Managing Secure Remote Infrastructure with Oryxis
Managing remote infrastructure often forces sysadmins to choose between bare-bones terminal clients and resource-heavy WebKit wrappers. While standard OpenSSH binaries work well in scripts, managing multiple server profiles, SSH key pairs, port forwards, and file transfers across environments gets tedious. Oryxis offers a middle ground by providing a desktop SSH client and terminal emulator written in Rust using the Iced framework. It combines local AES-GCM credential vault storage, SFTP file management, and port forwarding in a native binary.
Step 1 – Installing Oryxis and Setting Up the Encrypted Vault
Installing Oryxis starts with grabbing the binary for your platform or building it directly from the Rust repository. Building from source requires cargo and standard build utilities on Linux or macOS. Clone the repository and build the release executable:
git clone https://github.com/wilsonglasser/oryxis.git
cd oryxis
cargo build --release
When you launch Oryxis for the first time, the client prompts you to initialize an encrypted vault. The vault encrypts host definitions, saved SSH keys, and connection credentials on disk using AES-256-GCM. Select a strong master password during setup. This password derives the local encryption key, keeping host credentials protected even if raw configuration files are accessed by unauthorized local processes.
Step 2 – Configuring Remote Hosts and Key Authentication
After creating the vault, add server entries to organize your infrastructure connections. Oryxis allows import of existing OpenSSH configurations from ~/.ssh/config or manual host entry creation. You can associate specific identity files, non-standard SSH ports, and environment variables with each profile.
To prepare an SSH key pair outside the interface for import, generate an Ed25519 key using the standard OpenSSH utility:
ssh-keygen -t ed25519 -C "admin@vps-node-01" -f ~/.ssh/id_oryxis_vps
Import the generated private key into the Oryxis key manager. Once stored in the vault, credentials link to individual server profiles, allowing one-click connections without typing passphrases on every session start.
Storing SSH private keys inside an encrypted local vault prevents plain-text identity leaks while maintaining instant access across multiple remote environments.
Step 3 – Managing File Transfers with Integrated SFTP
Switching between terminal sessions and external file transfer tools breaks focus during deployment tasks. Oryxis integrates an SFTP browser alongside active terminal tabs. When connected to a host, open the dual-pane file panel to inspect remote directory trees, transfer assets, and modify file permissions.
You can execute file operations through keyboard shortcuts or direct drag operations between local directories and remote destinations. For quick remote edits without opening a full terminal editor, use the inline editor to adjust configuration files:
# Example file permissions check performed via integrated SFTP session
chmod 600 /etc/nginx/sites-available/default
chown www-data:www-data /var/www/html/index.html
The file manager runs inside the existing SSH connection stream, eliminating the latency of negotiating separate secondary connections over high-ping networks.
Step 4 – Setting Up Local and Remote SSH Port Forwarding
Accessing internal services like database engines or administration panels behind firewalls requires SSH tunneling. Oryxis includes a dedicated port forwarding editor that manages local (-L), remote (-R), and dynamic (-D) SOCKS proxies without requiring manual terminal command strings.
To configure a local port forward that routes local traffic on port 8080 to an internal database server on 10.0.0.5:5432, set up a rule in the session parameters:
# CLI equivalent managed visually inside Oryxis
ssh -L 8080:10.0.0.5:5432 admin@remote-bastion-host -N
Once activated, Oryxis maintains tunnel connection states, automatically reconnecting dropped sockets during transient network interruptions. Visual indicators in the sidebar display active traffic rates and open tunnel listeners across all active sessions.
Step 5 – Syncing Vault Configurations Across Nodes Securely
When working across multiple workstation setups, keeping connection profiles aligned requires consistent state synchronization. Oryxis supports peer-to-peer vault synchronization between authorized devices without relying on central third-party servers. Encrypted vault blobs transfer directly over local subnet connections or custom relay endpoints.
Export an encrypted vault backup for manual transfer or device pairing using the internal CLI utility:
oryxis vault export --out ~/.config/oryxis/vault_backup.enc
Importing the encrypted payload on a secondary workstation restores all host tags, saved shortcuts, and key references once decrypted with your master password.
Next steps
Test Oryxis on your primary workstation by importing existing SSH configuration profiles. Evaluating native Rust SSH tooling provides a fast, low-memory alternative to Electron apps while keeping identity keys and connection tunnels organized in one place.