Skip to main content
Version: 0.0.42

SSH Tunneling

SSH tunneling allows Lakehousecat to reach databases that are not directly accessible from the internet — for example, databases behind a corporate firewall or on a private subnet, accessed through a bastion host.

SSH is supported for all connection-URI-based database types. ClickHouse does not support SSH tunneling.

Enabling SSH​

In the data source creation form, toggle Use SSH to reveal the SSH settings fields.

SSH Fields​

FieldRequiredDescription
SSH HostYesHostname or IP address of the SSH bastion host
PortNoSSH port on the bastion host. Defaults to 22 if left empty.
SSH UsernameYesUsername on the bastion host (e.g., ubuntu, ec2-user)
SSH PasswordNoPassword for the SSH user. Leave empty if authenticating with a private key.
Private KeyNoUpload a .pem or .key file. Used instead of a password for key-based authentication.
Private Key PassphraseNoPassphrase for the private key, if the key is encrypted. Leave empty for unencrypted keys.

Authentication Options​

Use either password-based or key-based authentication — not both simultaneously:

Password authentication:

  • Fill in SSH Password
  • Leave Private Key empty

Key-based authentication (recommended):

  • Upload the Private Key file (.pem or .key)
  • Fill in Private Key Passphrase if the key is protected
  • Leave SSH Password empty

How it Works​

When SSH is enabled, Lakehousecat establishes an encrypted tunnel to the bastion host first, then connects to the database through that tunnel. The Connection URI still points to the database host and port as seen from the bastion — not from the public internet.

Example setup:

  • Bastion host: bastion.company.com (port 22, user ubuntu)
  • Database (from bastion): db.internal:5432
  • Connection URI: postgresql://user:password@db.internal:5432/mydb

Notes​

  • The bastion host must be reachable from the Lakehousecat backend network.
  • The database must be reachable from the bastion host.
  • Use a dedicated SSH user with minimal permissions on the bastion host.
  • Store private keys securely — they are saved as part of the data source configuration.