Skip to main content
Version: v3.9.0

Proxy

The SSH proxy manager maintains an optional reverse SSH tunnel configured by the Controller. It exposes remote access to the agent host through Controller-directed proxy settings pushed via the change feed.

Code: internal/proxy/

Purpose​

  • Open/close SSH tunnel based on Controller proxy config map
  • Monitor connection health
  • Update StatusReporter SSH proxy status (OPEN, CLOSED, FAILED)

Dependencies​

Depends onReason
statusreporterTunnel status for system status
configImplicit via proxy config payload
Used byReason
fieldagentproxy.GetInstance().Update(config) from changes processing

Lifecycle​

Not a Supervisor Module with Start() in the main sequence. lazy singleton updated when Controller sends proxy configuration.

Update(config map)​

  1. Validate non-empty config
  2. If connected and close flag set → close tunnel
  3. If not connected → establish tunnel from config
  4. Unexpected states logged with status OPEN/FAILED

Default ports in constants: local 22, remote 9999 (overridden by config).

Configuration​

Proxy settings arrive dynamically from Controller (not static config.yaml keys). Processed in fieldagent/changes.go when proxy-related changes appear.

External APIs​

No EdgeletAPI routes. Status visible on:

  • GET /v1/system/status → SSH proxy section
  • Controller diagnostics/status POST

Observability​

  • Log module: "SSH Proxy Manager"
  • SSHProxyManagerStatus on StatusReporter

Failure modes​

SymptomStatusCause
Tunnel already openOPENDuplicate open request
Invalid configFAILEDEmpty or malformed map
Connection dropMonitoring loopNetwork/firewall

Code map​

FileRole
manager.goUpdate orchestration, monitoring
connection.goSSH connection implementation

Related: Field agent, Status reporter.

Group 3See anything wrong with the document? Help us improve it!