Sign inSign up

zaysahq/beam-connector

By zaysahq

•Updated 1 day ago

Zaysa: just-in-time access to private databases, servers and clusters. No open ports.

Image
Networking
Security
Databases & storage
0

323

zaysahq/beam-connector repository overview

Zaysa

⁠Zaysa Beam Connector

Just-in-time access to private databases, servers and Kubernetes clusters, without opening a port. A small agent you run inside your own network, next to the resources it serves. It dials out to Zaysa⁠ over verified TLS and waits for signed work. Zaysa never connects in, so nothing needs a public port.

⁠Supported tags

TagDescription
1.0.0, latestFirst release on zaysahq. linux/amd64 and linux/arm64.

Zaysa's installers pin zaysahq/beam-connector:<version>@sha256:<digest>, never latest, so a box refuses any other image even if a tag is overwritten.

⁠What it does

ResourceHow access is granted
PostgreSQL · MySQL/MariaDB · MongoDB (incl. DocumentDB) · Redis/ValkeyA temporary, least-privilege login is created for each grant and removed when it ends. Managed services too: RDS/Aurora, Cloud SQL, AlloyDB, Azure Flexible Server, Atlas, ElastiCache/MemoryDB, Memorystore, DigitalOcean Managed DBs.
Linux servers (SSH)A short-lived user or a CA-signed certificate. Port 22 stays closed: sessions travel user → relay → connector → the host.
KubernetesA temporary ServiceAccount with a scoped role binding and a bound token. Same path on GKE, EKS, AKS and DOKS.

Every session runs user → Zaysa relay → connector → resource, over the connector's own outbound tunnel.

⁠Quick start

In Zaysa, open Beam → Connectors → Add connector. Zaysa generates the exact command, with this connector's ID, token and command-signing key already filled in. For Docker it looks like this:

docker run -d --restart unless-stopped --name beam-connector \
  -v /etc/beam/token:/run/secrets/beam_token:ro -e BEAM_TOKEN_FILE=/run/secrets/beam_token \
  -v beam-connector-state:/var/lib/beam \
  -e BEAM_URL=<from Zaysa> \
  -e BEAM_RELAY_URL=<from Zaysa> \
  -e BEAM_CONNECTOR_ID=<from Zaysa> \
  -e BEAM_COMMAND_PUBKEY=<from Zaysa> \
  zaysahq/beam-connector:1.0.0@sha256:<from Zaysa>

Zaysa also generates a systemd install script and a Kubernetes manifest. The connector turns green in Zaysa within seconds.

⁠Where to run it

Beside the resource, anywhere on the same private network. Never on the database itself.

Resource lives on…Run the connector on…
AWS (RDS, Aurora, DocumentDB, ElastiCache, MemoryDB, EC2)a small EC2 instance, ECS/Fargate task or EKS pod in the VPC
GCP (Cloud SQL, AlloyDB, Memorystore, GCE)a small GCE VM, Cloud Run service or GKE pod
Azure (Flexible Server, Cache for Redis, VMs)a small VM, Container Instance or AKS pod in the VNet
DigitalOcean (Managed Databases, Droplets)a Droplet in the same VPC (add it to trusted sources)
On-prem or self-managedthe same host, or any host on that network

Keep managed databases' public access off. The connector uses the private endpoint.

⁠Security

  • Outbound only. No inbound ports.
  • Device identity. On first start the connector creates its own key pair in /var/lib/beam and Zaysa pins the public key. Every request and tunnel is signed with it, so a copied token alone is useless.
  • Signed, single-use commands. Each command is signed by Zaysa, expires, and runs once. The connector refuses anything unsigned, expired, replayed or meant for another connector.
  • Sealed credentials. Admin passwords, SSH keys and cluster tokens are sealed to this connector's key. Only this connector can open them, not even Zaysa.
  • Your policy wins. BEAM_ALLOW_TARGETS limits where it may connect and BEAM_CAPABILITIES limits what it may do. Host commands and admin-level grants are off unless you turn them on.
  • Verified TLS to Zaysa and, where configured, to your databases.

⁠Environment variables

VariableRequiredDescription
BEAM_URLyesZaysa base URL.
BEAM_TOKEN_FILEyes*Path to a file holding the bmc_… token (preferred: keeps it out of docker inspect).
BEAM_TOKENyes*The token itself, if you can't mount a file. *One of the two.
BEAM_CONNECTOR_IDyesThis connector's ID. Commands for any other connector are refused.
BEAM_COMMAND_PUBKEYyesZaysa's command-signing public key (comma-separated only during a key rotation).
BEAM_RELAY_URL—Relay tunnel (wss://…/beam-tunnel) that carries live sessions.
BEAM_STATE_DIR—Device identity directory (default /var/lib/beam). Must be persistent: if it's lost, the owner resets the connector's identity in Zaysa. The connector refuses to start if it can't persist it.
BEAM_ALLOW_TARGETS—Where it may connect: private, loopback, CIDR, host[:port], *.suffix, * (default private,loopback).
BEAM_CAPABILITIES—Work it accepts: db, ssh, k8s, cloud-api (default), plus opt-in ssh-sudo, k8s-cluster-admin, k8s-custom-roles, host-exec.
BEAM_SSH_LOCAL_HOSTS—Hosts to treat as this machine (same-box mode, no SSH key needed). Needs --privileged --pid=host.
BEAM_POLL_INTERVAL_MS—Poll interval in ms (default 4000).

⁠Support

zaysa.io⁠

Tag summary

Content type

Image

Digest

sha256:229ea932b…

Size

65.2 MB

Last updated

1 day ago

docker pull zaysahq/beam-connector