Add SSH-over-tunnel sub-doc to woltspace-cloudflare skill - #382
Open
woltspace-jerpint[bot] wants to merge 1 commit into
Open
Add SSH-over-tunnel sub-doc to woltspace-cloudflare skill#382woltspace-jerpint[bot] wants to merge 1 commit into
woltspace-jerpint[bot] wants to merge 1 commit into
Conversation
SSH to the host through the existing named tunnel: ingress rule to host.docker.internal:22, DNS CNAME, dedicated owner-only Access app (never the wildcard app), client ProxyCommand setup, key-only hardening, and rollback steps. Written from the live setup verified on ssh.woltspace.com. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
New
ssh.mdsub-doc in thewoltspace-cloudflareskill + one router row in SKILL.md. Documents how to expose the host machine's sshd atssh.{domain}through the existing named tunnel so the owner can ssh/scp/VS-Code-Remote in from anywhere — with zero ports opened on the router.Why
jerpint asked for external ssh access and wanted it documented so anyone can set it up. The doc is written from the live setup running right now on
ssh.woltspace.com(every step verified, including the edge-app precedence check).Design points
ssh://host.docker.internal:22, not localhost — the tunnel runs inside the container, so localhost would be the container. Doc warns about non-Docker-Desktop setups.*.{domain}wildcard or it never matches.Security model (as documented)
Outbound-only tunnel (no scannable ports) → Access email OTP at the edge (nobody reaches the handshake unauthenticated) → end-to-end SSH crypto (Cloudflare proxies ciphertext) → normal ssh key auth. Attack path requires owner's inbox AND owner's private key.
🤖 Generated with Claude Code