended ssh tunnels alive, if the connection is flaky or one end is only intermittently available. So for using tunnels for the sort of thing you might otherwise use a VPN for.
- leni536 2y agoI have used autossh + tmux before to enable X forwarding (just for clipboard sharing). Couldn't do that in mosh.
- st380752143 2y agoAIK, for using mosh, you need to install mosh on target host as well. Seems like autossh doesn't need this step.
- suninsight 2y agoBiggest issue i have with mosh is that it you cant scroll up the history. It is kind of a deal breaker for me.
- lloeki 2y agohence why most throw in tmux/screen on the other end, possibly automatically so: https://github.com/blinksh/blink/discussions/1526 https://github.com/blinksh/blink/discussions/1526
- sgt 2y agoRather than using AutoSSH for port forwarding and such, I just create a systemd unit with a restart policy. Then you don't need autossh at all, just use ssh.
- xk3 2y agoIf you have systemd, you could do this: [Unit] Description=look ma, no autossh After=network.target [Service] Type=exec ExecStart=/usr/bin/ssh -o ServerAliveInterval=60 -o ExitOnForwardFailure=yes -Nn -R 7070:localhost:22 pc 'sleep 20m' Restart=always RestartSec=20 RuntimeMaxSec=30m [Install] WantedBy=default.target
- nine_k 2y ago[flagged]
- sevg 2y agoDo we really still have to turn every conversation into systemd friction?
- redundantly 2y ago[flagged]
- nine_k 2y agoNo. Some people use ssh while not running Linux, and not by running something exotic; macOS is widely popular.
- ChoHag 2y agoThat's so much better than bourne/bash, which requires this monstrous wart of a code blob: autossh() { # Tiny delay after failure in case of connection errors while ! ssh "$@"; do echo Restarting ssh "$@"...; sleep 1; done }
- botto 2y agoThis is quite clean and tidy
- denimnerd42 2y agobeen doing this since 2012... autossh wasn't the solution back then even. you want ServerAliveCountMax too but default is 3.
- ndreas 2y agoI used to use autossh to set up a SOCKS proxy to tunnel my web browser traffic via my home network and it worked really well. Also had a ControlMaster on the tunnel which made SSH connections to my server instantaneous. Nowadays I use wireguard an a dedicated SOCKS proxy. The upside is that I can access everything on my home network directly without having to tunnel.
- isoprophlex 2y agoNot 100% the same use case as autossh was built for maybe, but I'm now simply throwing tailscale on every box i need to interact with. Does away with all the port forwarding stuff, it's absolutely delightful.
- amlib 2y agoHow much reliance on third party am I subjecting myself by using Tailscale? What happens if I make a local connection to a machine/service running on Tailscale, does it still go out of the local network? If so, is the bulk of the payload transferred locally? Is there any advantage on using it if the machine/service is easily accessible over ipv6?
- botto 2y agoThat's what Tailscale is built for, when it can it sets up a P2P connection, it only ever sends data through Tailscales servers if you are in a restrictive network environment (i.e. corp network that controls all inbound and outbound traffic)
- snailmailman 2y agoIt will route directly over the local network when possible. It will be encrypted through the VPN, so there will be some overhead. But will be as direct as it can be. It only routes through tailscales servers as a last resort, when it can’t find a direct route at all (usually because NAT holepunching fails somehow). Their “DERP” relay servers just relay the encrypted connection. I think you can use your own relay servers, but I don’t know if that feature can be disabled entirely. Headscale can be entirely self-hosted. It still uses the tailscale client applications- but is compatible.
- isoprophlex 2y agogood questions, pretty well answered by other commenters. if you are happy with the level of encryption you have on your 'plain' ipv6 connection, sure, use that. additionally the acl/auth system, their dns and service discovery thing is nice, though not essential.
- 2y ago
- leetrout 2y agoI used autossh to do terrible things securing redis back in 2013. Fantastic tool.
- r0n22 2y agoOhh tell me more?
- leetrout 2y agoWay back redis didnt have passwords at all. That got added but there was no secure transport support. So I ran redis in a higher memory box at rackspace separate from my db and my app server. I used autossh to forward 6379 from localhost on the app server(s) to the redis server. Worked like a charm and never caused any issues. Other commenters are right in that wireguard is a great modern solution to this!
- frizlab 2y agoHow is this different from this ssha () { while true do ssh "$@" sleep 1 done true } EDIT: Oh I think I know, autossh must be detecting when the connexion is closed but ssh does not automatically…
- beagle3 2y agoSsh does with the right settings and has for about a decade - see the systemd example someone posted above.
- botto 2y agoI've used autossh to have a reverse tunnel open connection back to my work desktop, IT never found it and I had that in place for year
- hi-v-rocknroll 2y agoThe last time I used autossh it was on a client site to keep 2 layers of ssh tunnels open to jump through their network isolation hoops. In general, when flexibility is possible, such a use-case nowadays would often be better served by deploying WireGuard. Grouchy, out-of-touch corporate net admins probably don't even know what it is and insist on their antiquated Cisco VPNs.
- beagle3 2y ago14 years ago, i was using auto ash to keep SSH tunnels up; but at some point (quite far back - perhaps 2016?) ssh gained everything needed to do this internally except the restart. At this point I configure all of the keep alive and retry options in ssh_config and sshd_config, and use While true; do ssh user@host ; sleep 10; done To get the same effect, but with much more flexibility - e.g. alternating connection addresses on a multihomed host, add logging, run from daemontools or systemd unit instead of a loop and let them track the process and restart, etc.
- amelius 2y agoNice tool, but I'm getting tired of using port numbers for everything instead of more descriptive strings. My system has more than 10 tunnels and servers running, and since I only do sysadmin work once every half year or so, the port numbers are very cumbersome to deal with.
- jclulow 2y agoI believe these days SSH is willing to forward a UNIX domain socket to a remote TCP port, or a local TCP port to a remote UNIX domain socket, or any combination of the two families really. You could use names locally, if your client tools are willing to do AF_UNIX!
- mjw1007 2y agoThe nice thing about this is that, with filesystem permissions on one end and a check for SCM_CREDENTIALS or SO_PEERCRED on the other, you can effectively get user-based access control working between two machines. I think this is the one remaining advantage of ssh tunnels over using a VPN. NB if you're doing this sort of thing, you probably want to add `StreamLocalBindUnlink yes` to the ssh options.
- aflukasz 2y agoAnd if you are wondering, if you can just point your browser to a local unix socket (without setting up a proxy - which will listen on... local tcp port), then no, but maybe some day? Anyway: - https://bugzilla.mozilla.org/show_bug.cgi?id=1688774 https://bugzilla.mozilla.org/show_bug.cgi?id=1688774 - [open] "Support HTTP over unix domain sockets" - 4 years old, last activity 7 months ago, - https://issues.chromium.org/issues/40402523 https://issues.chromium.org/issues/40402523 - [closed; won't fix] "[ENH] Support HTTP over Unix Sockets via http://localhost:[/tmp/socket]/foo http://localhost:[/tmp/socket]/foo convention " - 9 years old, last activity 11 months ago.
- sjf 2y agoAgreed, I have so many services that all want to run their own webserver, db, elasticsearch, etc. I have to start using non-standard port numbers and it’s a burden to have to keep track of them.
- dheera 2y agoautossh is nice but the default options suck. I have to do something like this for it to work well autossh -f -N -o ServerAliveCountMax=2 -o ServerAliveInterval=5 -o ConnectTimeout=5 -o BatchMode=yes [...]
- chasil 2y agoUse stunnel for non-interactive tunneling over TLS. It is much more straightforward than ssh for this purpose, and works well with socket activation under systemd. I use it with the systemd automounter to encrypt NFSv4, and I have found it to be quite reliable.
- dingi 2y agoSometime back, I had a rapsberry pi connected to wired network of a coworking space. I remember using autossh to keep a tunnel open with one of my VPS. Mainly used it as a torrent box. I added magnet links through qbittorrent webui installed on raspberry pi. Qbittorrent was configured to only run at night time to not cause issues for business work. Downloaded all sort of things easily reaching thousands of GBs throughout my time there. They never found out. Or they didn't care to look. Good times.
- qwertox 2y agoI use this to set up reverse tunnels, for example to set up MongoDB replica sets which sync through SSH. It kind of simplifies the security aspect of replica sets a bit, since then MongoDB does not need to be exposed to the internet and no VPN setup is needed.
- aborsy 2y agoWouldn’t ssh with systemd or auto ssh be a more secure means of remote access to apps (like http/https apps) than the zero trust network access solutions (like Cloudflare Tunnels which terminates the TLS) or even Tailscale (which should be a trusted third party)? You set up public key authentication with SSH to a reverse proxy, a persistent tunnel, and a socks proxy. In a Firefox profile, you set localhost:port. Done! All your services are available in that browser all the time. Autossh with a reverse ssh tunnel can also be used to expose an internal service to the Internet through a VPS. SSH has been very secure over the decades. A good feature of SSH is that it can jump from host to host, unlike VPN.
- curben 2y agoSSH protocol does not protect against weak configuration, e.g. password authentication without brute force mitigation. Zero-trust can be misconfigured too, so it depends how well either of them is configured.
- whalesalad 2y agomosh
- bashkiddie 2y agoI used to be a happy user of `autossh` until 2023. I used it on Cygwin on Windows and was quite happy how reliably it set up my tunnels (upon tunnels) in a flaky corporate network. `autossh` worked reliable compared to `ssh`s many timeout options. I would still recommend it.
- mifydev 2y agoI’d recommend https://eternalterminal.dev/ https://eternalterminal.dev/, compared to mosh(poor colors support), this is the only thing that manages to consistently keep up my ssh sessions.
- goode 2y agoI love ET. Some discussion here of its advantages over mosh: https://news.ycombinator.com/item?id=21640200 https://news.ycombinator.com/item?id=21640200. Beware that ET does phone home: depending on how it's packaged for your system, telemetry is enabled by default in /etc/et.cfg.
- 89nn 2y agoIs there anything like this but for `kubectl port-forward`?
- pawelduda 2y agoI used autossh to access hundreds of on prem client machines via a reverse SSH tunnel. Never failed me!
- eichin 2y agoPer https://github.com/Autossh/autossh/issues/7 https://github.com/Autossh/autossh/issues/7 this is not upstream - that would be https://www.harding.motd.ca/autossh/ https://www.harding.motd.ca/autossh/
- paulfharrison 2y agoFor web-servers on remote machines, I have found this useful: socat TCP4-LISTEN:1234,fork,bind=127.0.0.1 EXEC:'ssh my.remote.server nc 127.0.0.1 1234' 1234 = local/remote port. Can be adapted to use unix sockets at the remote end. my.remote.server = your remote server address. This will set up a tunnel only when needed, and seems to play nicely with my browser.
- cperciva 2y agoIf your concern is to have secure tunnels between hosts, you should probably use spiped rather than SSH, since it uses a separate TCP connection for each pipe -- this avoids the "connection dropped" problem and also the "multiplexing many connections over one TCP connection" performance hit. Also, spiped is way simpler and more secure than SSH. (On my servers, I tunnel SSH over spiped, to protect the sshd from attacks.)
- whatever1 2y agoWhy SSH does not do this by default? Why the average Joe wants his SSH session to timeout?
- oxygen_crisis 2y agoThere's no timeout on SSH sessions by default. In good conditions you can go months without sending a single byte of traffic between an SSH server and client and both will pick up the connection just fine when it's time to communicate again. You could cut off traffic between them for any amount of time and they would be none the wiser as long as the network connection is back to normal when they finally try to send traffic again. (I had SSH sessions in a QA lab persist as if nothing had happened after the connection between the endpoints was down for almost a week while we replaced the aggregation layer routers. They never saw a link state change since the access layer switches were up the whole time. They never attempted to communicate while the connections between those were down, so there was never any problem as far as they were concerned.) The keepalives and connection checks and so forth are mostly to account for things like stateful network gear (firewalls, NAT routers, etc) between the endpoints that will cease relaying traffic between them if they are quiet for too long.
- _davide_ 2y agoMay I suggest a tool built for application level portals instead? https://github.com/build-trust/ockam https://github.com/build-trust/ockam One binary, easy to use, no ssh getting stuck! (yep, I work at Ockam :)
- jbverschoor 2y agoCan’t recommend… just loop ssh. I’ve run autossh for quite some time but it was not reliable enough under my conditions