Cordium documentation · Latest
SSH and IDEs
Cordium provides standard, secretless SSH access to running Workspaces. This enables everything that assumes real SSH: interactive shells, remote commands, local port forwarding, SOCKS5 proxying, SFTP/SCP file transfers, rsync, and remote development with VS Code, Zed, JetBrains IDEs, Cursor and any other SSH-based tool.
How It Works
Workspaces do not use SSH keys or passwords at all. Every Workspace runs an embedded SSH server as part of its octelium connect process, and that server is only reachable through a dedicated Octelium SSH Service named <REGION>-ssh.cordium (i.e. default-ssh.cordium for the default Region) that is implemented by a Cordium-specific identity-aware proxy. When you connect, the proxy identifies you via your Octelium Session and only lets you in if:
You own the target Workspace, which is identified by the SSH username (i.e. the Workspace name).
The Workspace is in the
PREPARINGorRUNNINGstate, in the same Region as the proxy.The Workspace's Space does not disable SSH access via its
authorization.disableSSHfield (read more here).
Since the SSH Service is a private Octelium Service, you need to be connected to the Cluster via octelium connect before using SSH (read more about connecting to the Cluster here):
Workspaces are already connected to the Cluster. This means that you can use cordium ssh and cordium cp from inside one of your Workspaces to reach your other Workspaces without any additional setup (read more here).
Every SSH connection counts as activity, which keeps the Workspace from being stopped by its inactivity timeout, and every SSH session is visible in the Cluster's OpenTelemetry access logs.
cordium ssh
cordium ssh opens an interactive shell or runs a remote command via an SSH client that is embedded in the cordium CLI. A remote command and its arguments can be passed after a double-dash (--). Here are some examples:
| Flag | Description |
--local, -L | A local port forward in the [BIND_ADDR:]PORT:HOST:HOSTPORT format. Repeatable. |
--dynamic, -D | A dynamic SOCKS5 forward in the [BIND_ADDR:]PORT format. Repeatable. |
--no-command, -N | Do not execute a remote command, which is useful for port forwarding only. |
--print-config | Print an OpenSSH config block for the Workspace and exit. |
OpenSSH Config
To use any standard SSH-based tool, generate an OpenSSH config block for the Workspace and append it to your ~/.ssh/config:
The generated block defines the cordium-<WORKSPACE> host alias and looks roughly as follows:
You can now use the standard OpenSSH tooling:
The HostName is the private hostname of the SSH Service, which only resolves while you are connected to the Cluster. If you connect via the rootless mode and publish the SSH Service to a local port instead (e.g. octelium connect -p default-ssh.cordium:2222), re-generate the block after connecting so that it points to localhost:2222.
Copying Files
cordium cp copies files and directories between your local filesystem and a Workspace, or between two Workspaces, using SFTP. Workspace paths are specified as <WORKSPACE>:<PATH> and local paths as plain filesystem paths. Use -r to copy directories recursively:
Once your OpenSSH config is set up, you can also use scp, sftp and rsync:
Remote Development with IDEs
Any IDE that supports remote development over SSH can work directly inside a Workspace once its OpenSSH config block is added to your ~/.ssh/config:
VS Code, Cursor and other VS Code-based editors with the Remote - SSH extension:
For VS Code, cordium code does the same in one step without any SSH config, provided that the code command is installed and that you are connected via octelium connect. It opens /workspace/repo by default, which you can change via the --dir flag:
Zed:
JetBrains IDEs (e.g. GoLand, IntelliJ IDEA, PyCharm) via JetBrains Gateway or the IDE's remote development: choose SSH, select the cordium-abc host from your SSH config and open /workspace/repo.
Persistent Workspaces are a great fit for IDEs since the IDE server components installed inside the Workspace (e.g. ~/.vscode-server) survive restarts. You can also pre-install them in a Template image or via dotfiles to speed up the first connection.
Disabling SSH
Space owners can deny SSH access, and therefore cordium ssh, cordium cp and IDE access, to all the Workspaces of a Space via the Space's authorization.disableSSH field (read more here). Terminals and cordium exec still work via the Cordium API. Additionally, since the SSH endpoint is an Octelium Service, access to it can be further restricted by Octelium Policies (read more here).