Docs
Tunnels and forwards
Ports on your instances, and anything they can reach, on your Mac's loopback.
Updated
New Tunnel… (⌘T), or Tunnel to Port… on an instance, forwards a
port of that instance to 127.0.0.1 on your Mac. Pick a preset (SSH, RDP,
PostgreSQL, MySQL, SQL Server, Redis, HTTP, HTTPS) or a custom port. The local port stays
the same between runs, and Start automatically when this account opens brings the
tunnel back with its account.
Under Options, Access decides which programs on your Mac may use the tunnel:
- Ostgate only: the default for SSH, RDP and custom ports.
- My processes: any app running as your macOS user, such as a database client or a browser. The default for database and web presets.
- Any local process…: every program on the Mac, only after you confirm a shared tunnel.
Tunnels are listed under Connections and in the menu bar. They keep running when you close the window, and reconnect by themselves after a network drop. Copy Command gives you the matching client command line.
- Forward profiles (Connections › Forwards › New Forward Profile…) reach
anything a chosen VM can see, several ports at once over one SSH session: an internal
load balancer, a private database, any internal address. Optionally they manage
/etc/hostsaliases while running, after macOS asks for an administrator's password. - Cloud SQL: Open Tunnel… on an instance with a private IP reaches it through one of your running VMs on the same network.
- Cloud Run: Open in Browser opens an internal-only service through a local proxy. Services that require IAM authentication cannot be opened yet.
- Local › Local Ports lists every listener on your Mac's loopback and stops stuck
ones; Local › Hosts edits
/etc/hosts.