gcloud start-iap-tunnel vs Ostgate: IAP on a Mac

If you already reach Compute Engine VMs from a Mac with gcloud, Terminal and Microsoft's Windows App, you have a setup that works and costs nothing. Ostgate is a paid native macOS app that opens the same Identity-Aware Proxy TCP tunnels itself, with SSH, Remote Desktop, file transfer and port tunnels in one window. This page compares the two task by task, says when gcloud is the better tool, and lists what Ostgate does not do. If you are coming from Google's IAP Desktop on Windows instead, read IAP Desktop for Mac.

By Ostgate · Updated

When gcloud is enough

The Google Cloud CLI is free, its source is licensed under Apache 2.0, and it runs on macOS, Linux and Windows. Stay with it, and skip a client, if most of these describe you:

  • You script or automate. CI jobs, deploy scripts and runbooks need a command line. Ostgate has none for that (see below).
  • You open a tunnel now and then. One gcloud compute ssh a week costs a few seconds of typing. For a VM without an external IP, gcloud compute ssh uses IAP on its own and prints "External IP address was not found; defaulting to using IAP tunneling".
  • You live in the terminal. SSH, scp and sftp through an ssh_config ProxyCommand cover Linux VMs completely.
  • Your team uses Linux or Windows laptops too, and one documented route for everyone serves it better than a Mac-only app.
  • Your access levels require a device certificate. gcloud can present one through gcloud auth enterprise-certificate-config; Ostgate cannot.

A client starts to pay off when several of these are daily work: Windows VMs over RDP, several ports or projects open at once, more than one Google account, a laptop that sleeps and changes networks, and colleagues who should not need to learn gcloud.

Side by side, by task

Both columns use the same IAP TCP forwarding, the same firewall rule from 35.235.240.0/20 and the same IAM role, roles/iap.tunnelResourceAccessor.

Taskgcloud + Windows AppOstgate
SSH gcloud compute ssh; uses IAP when the VM has no external IP Double-click a Linux instance: a terminal tab
RDP A start-iap-tunnel to 3389, then Windows App to localhost Double-click a Windows instance: a Remote Desktop tab
Windows password gcloud compute reset-windows-password prints it; paste it into Windows App Set Windows Password…; can be saved for automatic logon
File transfer gcloud compute scp, or sftp through a tunnel Browse Files: an SFTP tab with Finder drag and drop
Port forwards One start-iap-tunnel process per port New Tunnel… with presets; local ports kept between runs
Private database, internal load balancer gcloud compute ssh to a VM with -- -N -L forwards Forward profiles: several forwards over one SSH session
Internal Cloud Run An SSH forward through a VM, plus an identity token for IAM Open Proxy… for services that need no token; IAM not yet
Several Google accounts One active per configuration; --account per command All signed in side by side, in one window
After sleep or a network change Retries the relay on a timer, for up to 15 minutes Redials on wake and when the network returns
Diagnosing errors Close code, a hint for 4003; ssh --troubleshoot Connection Doctor names the cause and a fix command
Who may use a local port Any process on the Mac Ostgate only by default for SSH, RDP and custom ports
Scripts and CI Yes, on any OS No; only an ssh ProxyCommand helper
Runs on macOS, Linux, Windows Apple Silicon Macs, macOS 26.3 or later
Price and source Free; Apache 2.0 7-day trial, then from $79 a year; closed source

Where the time goes

Each of these steps is small, but they repeat every day.

One process per port, one terminal each

start-iap-tunnel forwards one VM port per process, and the local port lives only as long as that process. An RDP session and a database on two VMs is two commands and two windows, or two background jobs you stop yourself:

gcloud compute start-iap-tunnel win-01 3389 \
    --local-host-port=localhost:13389 \
    --zone=europe-west1-b --project=acme-prod

gcloud compute start-iap-tunnel db-01 5432 \
    --local-host-port=localhost:15432 \
    --zone=europe-west1-b --project=acme-prod

Without --local-host-port, gcloud picks an unused port each run, so you choose and remember fixed ones yourself. In Ostgate, New Tunnel… (⌘T) forwards any port, with presets for SSH, RDP, PostgreSQL, MySQL, SQL Server, Redis and HTTP(S). A tunnel keeps its local port between runs, can start with its account, keeps running when you close the window, and appears in the menu bar. Copy Command gives you the client's command line. See Port forwarding to a GCP VM over IAP.

Python, and the NumPy warning

gcloud is a Python program: it runs on the interpreter bundled with the SDK when the install has one, otherwise on python3 from your PATH. If NumPy is missing from that interpreter, every start-iap-tunnel prints "To increase the performance of the tunnel, consider installing NumPy." Google's IAP documentation gives the command for its section on increasing TCP upload bandwidth:

$(gcloud info --format="value(basic.python_location)") -m pip install numpy

Ostgate is a native app with its own relay implementation; there is no Python on the path.

An ssh_config entry per host

gcloud compute config-ssh writes ~/.ssh/config entries only for instances with an external IP. For the rest you write the ProxyCommand yourself, and because it needs the zone and project, one block covers one host, or one zone of one project:

Host example-vm
    User alice_example_com
    IdentityFile ~/.ssh/google_compute_engine
    ProxyCommand gcloud compute start-iap-tunnel %h 22 --listen-on-stdin --zone=europe-west1-b --project=acme-prod

Ostgate's SSH Integration setting installs one managed Host *.gcp block, after which ssh INSTANCE.ZONE.PROJECT.gcp reaches any instance. See Use ssh from Terminal.

RDP: a tunnel, a password, a second app

For a Windows VM the gcloud route is three steps: open the tunnel to 3389, get a password with gcloud compute reset-windows-password win-01 --user=alice (it creates the account, or resets the password of an existing one), and point Windows App at localhost:13389. Ostgate draws the desktop in a tab with text clipboard sync, a Mac folder shared as a drive and a desktop that resizes with the window. Set Windows Password… creates or resets the account; the password can be saved per instance in the Keychain or read from Secret Manager for automatic logon. See RDP to a Windows VM from a Mac.

Files

gcloud compute scp --tunnel-through-iap and sftp through a tunnel work well from Terminal; there is no file browser. Ostgate's Browse Files opens an SFTP tab: upload and download with progress and Cancel, drag files in from and out to Finder, and folders packed with tar on the VM and streamed. See SFTP to a GCP VM from a Mac.

Private databases, load balancers and Cloud Run

Anything that only a VM in the VPC can reach goes through an SSH local forward, which gcloud compute ssh passes after --:

gcloud compute ssh bastion-01 --tunnel-through-iap \
    --zone=europe-west1-b --project=acme-prod \
    -- -N -L 15432:10.10.0.7:5432 -L 8443:10.10.0.5:443

Ostgate's forward profiles do the same over one SSH session and can add /etc/hosts aliases while they run; Open Tunnel… on a Cloud SQL instance reaches its private IP through one of your VMs; Open Proxy… on an internal Cloud Run service opens it in your browser. See internal load balancer, Cloud SQL private IP and internal Cloud Run.

Several accounts

gcloud keeps credentials for every account you log in with, but one is active per configuration. You switch with gcloud config configurations activate, per shell with CLOUDSDK_ACTIVE_CONFIG_NAME, or per command with --account. Ostgate keeps every signed-in account side by side, each with its own tokens, SSH key, tunnels and settings, and a window shows all of them or one. ssh through its block tries each signed-in account in turn until IAP lets one through.

Tunnels after sleep or a network change

When the relay connection drops, gcloud reconnects the same session: it retries with a pause that starts at 1.5 seconds and grows to 20, for up to 15 minutes. It does not watch for the Mac waking or the network returning, so the next attempt comes when its timer says. Ostgate redials at once on wake and when the network comes back, and a tunnel that cannot come back says so within a few minutes, with Reconnect. In both cases the program inside the tunnel decides whether its own session survived; after a long sleep the SSH server has often given up. See IAP tunnel slow or disconnecting.

Diagnosing 4003, 4033 and 4047

When a tunnel fails to open, start-iap-tunnel prints the relay's close code. It adds "Failed to connect to port" to a 4003 and "May be due to missing permissions" to a rejected handshake; 4033 and 4047 come without a hint, and you work out the missing role, firewall rule or wrong name from the code's meaning. For SSH, gcloud compute ssh --troubleshoot checks VM status, network connectivity, user permissions, VPC settings and VM boot, and IAP port forwarding with --tunnel-through-iap. Ostgate shows each connection stage as it happens; when one fails, Connection Doctor names the cause, such as a missing roles/iap.tunnelResourceAccessor, no firewall rule for the port, a stopped or still-booting instance or a network interface the VM lacks, and gives the gcloud command that fixes it, for whoever administers the project.

Security model

Both are clients of the same service. Each signs in as you with Google OAuth, calls Google's APIs and the IAP tunnel endpoint directly, and gets exactly the access your IAM roles and IAP firewall rules allow. Neither sends your connections through a third party: Ostgate has no server in the path of your traffic, and the one server of ours it contacts is the licence server (see Privacy). The differences are local:

  • gcloud stores credentials in ~/.config/gcloud/credentials.db. Ostgate stores each account's refresh token in the macOS Keychain.
  • gcloud compute ssh uses ~/.ssh/google_compute_engine. Ostgate's SSH tabs use a key generated on your Mac, in the Secure Enclave where available; a Secure Enclave key cannot be exported.
  • A start-iap-tunnel listener accepts a connection from any process on the Mac. Each Ostgate tunnel admits Ostgate only, My processes, or Any local process, the last only after you confirm it.

What Ostgate does not do

  • It costs money. After a 7-day trial with no sign-up, Personal is $79 a year or $9 a month, and Business is $129 per user per year. See Pricing.
  • Mac only. Apple Silicon Macs with macOS 26.3 or later. No Intel Macs, Linux or Windows.
  • Closed source. You cannot audit or patch it as you can the SDK.
  • No CLI for scripts or CI. The app's iap-proxy helper exists only as the ProxyCommand of its ~/.ssh/config block: it carries one connection on standard input and output, the job --listen-on-stdin does for gcloud. It uses the accounts signed in through the app on that Mac, needs a valid licence or trial there, opens no local port and cannot sign in by itself.
  • No device-certificate access levels. Ostgate cannot present a client certificate, so an IAP access level that requires one does not admit it.
  • No IAM-authenticated Cloud Run yet. Open Proxy… opens internal services whose invoker is allUsers or whose invoker IAM check is off; it mints no identity tokens.
  • No Private Service Connect. There is no setting for a PSC endpoint for Google APIs.

Using both

The two do not interfere. Ostgate never reads or runs gcloud and does not touch its configuration: you sign in to Ostgate separately, in your browser, and your gcloud accounts, configurations and scripts stay as they are. A common split:

  • Interactive work in Ostgate: RDP and SSH tabs, files, standing tunnels to databases.
  • ssh from Terminal through Ostgate: after SSH Integration › Install, ssh, scp and an IDE reach INSTANCE.ZONE.PROJECT.gcp with Ostgate's window closed. They sign in with your own keys from ~/.ssh, which the VM must already accept.
  • Scripts and CI on gcloud: anything that runs unattended, or on another OS.

Questions

Is gcloud enough to use IAP from a Mac?

Yes. gcloud compute ssh, scp and start-iap-tunnel cover SSH, file copies and any port, and Microsoft's Windows App connects to an RDP tunnel on localhost. A client saves time when you keep several tunnels, Windows desktops or Google accounts open every day.

Does Ostgate need gcloud, or change my gcloud setup?

No. Ostgate signs in with your Google account in your own browser and opens IAP tunnels itself. It never reads or runs gcloud, so your gcloud accounts, configurations and scripts are unchanged.

Can I use Ostgate in scripts or CI pipelines?

No. Its only command-line part is the ProxyCommand helper behind the ssh block it installs, and that uses accounts signed in through the app on the same Mac. For CI, keep gcloud.

Do gcloud and Ostgate need different permissions?

No. Both use IAP TCP forwarding as your Google account, so both need roles/iap.tunnelResourceAccessor and a firewall rule that allows ingress from 35.235.240.0/20 to the ports you use. Nothing is installed on the VMs.

Compared on 7 October 2026 with Google Cloud SDK 541.0.0 and Ostgate 0.0.2.