Files
PatchBay/README.md
2026-10-04 19:21:50 +02:00

1.9 KiB

PatchBay

Port forwarding and routing between Linux machines over SSH, managed from a node-based web UI. One machine is the target (exit gateway, runs the web UI); every other machine is a client that connects to it.

Installing

./install.sh --role target      # on the gateway
./install.sh --role client      # on every other machine

The script installs dependencies via APT or XBPS, builds, installs to /usr/local (override with PREFIX=), creates /etc/patchbay/patchbay.conf from examples/ and installs systemd, runit or OpenRC services (--init to choose, --no-deps to skip packages).

Dependencies: a C99 compiler, make, pkg-config, libssh2 (1.11+ recommended for AES-GCM), SQLite 3; on the target also OpenSSH server, Python 3 with Flask and cryptography.

Usage

  1. Target: set the sysop account and mail server in /etc/patchbay/patchbay.conf, start patchbayd, patchbay-sshd and patchbay-web, open https://<target>:8443.
  2. Client: set TargetHost in the config, run patchbayd --pubkey and add the key under Settings -> Clients, start patchbayd.
  3. On the Patch page, wire a Client Source into a Public Sink (exposed on the target) or a Client Sink (exposed on another client), directly or through a Splitter.
  4. Optional, per sink: "PROXY v2" passes the visitor's address to services that speak the PROXY protocol (Apache RemoteIPProxyProtocol On, nginx proxy_protocol). "Transparent source spoofing" makes the connection to the service come from the visitor's address for any program; the source must be on a client and should use a loopback address (patchbayd adds the needed policy routing, see TransparentTable).

Building and testing

make                  # build/patchbayd
make test             # C unit tests + web tests
make test-c T=lines   # single C test
make test-web T=tests.test_auth.AuthTest.test_login_2fa
make docker-test      # end-to-end: target + 2 clients in Docker