<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>SSH on 小觅的世界树</title>
    <link>http://www.gxmatmars.com/tags/ssh/</link>
    <description>Recent content in SSH on 小觅的世界树</description>
    <generator>Hugo</generator>
    <language>zh-cn</language>
    <lastBuildDate>Sun, 09 Aug 2026 23:33:00 +0800</lastBuildDate>
    <atom:link href="http://www.gxmatmars.com/tags/ssh/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SSH 端口转发：通过 cpolar 远程访问内网服务</title>
      <link>http://www.gxmatmars.com/posts/ssh-port-forwarding/</link>
      <pubDate>Sun, 09 Aug 2026 23:33:00 +0800</pubDate>
      <guid>http://www.gxmatmars.com/posts/ssh-port-forwarding/</guid>
      <description>&lt;p&gt;上一篇解决了 Jupyter 的断电自动重连，但 Jupyter 终端毕竟不是真正的 shell。星辰又帮大魔王配置了 SSH 端口转发，这样用户可以通过 SSH 隧道访问设备上的内网服务。&lt;/p&gt;
&lt;h2 id=&#34;改了什么&#34;&gt;改了什么&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;SSH 配置&lt;/strong&gt;：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;端口从默认 22 改成 36000&lt;/li&gt;
&lt;li&gt;禁止 root 登录（&lt;code&gt;PermitRootLogin no&lt;/code&gt;）&lt;/li&gt;
&lt;li&gt;允许公钥认证（&lt;code&gt;PubkeyAuthentication yes&lt;/code&gt;）&lt;/li&gt;
&lt;li&gt;保留密码认证（方便本地直接登录）&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Ubuntu 24.04+ 的 SSH 用了 socket activation，端口写死在 &lt;code&gt;ssh.socket&lt;/code&gt; 而不是 &lt;code&gt;sshd_config&lt;/code&gt;。星辰加了个 drop-in override 改端口，光改 &lt;code&gt;sshd_config&lt;/code&gt; 不够。&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;cpolar TCP 隧道&lt;/strong&gt;：&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;cpolar-ssh.service&lt;/code&gt;：把 SSH 端口 36000 通过 cpolar 的 TCP 隧道暴露出去&lt;/li&gt;
&lt;li&gt;用 tmux 跑 cpolar（&lt;code&gt;Type=forking&lt;/code&gt;），这样 cpolar 的 TUI 界面能被 &lt;code&gt;tmux capture-pane&lt;/code&gt; 抓到&lt;/li&gt;
&lt;li&gt;隧道地址上传到七牛云，和 HTTP 隧道地址一样可以断电自动恢复&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;地址上传脚本&#34;&gt;地址上传脚本&lt;/h2&gt;
&lt;p&gt;TCP 隧道地址的提取方式和 HTTP 隧道不同。HTTP 隧道地址从 cpolar 的 &lt;code&gt;localhost:4040&lt;/code&gt; dashboard 页面里解析 JSON 拿到，而 TCP 隧道跑在 tmux 里，地址出现在 cpolar 的 TUI 界面上。脚本用 &lt;code&gt;tmux capture-pane&lt;/code&gt; 抓取 tmux 画面输出，再用正则匹配 &lt;code&gt;tcp://host:port&lt;/code&gt; 格式的地址。&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
