21 lines
1.5 KiB
Markdown
21 lines
1.5 KiB
Markdown
# rustunnel
|
|
|
|
`rustunnel` is a cross-platform Rust CLI tool for lab and development tunneling over HTTPS with mutual TLS (mTLS) and an application-level auth token. It exposes a local SOCKS5 proxy on the connector side and forwards traffic only after HTTPS, certificate, and auth checks succeed.
|
|
|
|
The tool is designed for local labs, development environments, and controlled testing where you own or are authorized to operate both endpoints. It is not a production-grade tunnel or a mechanism for accessing systems without permission.
|
|
|
|
## What it does
|
|
|
|
- **Listener** (`rustunnel listen`) — binds an HTTPS server that accepts mTLS connections from connectors, validates an auth token, then upgrades the connection to a persistent binary-framed tunnel.
|
|
- **Connector** (`rustunnel connect`) — connects to the listener over HTTPS with mTLS, authenticates, then exposes a local SOCKS5 proxy that forwards traffic through the tunnel.
|
|
- **Credential generation** (`rustunnel generate`) — creates a self-signed CA, server certificate, client certificate, and auth token for a local session.
|
|
- **Connection keys** (`rustunnel keygen`) — bundles all credential material into a single compressed base64url string that can be copy-pasted between machines.
|
|
|
|
## Quick links
|
|
|
|
- [Architecture](../overview/architecture.md)
|
|
- [Getting started](../overview/getting-started.md)
|
|
- [Tunnel engine](../systems/tunnel-engine.md)
|
|
- [TLS stack](../systems/tls-stack.md)
|
|
- [Security posture](../security.md)
|