> ## Documentation Index
> Fetch the complete documentation index at: https://docs.nebius.com/llms.txt
> Use this file to discover all available pages before exploring further.

# nebius tunnel connect

<div>
  <h2>Name</h2>

  <p style={{ paddingLeft: "4ch" }}>
    <code>nebius tunnel connect</code>
  </p>

  <p style={{ paddingLeft: "7ch" }}>
    Connect to a tunnel TCP service through the public edge.<br />

    <br />

    The argument is the tunnel route address \<service>-\<weakid>.\<domain>:\<port><br />
    and is passed to the dialer as-is. The host part is sent as the TLS server<br />
    name (SNI), which is how the edge routes the connection; --sni overrides it,<br />
    e.g. when connecting to an IP address directly. The server certificate is<br />
    verified against the system roots by default.<br />

    <br />

    The command performs no API calls and does not require a configured profile.<br />

    <br />

    With --stdio the process becomes a byte pipe suitable as an SSH ProxyCommand:<br />
    stdout carries tunnel bytes exclusively, and all diagnostics go to stderr.
  </p>
</div>

<div>
  <h2>Synopsis</h2>

  <p style={{ paddingLeft: "4ch" }}>
    ```
    nebius tunnel connect --stdio <address>
      --connect-timeout
      --insecure
      --sni
      --stdio
    ```
  </p>
</div>

<div>
  <h2>Examples</h2>

  <p style={{ paddingLeft: "4ch" }}>
    ```
    # SSH to a VM behind a tunnel (service "ssh" targeting 127.0.0.1:22)
    $ ssh -o ProxyCommand='nebius tunnel connect --stdio %h:%p' -p 443 ubuntu@ssh-hy3wnb3wstpk7dz.tunnel.applications.eu-north1.nebius.cloud

    # Same, dialing the edge by IP address; the route is selected by --sni
    $ ssh -o ProxyCommand='nebius tunnel connect --stdio --sni ssh-hy3wnb3wstpk7dz.tunnel.applications.eu-north1.nebius.cloud 203.0.113.10:443' ubuntu@vm
    ```
  </p>
</div>

<div>
  <h2>Options</h2>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--connect-timeout` (duration: 2h30m10s)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      TCP+TLS dial timeout per connection.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--insecure` (bool)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Skip TLS certificate verification; prints a warning to stderr.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--sni` (string)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      TLS server name (SNI) to send instead of the host part of the address; the edge routes on SNI, so set this when connecting by IP address.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--stdio` (bool)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Pipe stdin/stdout to the TLS connection (for use as an SSH ProxyCommand).
    </p>
  </div>
</div>

<div>
  <h2>Global Options</h2>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `-h, --help` (bool)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Show this message.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `-p, --profile` (string)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Set a profile for interacting with the cloud.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--format` (string)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Output format. Supported values: yaml|json|jsonpath|table|text.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `-f, --file` (string)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Input file. For 'update' commands automatically set --full=true.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `-c, --config` (string)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Provide path to config file.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--debug` (bool)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Enable debug logs.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `-I, --impersonate-service-account-id` (string)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Impersonate into the service account and use its token for a command.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--color` (bool)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Enable colored output.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--no-browser` (bool)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Do not open browser automatically on auth.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--auth-timeout` (duration: 2h30m10s)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Set the timeout for the request including authentication process, default is 15m0s.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--per-retry-timeout` (duration: 2h30m10s)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Set the timeout for each retry attempt, default is 20s.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--retries` (uint)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Set the number of retry attempts, 1 is disable retries, default is 3.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--timeout` (duration: 2h30m10s)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Set the timeout for the main request, default is 1m0s.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--no-check-update` (bool)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Suppress check for updates.
    </p>
  </div>

  <div style={{ paddingLeft: "4ch" }}>
    <p>
      `--no-progress` (bool)
    </p>

    <p style={{ paddingLeft: "4ch" }}>
      Suppress progress indicators and spinners.
    </p>
  </div>
</div>

*Auto generated on 26-Aug-2026*
