tomazbracic
Hi,
Has anybody done and documented/blogged about the “reverse SSH proxy” or “SSH jump host” setup with a Nerves device?
I would like to set this up with a device on a 4G network. The device will be collecting some specific data but not pushing it forward in the whole capacity. If there will be a trigger I would like to send down a MQTT message to bring up a SSH tunnel and specific limits/configs for required data. But I would like to start the tunnel from a remote device side.
I was looking into NervesSSH, but couldn’t find anything there mentioning this.
Any suggestion would be appreciated.
Thanks in advance.
Tomaz
Trending in Questions
I having some trouble figuring out if I have set myself too strict of standards for my production server. Currently I can handle 75% of r...
New
Hello,
I’m trying to build a basic Phoenix web-app, and I’d like to use Tailwind.
However, when I launch mix phx.server, I get an error...
New
I really like the adapter patterns that ecto, nebulex, waffle, etc. use and would love find something similar for a key management servic...
New
Hello folks!
So at work, we are seeing some situations where we have to define some “fixed” strings that are used across the codebase in...
New
I’m working on a small exercise involving update_in/3, and I came up with this solution:
data = %{
name: "Periodic Table",
category:...
New
I’ve got trouble wrapping my head around the order in which functions are called in this snippet (from Phoenix’s authentication):
toke...
New
Is there any way to avoid the Hologram compiler running when using iex? It seems like the front-end code could potentially be disregarded...
New
Other Trending Topics
Edit: 2026 May 15 - This post is archived.
Mob is alive!!
Main docs: mob v0.7.11 — Documentation
A bit of explanation for the slightly c...
New
Hobbes is a low-level distributed database for the Elixir programming language.
Hobbes provides a simple, safe, and scalable storage lay...
New
A little off-topic, but I feel like people here have a good head on their shoulders.
I used to be quite good at making software. Was luc...
New
Hey. Is there anyone here who creates agents in their apps? Not talking about using agents, but creating them. I’m finding it pretty diff...
New
I fully migrated to my own harness from Anthropic/Gemini and I think it’s time to share it. Welcome DSH, the DeepSeek Harness, fully writ...
New
ExRatatui lets you cook up rich terminal UIs in Elixir, powered by Rust’s ratatui via Rustler NIFs. Build interactive terminal applicatio...
New
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #library
- #deployment
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #elixirconf
- #channels
- #exunit
- #discussion
- #code-sync
- #podcasts
- #javascript
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #ai
- #podcasts-by-brainlid
- #ecto-query
- #blog-post
- #elixirconf-us
- #elixir-ls
- #phoenix_html
- #iex
- #graphql
- #genstage
- #websockets
- #supervisor
- #advent-of-code
- #distillery
- #processes
- #elixirconf-eu
- #api
- #forms
- #security
- #metaprogramming










Showing Posts 1 to 4- Show Best Posts
- Show All (oldest first)
- Show All (newest first)
tomazbracic
I mean, in addition to this, main purpose is to be able to manage files on /root (/data) partition. There will be a lot of files and for sure you can do a lot of this programatically, but due to the fact devices will be > 1000km away I would like to keep my options open.
lawik
To get a more clear idea I am not sure why you’d want to start an SSH tunnel rather than shove data over MQTT. Or maybe transfer it via HTTPS to something like object storage? These seem more straightforward.
But assuming you need a secure tunnel to access some private networked service to hand data to that. I guess you could install the SSH packages from buildroot and then use MuonTrap to run an SSH-command as a supervised daemon.
nerves_sshis tooling into the SSH subsystem of Erlang to allow connecting to the device I don’t believe it has any stuff for making outbound SSH connections.If you want something that is at least somewhat built out in Nerves I will say that Wireguard is not super hard to get rolling. You can install VintageNetWireguard and use that on the Nerves device, use the normal wireguard tooling with wg-quick on another end to set up a recipient port and all that. I think the design of wireguard actually makes it feasible to leave the tunnel “active” continuously. By default it shouldn’t be doing any keepalive so you can keep the wireguard interface/network up and just close whatever connection you used and it will be quiet (and actually disconnected) until you try to send packets again.
I think wireguard is a quicker win than SSH for this.
tomazbracic
Yea, my post might not be best written. To elaborate a bit more. I will be getting data into my Nerves device with 2 separate streams. One getting data at 1Hz and one at 50Hz rate. Not really important, but this will be energy related data.
1Hz data will be, after some checks and processing pushed over MQTT to the cloud side.
50Hz data will be stored locally. There is a whole logging/rotation/retention/processing code for that. This data will have a retention and will be used on per request from cloud side. We’re talking about Gb’s of data, but with some slick approach it should be ok.
I will be using something like ExAws.S3 to upload this data to my Min.io (object storage) as you @lawik already suggested. I would just like to have “shell” access to a device to be able to manually intervene if needed in regards to this “file management”
Wireguard is really a good idea. Will check this as well. But just for the sake of debate, if you would have like 10k devices … what would that mean in regards to cloud side Wireguard administration? Never did Wireguards before. I expect I could wire up Wireguards with my mTLS as well?
lawik
Oh, you just want terminal access to the device? Use NervesHub. Easiest way. You get a terminal on the web and full IEx. We know it works with way more than 10k devices.
If you must have direct networking to the device to poke it, then Wireguard is probably the good choice. It uses UDP and it’s own protocol but it is PKI-based so both parties actually hold a full public/private key pair and that’s how they shake hands. You could just pack these keys in during device provisioning if you want the easiest way. Or you could add some exchange mechanism to your cloud application to set them up as needed.
I want to explore adding wireguard to NervesHub but there is no timeline for it currently.
Absolutely easiest for manual intervention is by far just using a NervesHub service and enabling the remote iex shell.