Reach any TCP service from DuckDB through an SSH bastion, Tailscale or NetBird — and publish local ports back onto those networks.
Maintainer(s):
jrosskopf
Installing and Loading
INSTALL erpl_tunnel FROM community;
LOAD erpl_tunnel;
Added Functions
| function_name | function_type | description | comment | examples |
|---|---|---|---|---|
| tunnel_close | pragma | Close one tunnel by id; idempotent, and reports whether the tunnel was still open. | NULL | [PRAGMA tunnel_close(1);] |
| tunnel_close_all | pragma | Close every open tunnel; idempotent. | NULL | [PRAGMA tunnel_close_all;] |
| tunnel_create | pragma | Deprecated alias of tunnel_import, kept so existing scripts keep working; use tunnel_import instead. | NULL | [PRAGMA tunnel_create(secret = 'bastion', remote_host = 'db.internal', remote_port = 5432, local_port = 15432);] |
| tunnel_export | pragma | Publish a local port onto the network; returns (tunnel_id, remote_port, message). Named parameters: secret, local_port, local_host, remote_port, remote_host, timeout. Over a mesh backend there is no host to name, so remote_host is rejected. | NULL | [PRAGMA tunnel_export(secret = 'ts', local_port = 9494);] |
| tunnel_import | pragma | Bring a remote service to a local port; returns (tunnel_id, message). Named parameters: secret, remote_host, remote_port, local_port, timeout, bind_all. Binds 127.0.0.1 unless bind_all is true. | NULL | [PRAGMA tunnel_import(secret = 'bastion', remote_host = 'db.internal', remote_port = 5432, local_port = 15432);] |
| tunnel_mesh_activate | pragma | Advanced – force-load a mesh backend ('tailscale' or 'netbird') now. Normally automatic on first tunnel_import/tunnel_peers; use only to surface auth errors early or to pin the one mesh for this process. | NULL | [PRAGMA tunnel_mesh_activate('tailscale');] |
| tunnel_peers | table | Enumerate mesh peers for a tunnel secret (peer-local, no API token). | NULL | [SELECT * FROM tunnel_peers(secret = 'ts')] |
| tunnel_self | table | Show this node's own mesh identity (name/ip/tags) for a tunnel secret. | NULL | [SELECT * FROM tunnel_self(secret = 'ts')] |
| tunnels | table | List all active tunnels (SSH and mesh) with their backend, connection details, and status. | NULL | [SELECT * FROM tunnels()] |
Overloaded Functions
This extension does not add any function overloads.
Added Types
This extension does not add any types.
Added Settings
| name | description | input_type | scope | aliases |
|---|---|---|---|---|
| datazoo_banner | Show the DataZoo feedback banner when an extension is loaded in an interactive terminal (at most once a day per extension). | BOOLEAN | GLOBAL | [] |
| erpl_telemetry_enabled | Enable ERPL telemetry, see https://erpl.io/telemetry for details. | BOOLEAN | GLOBAL | [] |
| erpl_telemetry_key | Telemetry key, see https://erpl.io/telemetry for details. | VARCHAR | GLOBAL | [] |