You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fix --visable flag to support no-argument usage and correct README concepts
- Set NoOptDefVal on --visable flag so it works without a value (defaults to "visable")
- Fix README: invisible mode is the default, visible mode requires --visable
- Fix README: visibility is about authorization (Site URL access), not console display
- Remove API Tunnel line from example output
- Fix stray dot syntax error in root.go
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
-**Browser-Based Access** — RDP, VNC, SSH all rendered in the browser via HTML5, no plugins or client software needed
40
40
-**Zero Config** — Just specify protocol and target, everything else is automatic
41
-
-**Visible & Invisible Modes** — Choose whether the tunnel is listed in the management console or hidden
41
+
-**Visible & Invisible Modes** — Control whether unauthorized users can access the service via the Site URL alone
42
42
-**Cross-Platform** — Linux, macOS, Windows native support
43
43
-**Encrypted Tunnels** — Built on [chisel](https://github.com/jpillora/chisel) with WebSocket transport
44
44
-**Auto Credentials** — Machine fingerprint-based identity, encrypted local storage
@@ -65,43 +65,53 @@ Once the tunnel is established, open the **Access URL** in any browser — that'
65
65
66
66
## Visibility Modes
67
67
68
-
Shield CLI supports two visibility modes controlled by the `--visible` flag:
68
+
Shield CLI supports two access modes controlled by the `--visable` flag.
69
69
70
-
### Visible Mode (default)
70
+
When a tunnel is established, two URLs are generated:
71
71
72
-
The tunnel and its associated application are listed in the management console. Ideal for shared services that team members need to discover and access.
72
+
-**Site URL** — The application address (e.g., `https://xxxx.hk01.apps.yishield.com`). This URL alone is **not accessible** without authorization.
73
+
-**Access URL** — Contains an embedded authorization key. Anyone with this URL can access the service directly.
74
+
75
+
### Visible Mode
76
+
77
+
The service is **open to unauthorized users** — anyone who knows the Site URL can access it without an authorization key. Suitable for services that are intended to be publicly reachable.
73
78
74
79
```bash
75
-
# Visible: appears in the console, team members can find and access it
76
-
shield -t rdp -s 10.0.0.5:3389
80
+
# Visible: the Site URL is accessible without authorization
81
+
shield --visable -t rdp -s 10.0.0.5:3389
82
+
83
+
# Filter a specific AC node by name
84
+
shield --visable=HK -t ssh -s 10.0.0.2:22
77
85
```
78
86
79
87
**Use cases:**
80
-
- Shared development servers that the whole team needs
88
+
89
+
- Public demo environments
90
+
- Shared development servers for the whole team
81
91
- Staging environments for QA testing
82
-
- Internal tools and dashboards
83
92
84
-
### Invisible Mode
93
+
### Invisible Mode (default)
85
94
86
-
The tunnel works identically but is **hidden from the management console**. Only users with the direct Access URL can connect. Ideal for temporary, sensitive, or personal access.
95
+
The service **requires authorization** — the Site URL alone will not grant access. Users must use the Access URL (which contains the authorization key) to connect. This is the secure default for all services.
87
96
88
97
```bash
89
-
# Invisible: works the same, but hidden from the console
90
-
shield --visible=false -t rdp -s 10.0.0.5:3389
98
+
# Invisible (default): only the Access URL (with key) grants access
99
+
shield -t rdp -s 10.0.0.5:3389
91
100
92
-
#Invisible SSH tunnel for a quick debugging session
93
-
shield --visible=false -t ssh -s 10.0.0.2:22
101
+
#Secure SSH tunnel — share the Access URL with specific people
- Temporary access during incident response — share the URL, close when done
101
-
- Personal development machines that don't need to be discoverable
102
-
- Sensitive servers where access should be strictly URL-based
103
109
104
-
> In both modes, the Access URL is printed to the terminal. The only difference is whether the tunnel appears in the management console.
110
+
- Production servers that must not be publicly accessible
111
+
- Temporary access during incident response — share the Access URL, revoke when done
112
+
- Sensitive machines where access is restricted to authorized users only
113
+
114
+
> Both modes print the Site URL and Access URL to the terminal. The difference is whether the Site URL alone is sufficient to access the service, or whether the authorization key in the Access URL is required.
105
115
106
116
## Installation
107
117
@@ -127,7 +137,7 @@ Flags:
127
137
-s, --source string Target address in ip:port format [required]
128
138
-H, --server string API server URL (default: https://console.yishield.com/raas)
129
139
-p, --tunnel-port int Chisel tunnel server port (default: 62888)
130
-
--visible Show tunnel in console (default: true)
140
+
--visable [filter]Enable visible mode (optional: AC node name filter)
0 commit comments