Edge Reverse Tunnels¶
This is the Tailscale-independent SSH fallback for reaching the ASS and APS
Linux VMs through data-ocean.gamb2le.co.uk when the Starlink or 5G WAN path
is reachable but direct inbound SSH is not.
The active design is:
| Edge host | data-ocean bind | Edge target |
|---|---|---|
ass-proxmox-linux |
127.0.0.1:2201 |
127.0.0.1:22 |
aps-proxmox-linux |
127.0.0.1:2202 |
127.0.0.1:22 |
The reverse tunnel clients live in GAMB2LE/aurora-edge-infra. The data-ocean
server-side account and SSH restrictions live in this repo.
Source-sync failover support is also present in this repo, but it is disabled by
default. The live source-sync hosts and ports remain the Tailscale values until
edge_source_sync_use_reverse_tunnels=true is set.
Use the Reverse Tunnel Rollout checklist for the live deployment sequence.
Server role¶
The edge_tunnel_server role is wired into playbooks/site.yml but disabled by
default:
edge_tunnel_server_enabled: false
edge_tunnel_server_allowed_inventory_hosts:
- aurora-cloud-droplet
When enabled on aurora-cloud-droplet, it creates a locked
aurora-tunnel system account and installs authorized keys restricted to remote
port forwarding for 127.0.0.1:2201 and 127.0.0.1:2202.
Use the focused playbook for check/apply work:
ansible-playbook playbooks/edge_tunnel_server.yml --check --diff \
-e edge_tunnel_server_enabled=true
Only run without --check after confirming current SSH access to data-ocean is
healthy and the tunnel public key has been prepared.
The optional sshd Match User fragment is also disabled by default:
Only enable that after confirming /etc/ssh/sshd_config includes
/etc/ssh/sshd_config.d/*.conf.
Client role¶
In GAMB2LE/aurora-edge-infra, the edge_reverse_tunnel role is attached to
linux_vms and disabled by default:
ass-proxmox-linux maps to 127.0.0.1:2201 and aps-proxmox-linux maps to
127.0.0.1:2202.
Source-sync tunnel transport¶
The source-sync scripts can be rendered for either Tailscale SSH or the reverse tunnel endpoints:
With the default false, source-sync jobs continue to use the Tailscale IPs on
port 22 and Tailscale SSH authentication.
With true, ASS-backed streams use 127.0.0.1:2201, APS-backed streams use
127.0.0.1:2202, and the scripts use normal SSH key authentication through the
forwarded edge SSH daemon. That requires a data-ocean private key:
edge_source_sync_ssh_key_path: /home/aurora/.ssh/id_ed25519_edge_source_sync
edge_source_sync_ssh_private_key_content: ""
edge_source_sync_ssh_private_key_source: ""
The matching public key must be authorized for the aurora user on
ass-proxmox-linux and aps-proxmox-linux before switching source-sync jobs to
the tunnel transport. In GAMB2LE/aurora-edge-infra, put that public key in
edge_source_sync_authorized_keys.
SSH access¶
After both sides are enabled and the tunnel services are running, connect
through data-ocean. Replace root with whichever admin account you normally use
to reach the droplet:
ssh -J root@data-ocean.gamb2le.co.uk -p 2201 aurora@127.0.0.1
ssh -J root@data-ocean.gamb2le.co.uk -p 2202 aurora@127.0.0.1
From a shell already on data-ocean:
Equivalent ~/.ssh/config aliases:
Host ass-proxmox-linux-tunnel
HostName 127.0.0.1
User aurora
Port 2201
ProxyJump root@data-ocean.gamb2le.co.uk
Host aps-proxmox-linux-tunnel
HostName 127.0.0.1
User aurora
Port 2202
ProxyJump root@data-ocean.gamb2le.co.uk
Safe rollout¶
- Generate one dedicated edge-to-data-ocean SSH keypair for the tunnel clients.
- Add the public key to
edge_tunnel_server_authorized_keysforaurora-cloud-droplet. - Run
playbooks/edge_tunnel_server.ymlin check mode first. - Apply this repo only after confirming the sshd config include path and current SSH access are healthy.
- Add the private key to the edge repo through Ansible Vault.
- Add the data-ocean source-sync public key to the edge repo as
edge_source_sync_authorized_keys. - Run the edge repo with
edge_managed_write_mode=trueandedge_reverse_tunnels_enabled=true. - Verify listeners on data-ocean:
ss -ltn '( sport = :2201 or sport = :2202 )'
ssh -p 2201 aurora@127.0.0.1 hostname
ssh -p 2202 aurora@127.0.0.1 hostname
edge_source_sync_use_reverse_tunnels=true and a configured
edge_source_sync_ssh_key_path.
Do not switch source-sync jobs from Tailscale to these tunnel endpoints until the tunnels have survived a soak period and the change has been checked against current operations.