Client side control of SSH. #204

Closed
opened 2025-11-20 05:08:00 -05:00 by saavagebueno · 6 comments
Owner

Originally created by @dragon2611 on GitHub (Oct 17, 2022).

Can we please make SSH support something that can be disabled from the client side?

I quite like the way tailscale handles it where if you want to use their SSH implementation you have to connect the client with an argument passed so it tells the control plane SSH is available before you can switch on tailscale SSH.

Originally created by @dragon2611 on GitHub (Oct 17, 2022). Can we please make SSH support something that can be disabled from the client side? I quite like the way tailscale handles it where if you want to use their SSH implementation you have to connect the client with an argument passed so it tells the control plane SSH is available before you can switch on tailscale SSH.
saavagebueno added the enhancementagent labels 2025-11-20 05:08:00 -05:00
Author
Owner

@Zorlin commented on GitHub (Jan 6, 2023):

This is hugely important, otherwise all my Netbird boxes basically have root on each other :/

@Zorlin commented on GitHub (Jan 6, 2023): This is hugely important, otherwise all my Netbird boxes basically have root on each other :/
Author
Owner

@tconnard commented on GitHub (Feb 4, 2023):

This is a big issue for me.
I don't want the cloud hosted (either managed or on a vm) management for the overlay network to be able to bypass access control for ssh.
I already have my own ssh management in place

@tconnard commented on GitHub (Feb 4, 2023): This is a big issue for me. I don't want the cloud hosted (either managed or on a vm) management for the overlay network to be able to bypass access control for ssh. I already have my own ssh management in place
Author
Owner

@grzybniak commented on GitHub (Jun 7, 2023):

hello, any news here?

@grzybniak commented on GitHub (Jun 7, 2023): hello, any news here?
Author
Owner

@tjarbo commented on GitHub (Nov 12, 2023):

Hi,
any progress on this topic? Maybe @braginini (as you posted on #852)?
As highlighted in https://github.com/netbirdio/netbird/issues/683#issuecomment-1806477634, this SSH feature (among others) is really a no-go as the netbird server/network operator is currently too powerful. ACLs etc. are not a mitigation for this threat.

@tjarbo commented on GitHub (Nov 12, 2023): Hi, any progress on this topic? Maybe @braginini (as you posted on #852)? As highlighted in https://github.com/netbirdio/netbird/issues/683#issuecomment-1806477634, this SSH feature (among others) is really a no-go as the netbird server/network operator is currently too powerful. ACLs etc. are not a mitigation for this threat.
Author
Owner

@jonathanspw commented on GitHub (Nov 22, 2023):

+1

@jonathanspw commented on GitHub (Nov 22, 2023): +1
Author
Owner

@codyro commented on GitHub (Nov 22, 2023):

+1

@codyro commented on GitHub (Nov 22, 2023): +1
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SVI/netbird#204