What is SSH port forwarding?
SSH port forwarding carries a TCP connection through an SSH session, so a port on one machine answers as if it were a port on another.
runtime sandbox port-forward <id> 5432 makes localhost:5432 on your
machine the database inside a Runtime sandbox, through the API, with no port
opened to the internet. Any TCP port works, not only HTTP: Redis, a debugger,
a dev server that uses WebSockets (forward ports).
Local and remote forwarding
RFC 4254, the SSH connection protocol, defines both directions as channel types:
| Direction | Channel | What it does |
|---|---|---|
| Local | direct-tcpip |
A port on your machine reaches a host and port the server can see |
| Remote | tcpip-forward, then forwarded-tcpip |
A port on the server reaches back to your machine |
With OpenSSH, ssh -L 5432:localhost:5432 server is local forwarding and
ssh -R 8080:localhost:3000 server is remote.
When to forward, and when to publish
A forward is private: only the machine that runs it can use the port, and it lasts until you press Ctrl-C. To let others reach a service, publish it instead.
| You want | On Runtime |
|---|---|
| Your own tools on a sandbox's database | runtime sandbox port-forward |
| A link to a web app for someone else | A preview URL, private by default |
| A raw TCP port anyone can reach | A TCP port, on a paid account (open a TCP port) |
| Private traffic with your own servers | A WireGuard tunnel, $5 a 30-day month |
Keep the server running
A forward needs something listening. Start the server with
runtime sandbox spawn <id> -- <command> so it keeps running; a process
started by exec ends with its command. The forward says so when nothing
listens on the port.
Related
- How to port-forward a database from a sandbox
- What is SSH?
- What is a preview URL?
- How to open a TCP port
Sources
Checked 27 September 2026.