Name
nebius tunnel ssh-config
Install a managed block into ~/.ssh/config so that SSH to any tunnel route
hostname works with no per-tunnel setup:
Host *.tunnel.applications.*.nebius.cloud
Port 443
ProxyCommand “<path to this binary>” tunnel connect —stdio %h:%p
ServerAliveInterval 30
After one run, ssh, scp, sftp, and rsync -e ssh to
<service>-<weakid>.tunnel.applications.<region>.nebius.cloud just work: the
hostname itself carries everything the tunnel edge needs to route.
A re-run replaces the managed block in place and never duplicates it.
The block goes to the top of the file because ssh takes the first obtained
value for each option, so an earlier Host or Match block would shadow it.
Synopsis
Examples
Install the block once, then SSH through the tunnel
Options
--print (bool)
Only print the ssh_config block to stdout.
--remove (bool)
Remove the managed block.
Global Options
-h, --help (bool)
Show this message.
-p, --profile (string)
Set a profile for interacting with the cloud.
--format (string)
Output format. Supported values: yaml|json|jsonpath|table|text.
-f, --file (string)
Input file. For ‘update’ commands automatically set —full=true.
-c, --config (string)
Provide path to config file.
--debug (bool)
Enable debug logs.
-I, --impersonate-service-account-id (string)
Impersonate into the service account and use its token for a command.
--color (bool)
Enable colored output.
--no-browser (bool)
Do not open browser automatically on auth.
--insecure (bool)
Disable transport security.
--auth-timeout (duration: 2h30m10s)
Set the timeout for the request including authentication process, default is 15m0s.
--per-retry-timeout (duration: 2h30m10s)
Set the timeout for each retry attempt, default is 20s.
--retries (uint)
Set the number of retry attempts, 1 is disable retries, default is 3.
--timeout (duration: 2h30m10s)
Set the timeout for the main request, default is 1m0s.
--no-check-update (bool)
Suppress check for updates.
--no-progress (bool)
Suppress progress indicators and spinners.