Docs

Tunnels and forwards

Ports on your instances, and anything they can reach, on your Mac's loopback.

Updated

New Tunnel… (⌘T), or Tunnel to Port… on an instance, forwards a port of that instance to 127.0.0.1 on your Mac. Pick a preset (SSH, RDP, PostgreSQL, MySQL, SQL Server, Redis, HTTP, HTTPS) or a custom port. The local port stays the same between runs, and Start automatically when this account opens brings the tunnel back with its account.

Under Options, Access decides which programs on your Mac may use the tunnel:

  • Ostgate only: the default for SSH, RDP and custom ports.
  • My processes: any app running as your macOS user, such as a database client or a browser. The default for database and web presets.
  • Any local process…: every program on the Mac, only after you confirm a shared tunnel.

Tunnels are listed under Connections and in the menu bar. They keep running when you close the window, and reconnect by themselves after a network drop. Copy Command gives you the matching client command line.

  • Forward profiles (Connections › Forwards › New Forward Profile…) reach anything a chosen VM can see, several ports at once over one SSH session: an internal load balancer, a private database, any internal address. Optionally they manage /etc/hosts aliases while running, after macOS asks for an administrator's password.
  • Cloud SQL: Open Tunnel… on an instance with a private IP reaches it through one of your running VMs on the same network.
  • Cloud Run: Open in Browser opens an internal-only service through a local proxy. Services that require IAM authentication cannot be opened yet.
  • Local › Local Ports lists every listener on your Mac's loopback and stops stuck ones; Local › Hosts edits /etc/hosts.