Outbound Reverse Tunneling
Integration & Setup Manual
Outbound Reverse Tunneling Integration Guide
Overview
Cup’n’String uses outbound-only reverse tunneling to securely connect developer workstations to the control plane. Because all sessions are established via outbound TLS 1.3 connections, enterprise firewalls do not need to allow inbound ports.
Support level
Outbound-Only Transport
What Cup’n’String detects
- Workstation internet connectivity state
- Latency and round-trip tunnel times
- Active multiplexed gRPC streams
What it governs
- Workstation service exposure to remote tenants
- Access authentication using rotating integration tokens
- Traffic encryption and certificate validation
Recommended policies
- Restrict reverse tunnel establishment to trusted tenant gateways
- Apply daily bandwidth limits to active relay sessions
- Require OIDC/PKCE session authorization before starting tunnels
Setup outline
- Bind the workstation agent using the tenant enrollment profile.
- The agent initiates a secure WebSocket/gRPC connection to the
edge-gateway. - Port mappings are established over the established outbound channel.
Verification
Confirm the agent status shows “Connected” in the tray menu and that the workstation is listed as “Online” in the admin portal.
Troubleshooting
Ensure the workstation can resolve the edge-gateway hostname and outbound HTTPS traffic (port 443) is allowed by local proxies.
Known limitations
Requires a stable internet connection; will dynamically buffer metrics offline but live tunnels will drop.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix