Relay administrator
Independent recovery only. It is not the everyday jump or tunnel identity.
PROJECT-OWNED SAMPLE · 9 SEPTEMBER 2026
A worked example for one Linux workstation behind CGNAT, one existing relay, and two owner-operated clients.
DECISION
The route is a reasonable fit if every reverse listener remains on relay loopback, the tunnel and jump roles use separate restricted identities, host keys are pinned, and an independent administrator path survives the test. Do not deploy if any of those gates cannot be met.
Reach a home Linux workstation from a laptop and phone for SSH and a private browser viewer. The home connection is behind CGNAT, so it cannot accept a normal inbound port forward.
One owner-controlled relay with public SSH, one workstation that can make outbound SSH connections, and two owner-controlled client devices. No hardware purchase or relay hosting is part of the review.
The route is end-to-end SSH through reviewed identities. A successful carrier alone does not authorize a user, and a browser viewer does not become public merely because the relay is public.
| Boundary | Intended bind | Who can reach it | Decision |
|---|---|---|---|
| Relay SSH | Reviewed public address | Approved SSH clients | Conditional |
| Reverse listener | 127.0.0.1 on relay | Relay-local jump path only | Required |
| Endpoint controller | 127.0.0.1 on workstation | Local app or declared forward | Required |
| Private browser viewer | 127.0.0.1 on workstation | Its dedicated reviewed forward | Required |
| Raw VNC / RDP | No public listener | No Internet source | Stop if exposed |
Illustrative labels only. The paid report records the buyer’s observed bind addresses and listener owners without copying secrets.
Independent recovery only. It is not the everyday jump or tunnel identity.
No shell, TTY, X11, agent forwarding, wildcard listener, or arbitrary target.
Separate client key and a pinned relay host key; access ends at declared loopback routes.
Separate host identity and permissions for each enrolled computer.
If the relay shows a reverse listener on 0.0.0.0 or ::, stop the candidate and correct the SSH policy before any client test.
Do not reuse the relay administrator key for the persistent carrier or for everyday client access.
Pin the relay and endpoint host identities. A changed fingerprint fails closed and requires an independent check.
A running service is not reboot evidence. Prove one controlled restart and one authorized reboot before calling persistence verified.
FREE FIT CHECK FIRST
Send the endpoint operating systems, whether a reachable relay already exists, the NAT or port constraint, and the intended access path. Do not attach passwords, private keys, access codes, or unredacted configuration.
Review the fixed scope