Configure a reverse SSH tunnel in Integrate.io ELT & CDC to securely connect to private databases behind a firewall without opening inbound network ports.
Reverse SSH tunneling allows customers behind strict firewalls to connect their databases to Integrate.io without exposing any inbound ports. Instead of Integrate.io connecting to your server, you initiate an outbound SSH connection to our public jumphost, which creates a port forward that our pipeline containers connect through.
The reverse SSH tunnel host runs only a lightweight SSH client (autossh) that forwards a single port to your database. It performs no data processing, so a minimal VM is sufficient.Recommended minimum specification:
CPU: 1 vCPU
RAM: 1 GB
Disk: ~10 GB (OS plus autossh and tunnel logs)
OS: any current Linux distribution with systemd and OpenSSH, for example Ubuntu 20.04/22.04/24.04, Debian 11/12, Amazon Linux 2/2023, or RHEL/CentOS 8/9. Windows Server is also supported (see Reverse SSH Tunnel from Windows (PowerShell)).
Connectivity: outbound SSH access to the Integrate.io jump host.
This maps to the smallest common cloud instance types, such as AWS t3.micro / t4g.micro, Azure B1s, or GCP e2-micro.Sizing note: the only real constraint is network throughput for the database traffic being forwarded, not CPU or RAM. For high-volume CDC workloads, 2 vCPU / 2 GB with adequate network bandwidth is comfortable, but the host never needs to be sized like a data-processing node.
You need to generate an SSH key pair on the machine that will run autossh. The private key stays on your machine, the public key is pasted into Integrate.io.Supported key type: ssh-ed25519
After creation, you will see the Tunnel Endpoint (e.g. virginia-tunnel.flydata.app:12345). The status will show Setup Complete and Inactive until you establish the tunnel from your side.
The UI provides step-by-step setup instructions with pre-filled commands. All commands include your tunnel’s endpoint, port, and hostname. Click Copy to copy each one.
3a. Install autossh on your server (or a server that has access to your database):
AUTOSSH_GATETIME=0 prevents autossh from exiting if the first connection attempt takes longer than 30 seconds.3e. Add to crontab for automatic reconnect on reboot:Run crontab -e and add: