1.9 KiB
1.9 KiB
PatchBay
Port forwarding and routing between Linux machines over SSH, managed from a node-based web UI. One machine is the target (exit gateway, runs the web UI); every other machine is a client that connects to it.
Installing
./install.sh --role target # on the gateway
./install.sh --role client # on every other machine
The script installs dependencies via APT or XBPS, builds, installs to /usr/local (override with PREFIX=), creates /etc/patchbay/patchbay.conf from examples/ and installs systemd, runit or OpenRC services (--init to choose, --no-deps to skip packages).
Dependencies: a C99 compiler, make, pkg-config, libssh2 (1.11+ recommended for AES-GCM), SQLite 3; on the target also OpenSSH server, Python 3 with Flask and cryptography.
Usage
- Target: set the sysop account and mail server in
/etc/patchbay/patchbay.conf, startpatchbayd,patchbay-sshdandpatchbay-web, openhttps://<target>:8443. - Client: set
TargetHostin the config, runpatchbayd --pubkeyand add the key under Settings -> Clients, startpatchbayd. - On the Patch page, wire a Client Source into a Public Sink (exposed on the target) or a Client Sink (exposed on another client), directly or through a Splitter.
- Optional, per sink: "PROXY v2" passes the visitor's address to services that speak the PROXY protocol (Apache
RemoteIPProxyProtocol On, nginxproxy_protocol). "Transparent source spoofing" makes the connection to the service come from the visitor's address for any program; the source must be on a client and should use a loopback address (patchbayd adds the needed policy routing, seeTransparentTable).
Building and testing
make # build/patchbayd
make test # C unit tests + web tests
make test-c T=lines # single C test
make test-web T=tests.test_auth.AuthTest.test_login_2fa
make docker-test # end-to-end: target + 2 clients in Docker