F1REFlY product

Tunello

SSH tunnels, local ports, and diagnostics in a native macOS interface.

Tunello helps developers and operations teams manage tunnels, routes, snippets, workspace launches, and checks without manually assembling long SSH commands.

macOSSSH tunnelsport forwardingon demanddiagnostics

Developer: F1REFlY

tunello@macos:~/tunnels product screenshot
Tunello manager with sample tunnels, toolbar actions, statuses, and search

process

How Tunello opens access

A typical flow starts from a service or text description: Tunello builds a tunnel draft, shows the route, checks risk, and only then brings access up.

$ create tunnel -> review route -> approve safety -> connect -> use snippet

01

Create a tunnel manually, from a recipe, Docker source, or short text description.

02

Review server, identity, forwarding rules, topology preview, and snippets before connecting.

03

Connect immediately or leave an on-demand listener that wakes on the first TCP request.

04

Start a workspace, copy a connection snippet, or launch a client with the endpoint already prepared.

Tunello Getting Started with tunnel template, permissions, SSH identity, and setup verification
Quick create with verification

Getting Started prepares a tunnel draft and shows permissions, SSH identity, host-key trust, and verification before saving.

product surface

4 forwarding modes and 6 working surfaces

Tunello does not reduce SSH to one switch. It combines forwarding modes, gateway routes, workspaces, snippets, diagnostics, and safety policies so access stays understandable.

4

forwarding modes

6

working surfaces

strict

known_hosts policy

Forwarding

4

Local, remote, dynamic SOCKS, and gateway rules for services, databases, web UIs, and operational endpoints.

On demand

wake

A listener accepts the local TCP request, starts a hidden SSH backend port, and sleeps after the idle policy.

Gateway

routes

One local gateway host can route to several services through readable route rules.

Workspaces

start

Grouped tunnel launches with production confirmation, favorite ordering, and controlled stop policy.

Diagnostics

port

Port Doctor, health checks, logs, and topology help show exactly where access broke.

Security

trust

Strict known_hosts, explicit host-key approval, safe backups, and configuration without private keys.

Tunello manager list with sample forwarding routes, tags, and tunnel states
Routes visible before launch

The list shows bind host, local port, target host, tags, and tunnel state without reading raw SSH flags.

capabilities

Why Tunello works well day to day

Tunello removes repetitive SSH work while keeping the engineer in control: what opens, through which bastion, on which port, and with which risks.

Tunello manager overview with sidebar, tunnel list, and selected connection details
Tunnel manager

The manager keeps groups, tags, service routes, selected tunnel details, and connection state in one desktop window.

Quiet menu bar control

Connections, search, statuses, snippets, and quick actions live in the menu bar, while the full manager opens when context is needed.

Topology instead of SSH flags

Each forward is shown as a route from local endpoint to remote service, including proxy jumps, on-demand behavior, and gateway hops.

On-demand access

A tunnel does not need to keep an SSH process running all the time: the local listener wakes the backend only on real traffic.

Snippets and app launch

For Redis, Postgres, HTTP, SOCKS, and other routes, Tunello prepares URIs, env vars, CLI commands, and client launch actions.

Diagnostics next to the tunnel

Port Doctor, health checks, and redacted logs show the occupied port, process owner, suggested port, and route state.

Team-safe configuration

Backup and team workspace bundles move safe metadata without private keys, passphrases, or raw known_hosts bodies.

execution control

Safety is visible in the workflow

Tunello requires explicit host-key approval, uses strict known_hosts, shows production confirmations, and keeps secret material out of backups and team bundles.

Strict known_hostsProduction approvalPort DoctorSafe backupTeam bundle without secrets
Tunello overview with attention state, traffic, on-demand activity, and failure breakdown

F1REFlY

Need Tunello for your SSH workflows?

Email F1REFlY to see a demo, discuss team workflow, or check how Tunello fits your dev, staging, and production tunnels.

$ open mailto:hello@firefly.in.ua

--subject tunello-product-demo

Discuss Tunello Back home