Skip to content

Latest commit

 

History

7 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

RevSH

RevSH is a secure reverse-tunneling application that provides instant, browser-based terminal access to remote devices. It streamlines infrastructure management by working seamlessly across complex networks, completely eliminating the need for inbound port forwarding or static IP configurations.

This project provides a zero-trust infrastructure management platform, combining a centralized web dashboard, a low-footprint remote agent, and context-aware AI assistance to securely monitor, pair, and command remote endpoints across any network.

Core Features

  • Reverse Tunneling Infrastructure: Connects remote devices securely to the server via persistent WebSocket connections, ensuring sub-millisecond command execution.
  • Browser-Based Terminal Emulator: Provides a fully interactive command-line interface within the web application, rendering stdout/stderr streams as if working on a local machine.
  • Zero-Trust Authentication: Offloads identity management to enforce strict JWT validation. Every terminal session and API endpoint is cryptographically verified.
  • Dynamic Device Management: A centralized dashboard to view active servers, generate secure time-limited pairing tokens, and instantly revoke device access.
  • Inline AI Assistant: Real-time terminal support utilizing vector-searched context to debug server issues and execute complex commands safely.

Context-Aware Inline AI

RevSH is built not just for secure access, but for intelligent terminal management. It features an inline AI assistant directly integrated into the terminal environment.

  • Powered by Gemini 3.5 Flash: Provides rapid, highly accurate natural language processing directly within the command-line interface. Users can ask the AI to explain complex system errors, write bash scripts, or translate intent into exact commands.
  • Retrieval-Augmented Generation (RAG): The AI does not rely solely on base training data. It utilizes a RAG pipeline backed by ChromaDB (a vector database). This allows the system to fetch and inject context such as recent terminal outputs, specific operating system environments, or historical command usage into the AI prompt, resulting in highly specific, accurate, and localized operational advice.

The Reverse Tunneling Advantage

Traditional remote management relies on standard SSH (Secure Shell), which comes with significant infrastructure and security overhead:

  • The SSH Problem: To SSH into a remote machine, that machine must have an open inbound port (typically port 22). This requires configuring router NAT rules, maintaining static IP addresses, and exposing the port to the public internet, leaving the server vulnerable to constant automated scanning and brute-force attacks.
  • The RevSH Solution: RevSH utilizes a reverse-tunnel architecture. Instead of the user connecting to the remote device, the lightweight RevSH agent installed on the target machine initiates an outbound connection to the centralized routing server.
  • Security & Convenience: Because the connection is established from the inside out, it naturally traverses NATs and strict corporate firewalls. The endpoint requires zero open inbound ports, making it completely invisible to public internet scanners.
  • Zero Network Configuration: Whether the target device is on a restrictive corporate network, a cellular connection, or shifting between dynamic IP addresses, the tunnel remains perfectly stable. The agent seamlessly reconnects from anywhere, eliminating the need to track IPs or manage dynamic DNS records.

Tech Stack

  • Next.js & React (Frontend)
    Drives the web dashboard and browser terminal. Next.js provides the fast, component-driven framework necessary for handling the complex state of an interactive terminal UI while maintaining a responsive user experience.

  • Python & FastAPI (Backend)
    Powers the core server and API routing logic. FastAPI’s native asynchronous support (ASGI) is essential for efficiently handling hundreds of simultaneous WebSocket connections with high throughput.

  • Rust (Remote Agent)
    Selected for the client executable due to its exceptional performance and memory safety. It compiles into a standalone binary that runs continuously on target devices with a near-zero resource footprint.

  • ChromaDB & Gemini 3.5 Flash
    ChromaDB serves as the vector store for the RAG pipeline, utilizing the text-embedding-004 model for semantic search. Gemini 3.5 Flash handles the LLM generation, delivering high-speed, context-aware terminal assistance.

  • WebSockets (Networking)
    The backbone of the application. WebSockets establish the persistent, bidirectional TCP connections required to stream keystrokes and server outputs back and forth in real-time.

  • Clerk (Authentication)
    Implemented for robust identity and access management. It enforces enterprise-grade JWT validation to ensure only authorized administrators can access the dashboard and initiate remote sessions.

Architecture Diagram

Privacy

This project does not collect, store, or share any personal data. All terminal streams, command outputs, and session information remain completely private and are processed locally to the user.

About

Secure browser-based terminal access via reverse tunneling Connect to any remote device across complex networks and NATs without exposing local ports, powered by context-aware inline AI

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages