gcloud start-iap-tunnel vs Ostgate: IAP on a Mac
If you already reach Compute Engine VMs from a Mac with gcloud, Terminal
and Microsoft's Windows App, you have a setup that works and costs nothing. Ostgate is a
paid native macOS app that opens the same Identity-Aware Proxy TCP tunnels itself, with SSH,
Remote Desktop, file transfer and port tunnels in one window. This page compares the two task
by task, says when gcloud is the better tool, and lists what Ostgate does not
do. If you are coming from Google's IAP Desktop on Windows instead, read IAP Desktop for Mac.
By Ostgate · Updated
When gcloud is enough
The Google Cloud CLI is free, its source is licensed under Apache 2.0, and it runs on macOS, Linux and Windows. Stay with it, and skip a client, if most of these describe you:
- You script or automate. CI jobs, deploy scripts and runbooks need a command line. Ostgate has none for that (see below).
- You open a tunnel now and then. One
gcloud compute ssha week costs a few seconds of typing. For a VM without an external IP,gcloud compute sshuses IAP on its own and prints "External IP address was not found; defaulting to using IAP tunneling". - You live in the terminal. SSH,
scpandsftpthrough anssh_configProxyCommandcover Linux VMs completely. - Your team uses Linux or Windows laptops too, and one documented route for everyone serves it better than a Mac-only app.
- Your access levels require a device certificate.
gcloudcan present one throughgcloud auth enterprise-; Ostgate cannot.certificate- config
A client starts to pay off when several of these are daily work: Windows VMs over RDP,
several ports or projects open at once, more than one Google account, a laptop that sleeps
and changes networks, and colleagues who should not need to learn gcloud.
Side by side, by task
Both columns use the same IAP TCP forwarding, the same firewall rule from
35.235.240.0/20 and the same IAM role,
roles/iap..
| Task | gcloud + Windows App | Ostgate |
|---|---|---|
| SSH | gcloud compute ssh; uses IAP when the VM has no external IP |
Double-click a Linux instance: a terminal tab |
| RDP | A start- to 3389, then Windows App to localhost |
Double-click a Windows instance: a Remote Desktop tab |
| Windows password | gcloud compute reset- prints it; paste it into Windows App |
Set Windows Password…; can be saved for automatic logon |
| File transfer | gcloud compute scp, or sftp through a tunnel |
Browse Files: an SFTP tab with Finder drag and drop |
| Port forwards | One start- process per port |
New Tunnel… with presets; local ports kept between runs |
| Private database, internal load balancer | gcloud compute ssh to a VM with -- -N -L forwards |
Forward profiles: several forwards over one SSH session |
| Internal Cloud Run | An SSH forward through a VM, plus an identity token for IAM | Open Proxy… for services that need no token; IAM not yet |
| Several Google accounts | One active per configuration; --account per command |
All signed in side by side, in one window |
| After sleep or a network change | Retries the relay on a timer, for up to 15 minutes | Redials on wake and when the network returns |
| Diagnosing errors | Close code, a hint for 4003; ssh --troubleshoot |
Connection Doctor names the cause and a fix command |
| Who may use a local port | Any process on the Mac | Ostgate only by default for SSH, RDP and custom ports |
| Scripts and CI | Yes, on any OS | No; only an ssh ProxyCommand helper |
| Runs on | macOS, Linux, Windows | Apple Silicon Macs, macOS 26.3 or later |
| Price and source | Free; Apache 2.0 | 7-day trial, then from $79 a year; closed source |
Where the time goes
Each of these steps is small, but they repeat every day.
One process per port, one terminal each
start-iap-tunnel forwards one VM port per process, and the local port lives only
as long as that process. An RDP session and a database on two VMs is two commands and two
windows, or two background jobs you stop yourself:
gcloud compute start-iap-tunnel win-01 3389 \
--local-host-port=localhost:13389 \
--zone=europe-west1-b --project=acme-prod
gcloud compute start-iap-tunnel db-01 5432 \
--local-host-port=localhost:15432 \
--zone=europe-west1-b --project=acme-prod
Without --local-host-port, gcloud picks an unused port each run, so you choose
and remember fixed ones yourself. In Ostgate, New Tunnel… (⌘T) forwards any port, with
presets for SSH, RDP, PostgreSQL, MySQL, SQL Server, Redis and HTTP(S). A tunnel keeps its
local port between runs, can start with its account, keeps running when you close the
window, and appears in the menu bar. Copy Command gives you the client's command
line. See Port forwarding to a GCP VM over
IAP.
Python, and the NumPy warning
gcloud is a Python program: it runs on the interpreter bundled with the SDK when
the install has one, otherwise on python3 from your PATH. If NumPy is
missing from that interpreter, every start-iap-tunnel prints "To increase the
performance of the tunnel, consider installing NumPy." Google's IAP documentation gives the
command for its section on increasing TCP upload bandwidth:
$(gcloud info --format="value(basic.python_location)") -m pip install numpy
Ostgate is a native app with its own relay implementation; there is no Python on the path.
An ssh_config entry per host
gcloud compute config-ssh writes ~/.ssh/config entries only for
instances with an external IP. For the rest you write the ProxyCommand yourself,
and because it needs the zone and project, one block covers one host, or one zone of one
project:
Host example-vm
User alice_example_com
IdentityFile ~/.ssh/google_compute_engine
ProxyCommand gcloud compute start-iap-tunnel %h 22 --listen-on-stdin --zone=europe-west1-b --project=acme-prod
Ostgate's SSH Integration setting installs one managed Host *.gcp block,
after which ssh INSTANCE.ZONE.PROJECT.gcp reaches any instance. See Use ssh from Terminal.
RDP: a tunnel, a password, a second app
For a Windows VM the gcloud route is three steps: open the tunnel to 3389, get a password
with gcloud compute reset- (it
creates the account, or resets the password of an existing one), and point Windows App at
localhost:13389. Ostgate draws the desktop in a tab with text clipboard sync, a
Mac folder shared as a drive and a desktop that resizes with the window. Set Windows
Password… creates or resets the account; the password can be saved per instance in the
Keychain or read from Secret Manager for automatic logon. See RDP to a Windows VM from a Mac.
Files
gcloud compute scp --tunnel-through-iap and sftp through a tunnel
work well from Terminal; there is no file browser. Ostgate's Browse Files opens an SFTP
tab: upload and download with progress and Cancel, drag files in from and out to
Finder, and folders packed with tar on the VM and streamed. See SFTP to a GCP VM from a Mac.
Private databases, load balancers and Cloud Run
Anything that only a VM in the VPC can reach goes through an SSH local forward, which
gcloud compute ssh passes after --:
gcloud compute ssh bastion-01 --tunnel-through-iap \
--zone=europe-west1-b --project=acme-prod \
-- -N -L 15432:10.10.0.7:5432 -L 8443:10.10.0.5:443
Ostgate's forward profiles do the same over one SSH session and can add
/etc/hosts aliases while they run; Open Tunnel… on a Cloud SQL instance
reaches its private IP through one of your VMs; Open Proxy… on an internal Cloud Run
service opens it in your browser. See internal load balancer, Cloud SQL private IP and internal Cloud Run.
Several accounts
gcloud keeps credentials for every account you log in with, but one is active per
configuration. You switch with gcloud config configurations activate, per shell
with CLOUDSDK_ACTIVE_CONFIG_NAME, or per command with --account.
Ostgate keeps every signed-in account side by side, each with its own tokens, SSH key,
tunnels and settings, and a window shows all of them or one. ssh through its
block tries each signed-in account in turn until IAP lets one through.
Tunnels after sleep or a network change
When the relay connection drops, gcloud reconnects the same session: it retries
with a pause that starts at 1.5 seconds and grows to 20, for up to 15 minutes. It does not
watch for the Mac waking or the network returning, so the next attempt comes when its timer
says. Ostgate redials at once on wake and when the network comes back, and a tunnel that
cannot come back says so within a few minutes, with Reconnect. In both cases the
program inside the tunnel decides whether its own session survived; after a long sleep the
SSH server has often given up. See IAP
tunnel slow or disconnecting.
Diagnosing 4003, 4033 and 4047
When a tunnel fails to open, start-iap-tunnel prints the relay's close code. It
adds "Failed to connect to port" to a 4003 and "May be due to missing permissions" to a
rejected handshake; 4033 and 4047 come without a hint, and you work out the missing role,
firewall rule or wrong name from the code's meaning.
For SSH, gcloud compute ssh --troubleshoot checks VM status, network
connectivity, user permissions, VPC settings and VM boot, and IAP port forwarding with
--tunnel-through-iap. Ostgate shows each connection stage as it happens; when one
fails, Connection Doctor names the cause, such as a missing
roles/iap., no firewall rule for the port, a stopped
or still-booting instance or a network interface the VM lacks, and gives the
gcloud command that fixes it, for whoever administers the project.
Security model
Both are clients of the same service. Each signs in as you with Google OAuth, calls Google's APIs and the IAP tunnel endpoint directly, and gets exactly the access your IAM roles and IAP firewall rules allow. Neither sends your connections through a third party: Ostgate has no server in the path of your traffic, and the one server of ours it contacts is the licence server (see Privacy). The differences are local:
gcloudstores credentials in~/.config/. Ostgate stores each account's refresh token in the macOS Keychain.gcloud/ credentials.db gcloud compute sshuses~/.ssh/. Ostgate's SSH tabs use a key generated on your Mac, in the Secure Enclave where available; a Secure Enclave key cannot be exported.google_compute_engine - A
start-iap-tunnellistener accepts a connection from any process on the Mac. Each Ostgate tunnel admits Ostgate only, My processes, or Any local process, the last only after you confirm it.
What Ostgate does not do
- It costs money. After a 7-day trial with no sign-up, Personal is $79 a year or $9 a month, and Business is $129 per user per year. See Pricing.
- Mac only. Apple Silicon Macs with macOS 26.3 or later. No Intel Macs, Linux or Windows.
- Closed source. You cannot audit or patch it as you can the SDK.
- No CLI for scripts or CI. The app's
iap-proxyhelper exists only as theProxyCommandof its~/.ssh/configblock: it carries one connection on standard input and output, the job--listen-on-stdindoes forgcloud. It uses the accounts signed in through the app on that Mac, needs a valid licence or trial there, opens no local port and cannot sign in by itself. - No device-certificate access levels. Ostgate cannot present a client certificate, so an IAP access level that requires one does not admit it.
- No IAM-authenticated Cloud Run yet. Open Proxy… opens internal services whose
invoker is
allUsersor whose invoker IAM check is off; it mints no identity tokens. - No Private Service Connect. There is no setting for a PSC endpoint for Google APIs.
Using both
The two do not interfere. Ostgate never reads or runs gcloud and does not touch
its configuration: you sign in to Ostgate separately, in your browser, and your
gcloud accounts, configurations and scripts stay as they are. A common split:
- Interactive work in Ostgate: RDP and SSH tabs, files, standing tunnels to databases.
sshfrom Terminal through Ostgate: after SSH Integration › Install,ssh,scpand an IDE reachINSTANCE.ZONE.PROJECT.gcpwith Ostgate's window closed. They sign in with your own keys from~/.ssh, which the VM must already accept.- Scripts and CI on
gcloud: anything that runs unattended, or on another OS.
Questions
Is gcloud enough to use IAP from a Mac?
Yes. gcloud compute ssh, scp and start-iap-tunnel cover SSH, file copies and any port, and Microsoft's Windows App connects to an RDP tunnel on localhost. A client saves time when you keep several tunnels, Windows desktops or Google accounts open every day.
Does Ostgate need gcloud, or change my gcloud setup?
No. Ostgate signs in with your Google account in your own browser and opens IAP tunnels itself. It never reads or runs gcloud, so your gcloud accounts, configurations and scripts are unchanged.
Can I use Ostgate in scripts or CI pipelines?
No. Its only command-line part is the ProxyCommand helper behind the ssh block it installs, and that uses accounts signed in through the app on the same Mac. For CI, keep gcloud.
Do gcloud and Ostgate need different permissions?
No. Both use IAP TCP forwarding as your Google account, so both need roles/iap.tunnelResourceAccessor and a firewall rule that allows ingress from 35.235.240.0/20 to the ports you use. Nothing is installed on the VMs.
Compared on 7 October 2026 with Google Cloud SDK 541.0.0 and Ostgate 0.0.2.