Your SSH. Your keys. Untrusted transit.
Connect two private computers over SSH when neither accepts a public connection. Both connect outward to your Relay. Independent end-to-end encryption keeps even a compromised Relay from reading the stream or impersonating an endpoint.
| Role | Install on | Purpose |
|---|---|---|
| Client | Your laptop or workstation | The computer you connect from |
| Relay | A public Linux VPS | Carries encrypted traffic |
| Target | The private Linux SSH machine | Delivers authenticated traffic to local SSH |
OwnTransit 1.0.5 supports Linux amd64/arm64 and an Apple-silicon Mac Client. SSH must already work on the Target. OwnTransit never configures SSH accounts, keys, permissions or forwarding.
Adding a tunnel to an already running Relay? Visit Target → Relay → Client, once each. Create the Target first and keep its output available. On the Relay, choose New tunnel and paste the public Target ID when asked; creation and approval finish in that visit. Go directly to the Client and paste the private code from the Target. The Relay does not issue a second code. Use Continue a tunnel instead if you already created a Relay draft.
curl -fsSL https://github.com/sentrybottale/OwnTransit/releases/download/v1.0.5/install-linux.sh | sudo sh -s -- relayThe installer opens Relay setup when an interactive terminal is available. To open or return to its menu:
sudo owntransit-relay setupFor a new Relay, enter its public URL, such as wss://relay.example/connects
(example only). The VPS needs an existing HTTPS site. Choose New tunnel
and give it a name. The entry is UNDER CONSTRUCTION; follow its Target step.
At the public Target ID prompt, press Enter if the Target has not been created.
If it already exists, enter its public ID to approve it now and continue on the Client.
Install the Target, then open its menu:
curl -fsSL https://github.com/sentrybottale/OwnTransit/releases/download/v1.0.5/install-linux.sh | sudo sh -s -- target
sudo owntransit-target setupChoose New tunnel, an unused local name and the Relay URL.
The Target starts and enables its service for reboot. It prints a public
Target ID for the Relay and one private otpair2. code for the Client.
Keep this output available until the Client has accepted its code; retrieving
the code later is recovery, not a required setup step.
Transfer the private code directly to the intended Client through your existing authenticated SSH or console access. Never give it to the Relay.
Run sudo owntransit-relay setup, choose Continue a tunnel, select the
draft and enter the public Target ID. Approval is a saved step; the tunnel
remains UNDER CONSTRUCTION. Follow the displayed Client step.
If you started on the Target and have no draft, choose New tunnel, name it,
and enter the public Target ID in the same visit. Do not create another draft
for a Target that already has one.
Linux: install, then open setup as your ordinary user without sudo:
curl -fsSL https://github.com/sentrybottale/OwnTransit/releases/download/v1.0.5/install-linux.sh | sudo sh -s -- client
owntransit-client setupApple-silicon Mac: install and open setup without sudo:
curl -fsSL https://github.com/sentrybottale/OwnTransit/releases/download/v1.0.5/install-macos.sh | sh -s -- client
"$HOME/.local/bin/owntransit-client" setupChoose New tunnel, an unused local name, the Relay URL and the private code from the Target. Run one command at a time; answer prompts before running the next command. Secret input is hidden.
Only the Client's actual authenticated end-to-end check can report TUNNEL READY. Then run its printed SSH command with your own SSH user and independently verified host identity. The printed command includes the executable path and tunnel selection. OpenSSH still decides whether your login is allowed.
Run on the Client computer, not inside a shell on the Target. Replace
office with the Client's tunnel name and user@target.example with your SSH
account and already-verified host label.
Linux:
ssh -o 'ProxyCommand=owntransit-client proxy --tunnel office' user@target.exampleMac:
ssh -o "ProxyCommand=\"$HOME/.local/bin/owntransit-client\" proxy --tunnel office" user@target.exampleAdd -i /path/to/your/ssh-key if needed. The tunnel selects the Target; the SSH
label is for OpenSSH's independent host verification. SCP upload/download examples.
Upgrading from 0.7, 0.8 or an earlier 1.0.x release? Run the new installer for each local role. On the Relay, choose Start or update this relay; on each Target, Continue tunnel starts the installed version. On the Client, Continue tunnel verifies the existing pairing. Do not choose New or replace keys for a software update.
Relay admission hardening: install 1.0.5 on the Relay and choose Start or update this relay for its existing URL. This also reconciles its selected reverse-proxy route. Existing Client/Target pairings remain valid. Upgrade details.
Recovering an expired pending renewal: upgrade both Target and Client to 1.0.4 or later, then Continue their existing tunnel. The Relay needs no upgrade for this fix. Recovery and mixed-version details.
Open the local role's setup menu again.
| Choice | What it does |
|---|---|
| New tunnel | Creates a separate tunnel with an unused name |
| Continue tunnel | Resumes the saved step; on the Client, checks transport |
| List tunnels | Shows local state, not proof of end-to-end readiness |
| Remove tunnel | Removes the local endpoint connection or Relay admission |
| Killswitch | Client/Target only: permanently disables that pairing |
| Restore removed tunnel | Client/Target only: restores retained, unalarmed state |
Endpoint removal keeps private state and can be restored explicitly. A killswitch cannot be undone. Relay removal never triggers an endpoint killswitch. Uninstalling the whole program is a separate installer action; see the installation guide.
Lost the code? On the Target, choose Continue tunnel to retrieve the same unused, unexpired code. Interrupted Client setup uses Continue tunnel too. Keep existing identities during outages and software upgrades. Recovery details.
The Relay, its host, keys and reverse proxy are assumed compromised. Each
endpoint uses outer TLS 1.3 mTLS; an independent inner TLS 1.3 mTLS stream
authenticates the endpoints. The Target dials only build-fixed
tcp4 127.0.0.1:22, after authorization. OpenSSH adds its own encryption and
authentication. OwnTransit is an SSH byte carrier, not a VPN or general proxy.
Installers retain existing pairing state and migrate only recognized managed software/services. The documented Client/Relay/Target commands are the 1.x compatibility baseline. Published versions remain immutable. Do not replace pairings just to update software or mix historical enrollment instructions.
Initial installer delivery trusts GitHub HTTPS; archives are signature-verified. Independent security certification, pristine-host qualification and extended soak testing are not claimed. Keep independent SSH or console recovery access.
Network failures retry automatically with retained pairing and bounded backoff, including HTTP 429 throttling. A broken SSH session still needs a new SSH command; old bytes are never replayed. See operational limits.
Architecture · Security · Protocol compatibility · Roadmap · Contributing · Apache 2.0 license