Operators reach database servers and application hosts over SSH from workstations the platform cannot see. This release moves that work inside the platform: an SSH Client tool opens a terminal in the browser, signs in with credentials held in the platform keystore, and records what was typed. The terminal is a governed surface, not a convenience.
Connecting
- Jump hosts An ordered list of hops, each connected through the previous and the target through the last. Every hop authenticates with the same rules as the target: a password, or a keystore entry the user owns or has been granted.
- Keystore credentials A key pair or a password secret from the keystore signs the user in. A stored password secret is used as the SSH password without the user ever seeing it.
- Trust on first use An unknown host key is pinned to a dedicated known-hosts file, never the service account's own. A changed key for the same host is refused.
- Shared hosts, private credentials Sharing a host does not share its keystore entry. Before a connection opens, the server checks the user's access to the target, to every jump host and to any database server's entry, and answers
403with the reason.
Audit
- Every command logged Each command line typed in a relayed terminal is reassembled, sanitised and written through the audit-log queue with the user, the client address, the target, the session and a sequence number.
- Secrets masked The sanitiser replaces the value in password-like environment assignments, in
--passwordand--tokenstyle flags, in credentials embedded in a URL and in bearer headers. A password typed at ansu,sudoor passphrase prompt is replaced with a fixed placeholder before it reaches the log. - SFTP audited Connection, listing, folder creation, upload and download each write a row with the outcome. A download records the bytes transferred and whether it completed. Paths and sizes only, never content.
Limits
- Twelve terminals per user, counted across the SSH Client, the database workbench and the SSH widget. The thirteenth is refused before any connection opens.
- SFTP per grant SFTP is off on every existing grant and switched on per grantee. The owner always has it, a sharer can only grant what they hold, and revoking it closes the open connection. Three SFTP connections per user, uploads to 100 MB, downloads streamed through a single-use ticket.
- Inactivity timeout per host, ten minutes by default, edited as a clock on the host.
Hosts and open sessions appear as folders in the tool's menu, snippets attach to a host and are visible read-only to everyone who may reach it, and the tool is translated into Catalan, German, Spanish and Italian. It appears only for users holding its access role.