Zaysa: just-in-time access to private databases, servers and clusters. No open ports.
323
Just-in-time access to private databases, servers and Kubernetes clusters, without opening a port. A small agent you run inside your own network, next to the resources it serves. It dials out to Zaysa over verified TLS and waits for signed work. Zaysa never connects in, so nothing needs a public port.
| Tag | Description |
|---|---|
1.0.0, latest | First release on zaysahq. linux/amd64 and linux/arm64. |
Zaysa's installers pin zaysahq/beam-connector:<version>@sha256:<digest>, never latest, so a box
refuses any other image even if a tag is overwritten.
| Resource | How access is granted |
|---|---|
| PostgreSQL · MySQL/MariaDB · MongoDB (incl. DocumentDB) · Redis/Valkey | A temporary, least-privilege login is created for each grant and removed when it ends. Managed services too: RDS/Aurora, Cloud SQL, AlloyDB, Azure Flexible Server, Atlas, ElastiCache/MemoryDB, Memorystore, DigitalOcean Managed DBs. |
| Linux servers (SSH) | A short-lived user or a CA-signed certificate. Port 22 stays closed: sessions travel user → relay → connector → the host. |
| Kubernetes | A temporary ServiceAccount with a scoped role binding and a bound token. Same path on GKE, EKS, AKS and DOKS. |
Every session runs user → Zaysa relay → connector → resource, over the connector's own outbound tunnel.
In Zaysa, open Beam → Connectors → Add connector. Zaysa generates the exact command, with this connector's ID, token and command-signing key already filled in. For Docker it looks like this:
docker run -d --restart unless-stopped --name beam-connector \
-v /etc/beam/token:/run/secrets/beam_token:ro -e BEAM_TOKEN_FILE=/run/secrets/beam_token \
-v beam-connector-state:/var/lib/beam \
-e BEAM_URL=<from Zaysa> \
-e BEAM_RELAY_URL=<from Zaysa> \
-e BEAM_CONNECTOR_ID=<from Zaysa> \
-e BEAM_COMMAND_PUBKEY=<from Zaysa> \
zaysahq/beam-connector:1.0.0@sha256:<from Zaysa>
Zaysa also generates a systemd install script and a Kubernetes manifest. The connector turns green in Zaysa within seconds.
Beside the resource, anywhere on the same private network. Never on the database itself.
| Resource lives on… | Run the connector on… |
|---|---|
| AWS (RDS, Aurora, DocumentDB, ElastiCache, MemoryDB, EC2) | a small EC2 instance, ECS/Fargate task or EKS pod in the VPC |
| GCP (Cloud SQL, AlloyDB, Memorystore, GCE) | a small GCE VM, Cloud Run service or GKE pod |
| Azure (Flexible Server, Cache for Redis, VMs) | a small VM, Container Instance or AKS pod in the VNet |
| DigitalOcean (Managed Databases, Droplets) | a Droplet in the same VPC (add it to trusted sources) |
| On-prem or self-managed | the same host, or any host on that network |
Keep managed databases' public access off. The connector uses the private endpoint.
/var/lib/beam and Zaysa
pins the public key. Every request and tunnel is signed with it, so a copied token alone is useless.BEAM_ALLOW_TARGETS limits where it may connect and BEAM_CAPABILITIES limits
what it may do. Host commands and admin-level grants are off unless you turn them on.| Variable | Required | Description |
|---|---|---|
BEAM_URL | yes | Zaysa base URL. |
BEAM_TOKEN_FILE | yes* | Path to a file holding the bmc_… token (preferred: keeps it out of docker inspect). |
BEAM_TOKEN | yes* | The token itself, if you can't mount a file. *One of the two. |
BEAM_CONNECTOR_ID | yes | This connector's ID. Commands for any other connector are refused. |
BEAM_COMMAND_PUBKEY | yes | Zaysa's command-signing public key (comma-separated only during a key rotation). |
BEAM_RELAY_URL | — | Relay tunnel (wss://…/beam-tunnel) that carries live sessions. |
BEAM_STATE_DIR | — | Device identity directory (default /var/lib/beam). Must be persistent: if it's lost, the owner resets the connector's identity in Zaysa. The connector refuses to start if it can't persist it. |
BEAM_ALLOW_TARGETS | — | Where it may connect: private, loopback, CIDR, host[:port], *.suffix, * (default private,loopback). |
BEAM_CAPABILITIES | — | Work it accepts: db, ssh, k8s, cloud-api (default), plus opt-in ssh-sudo, k8s-cluster-admin, k8s-custom-roles, host-exec. |
BEAM_SSH_LOCAL_HOSTS | — | Hosts to treat as this machine (same-box mode, no SSH key needed). Needs --privileged --pid=host. |
BEAM_POLL_INTERVAL_MS | — | Poll interval in ms (default 4000). |
Content type
Image
Digest
sha256:229ea932b…
Size
65.2 MB
Last updated
1 day ago
docker pull zaysahq/beam-connector