-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathconfig.example.yaml
More file actions
70 lines (63 loc) · 3.26 KB
/
Copy pathconfig.example.yaml
File metadata and controls
70 lines (63 loc) · 3.26 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
app:
log_level: info # Options: debug, info, warn, error
# AWS configuration
aws:
profile: "" # AWS profile to use (leave empty for default)
region: "" # AWS region (leave empty for default)
cli_path: aws # Path to AWS CLI executable
# Timeout configuration
timeouts:
tunnel_ready: 15s # Maximum wait time for tunnel to become ready
tunnel_ready_poll: 500ms # How often to check if tunnel is ready
idle_check: 30s # How often to check for idle tunnels
idle_timeout: 5m # Close tunnel after this much inactivity
shutdown: 10s # Maximum time to wait for graceful shutdown
shutdown_poll: 100ms # How often to check during shutdown
connection: 1s # TCP connection timeout for health checks
# Network configuration
network:
listen_address: localhost # Address to bind listeners to
tunnel_port_offset: 10000 # Offset added to local_port for SSM tunnel port
# Tunnel definitions
tunnels:
# Example: Production MySQL Database (using explicit instance ID)
- name: production-db
local_port: 3306 # Port to listen on locally
rds_endpoint: prod-db.cluster-xxxxx.us-east-1.rds.amazonaws.com
rds_port: 3306 # Port on the RDS instance
instance_id: i-xxxxx # Explicit EC2 bastion instance ID
description: "Production DB" # Human-readable description
aws_profile: production # Optional: Override AWS profile for this tunnel
aws_region: us-east-1 # Optional: Override AWS region for this tunnel
# Example: Staging MySQL Database (using instance pattern)
- name: staging-db
local_port: 3307
rds_endpoint: staging-db.cluster-xxxxx.us-east-1.rds.amazonaws.com
rds_port: 3306
instance_pattern: bastion-staging-* # Auto-discover instance by name pattern
description: "Staging DB"
aws_profile: staging
keepalive: 600 # Optional: keep the SSM session alive for at
# least 600s (10m) from the first connection,
# ignoring idle_timeout during that window.
# Omit or set 0 for default idle-only behaviour.
# Example: PostgreSQL Database (using wildcard pattern for auto-scaling group)
- name: postgres-db
local_port: 5432
rds_endpoint: postgres-db.cluster-xxxxx.eu-west-1.rds.amazonaws.com
rds_port: 5432
instance_pattern: app-server-* # Matches any instance with name starting with "app-server-"
description: "PostgreSQL DB"
aws_profile: customer-account
aws_region: eu-west-1
# Notes:
# - Replace xxxxx with your actual AWS resource IDs
# - Ensure the EC2 bastion instances have SSM agent installed
# - The AWS CLI must be configured with appropriate credentials
# - Local ports must be >= 1024 (unless running as root)
# - Each tunnel must have a unique local_port
# - Per-tunnel aws_profile and aws_region override global AWS settings
# - Optional per-tunnel keepalive (seconds) holds the SSM session open for at
# least that long from the first connection, on top of the global idle_timeout
# - Use either instance_id (explicit) or instance_pattern (auto-discovery), not both
# - Instance patterns use EC2 instance Name tag for matching (supports wildcards)