# PatchBay Port forwarding and routing between Linux machines over SSH, managed from a node-based web UI. One machine is the target (exit gateway, runs the web UI); every other machine is a client that connects to it. ## Installing ```sh ./install.sh --role target # on the gateway ./install.sh --role client # on every other machine ``` The script installs dependencies via APT or XBPS, builds, installs to `/usr/local` (override with `PREFIX=`), creates `/etc/patchbay/patchbay.conf` from `examples/` and installs systemd, runit or OpenRC services (`--init` to choose, `--no-deps` to skip packages). Dependencies: a C99 compiler, make, pkg-config, libssh2 (1.11+ recommended for AES-GCM), SQLite 3; on the target also OpenSSH server, Python 3 with Flask and cryptography. ## Usage 1. Target: set the sysop account and mail server in `/etc/patchbay/patchbay.conf`, start `patchbayd`, `patchbay-sshd` and `patchbay-web`, open `https://:8443`. 2. Client: set `TargetHost` in the config, run `patchbayd --pubkey` and add the key under Settings -> Clients, start `patchbayd`. 3. On the Patch page, wire a Client Source into a Public Sink (exposed on the target) or a Client Sink (exposed on another client), directly or through a Splitter. 4. Optional, per sink: "PROXY v2" passes the visitor's address to services that speak the PROXY protocol (Apache `RemoteIPProxyProtocol On`, nginx `proxy_protocol`). "Transparent source spoofing" makes the connection to the service come from the visitor's address for any program; the source must be on a client and should use a loopback address (patchbayd adds the needed policy routing, see `TransparentTable`). ## Building and testing ```sh make # build/patchbayd make test # C unit tests + web tests make test-c T=lines # single C test make test-web T=tests.test_auth.AuthTest.test_login_2fa make docker-test # end-to-end: target + 2 clients in Docker ```