SSH Tunneling
SSH tunneling allows Lakehousecat to reach databases that are not directly accessible from the internet — for example, databases behind a corporate firewall or on a private subnet, accessed through a bastion host.
SSH is supported for all connection-URI-based database types. ClickHouse does not support SSH tunneling.
Enabling SSH
In the data source creation form, toggle Use SSH to reveal the SSH settings fields.
SSH Fields
| Field | Required | Description |
|---|---|---|
| SSH Host | Yes | Hostname or IP address of the SSH bastion host |
| Port | No | SSH port on the bastion host. Defaults to 22 if left empty. |
| SSH Username | Yes | Username on the bastion host (e.g., ubuntu, ec2-user) |
| SSH Password | No | Password for the SSH user. Leave empty if authenticating with a private key. |
| Private Key | No | Upload a .pem or .key file. Used instead of a password for key-based authentication. |
| Private Key Passphrase | No | Passphrase for the private key, if the key is encrypted. Leave empty for unencrypted keys. |
Authentication Options
Use either password-based or key-based authentication — not both simultaneously:
Password authentication:
- Fill in SSH Password
- Leave Private Key empty
Key-based authentication (recommended):
- Upload the Private Key file (
.pemor.key) - Fill in Private Key Passphrase if the key is protected
- Leave SSH Password empty
How it Works
When SSH is enabled, Lakehousecat establishes an encrypted tunnel to the bastion host first, then connects to the database through that tunnel. The Connection URI still points to the database host and port as seen from the bastion — not from the public internet.
Example setup:
- Bastion host:
bastion.company.com(port 22, userubuntu) - Database (from bastion):
db.internal:5432 - Connection URI:
postgresql://user:password@db.internal:5432/mydb
Notes
- The bastion host must be reachable from the Lakehousecat backend network.
- The database must be reachable from the bastion host.
- Use a dedicated SSH user with minimal permissions on the bastion host.
- Store private keys securely — they are saved as part of the data source configuration.