SSH tunnels
A connection can go through an SSH server, often called a bastion or jump host. Recern opens the tunnel when it connects and closes it when the connection closes.
Settings
| Setting | Notes |
|---|---|
| SSH host and port | Port 22 by default. |
| User | The user on the SSH server. |
| Authentication | Password, Key file (with its passphrase, if any) or SSH agent. |
The database host and port are then resolved from the SSH server, so localhost means the SSH server itself.
Host keys
Recern checks the SSH server's host key before sending anything:
- Keys in your
~/.ssh/known_hostsare accepted. Recern only reads that file. - The first time Recern meets an unknown server, it shows the key's fingerprint and asks whether to trust it. Trusted keys are saved in Recern's own
known_hostsfile. - If a server's key has changed, Recern refuses to connect and names the file and line with the old key. Remove that line if the change is expected.
TLS through a tunnel
PostgreSQL connections can use TLS through a tunnel: the certificate is still checked against the database host name.
Redis connections through a tunnel do not support TLS yet. Turn off TLS for such a connection; the SSH tunnel already encrypts the traffic up to the SSH server.