kimo
DefinitionAll productsData

Outbound-only tunnel

Definition

An outbound-only tunnel is a secure connection that an agent inside a private network opens out to a remote service, which then sends requests back over that established connection. Because nothing listens for inbound traffic, the network needs no open ports, public IP or inbound firewall exceptions.

Updated 4 sources3 min read

An outbound-only tunnel is a secure connection that a small agent inside a private network opens out to a remote service, which then sends requests back over that already-established connection. Nothing inside the network listens for inbound traffic. The service can reach internal systems without open firewall ports, a public IP address or an inbound VPN.

What is an outbound-only tunnel?

Exposing a database to a cloud service traditionally means opening an inbound port, allow-listing IP ranges and hoping nothing else finds it. An outbound-only tunnel inverts that. Cloudflare’s documentation describes the pattern well: a lightweight daemon in your infrastructure creates outbound-only connections to the provider’s network, so resources connect without a publicly routable IP, and you can configure your firewall to allow only those outbound connections and block all inbound traffic.1 The classic version is OpenSSH’s -R option, which forwards connections arriving at a port on the remote host back to the local side over the connection the client opened.2

Kimo Bridge architectureThe bridge dials out from your network over mutually authenticated TLS; Kimo’s requests come back over that connection.YOUR NETWORK · VPC / ON-PREMKIMO CLOUDPostgreSQLPostgreSQLapp databaseClickHouseClickHouseproduct eventsInternal APIREST · read-onlykimo-bridgeagent · v1read-only credsnever leave hereFirewallno inbound ports openedoutbound TLS · mTLSBridge gatewayauthz · rate limitsAudit logevery query recordedSemantic layermodels · measuresDashboardslive tilesAsk Kimoaudited answersRevoke instantly: stop the agentNothing stored by defaultqueryresults
Figure.The bridge dials out from your network over mutually authenticated TLS; Kimo’s requests come back over that connection.

Scroll sideways to see the full diagram.

How does it compare with opening an inbound port or a VPN?

Inbound portSite-to-site VPNOutbound-only tunnel
Who initiatesThe outside serviceEither sideThe agent inside your network
Firewall changeOpen inbound port and allow-listVPN gateway and routesAllow one outbound destination
Exposure to scanningListening port is reachableGateway is reachableNo listening port
Scope of accessWhatever the port reachesOften a whole subnetOnly what the agent is configured to reach
RevocationFirewall changeTear down VPNStop the agent or revoke its certificate

Outbound-only does not mean trusted. Zero trust architecture, as NIST puts it, assumes no implicit trust based on network location.3 Each request through the tunnel should therefore be authenticated and authorized on its own merits. TLS 1.3 supports this in both directions: the server can send a CertificateRequest, and if the client presents no acceptable certificate the server can abort the handshake.4

Common misconceptions

  • “Outbound means one-way data.” Requests and responses both travel over the connection. What changes is who can start it.
  • “No open port means no risk.” The remote side can still send requests. Limit them with a local policy, read-only credentials and rate limits.
  • “A tunnel is the same as a VPN.” A VPN joins networks; an application tunnel exposes only the specific services its agent is set up to reach.

How Kimo Bridge uses an outbound-only tunnel

Kimo Bridge (kimo-bridge, image ghcr.io/getkimo/bridge) runs next to your database as a Docker container, a Helm chart or a single binary. It opens one outbound TLS connection to Kimo with mutual authentication. No inbound rules are needed. Database credentials stay on your server, every query is checked against a local policy, rate-limited and written to an audit log, and you can revoke access instantly. Install it with the Docker guide or the Kubernetes guide, review the security model, and manage bridges in the app.

Frequently asked questions

Why is it called a reverse tunnel?

Because the connection is opened in the reverse of the direction requests flow: the private side dials out, and the remote service sends requests back over it, as with SSH remote forwarding.

Does an outbound-only tunnel work behind a corporate proxy?

Usually, if the proxy allows the destination on port 443. TLS-inspecting proxies usually break mutual TLS, so the destination typically needs to be exempt from inspection.

How do I cut access immediately?

Stop the agent or revoke its credential. Because nothing listens inbound, no connection to your network remains once the agent’s outbound session ends.

Sources

4 references
  1. Cloudflare Tunnel (opens in a new tab)
    Cloudflare One docsdevelopers.cloudflare.com

    Outbound-only connections from a local daemon; no publicly routable IP; block all inbound traffic.

  2. ssh(1): OpenSSH remote login client (opens in a new tab)
    OpenBSD manual pagesman.openbsd.org

    -R remote forwarding: connections to a port on the remote host are forwarded to the local side.

  3. SP 800-207: Zero Trust Architecture (opens in a new tab)
    National Institute of Standards and Technology2020csrc.nist.gov

    No implicit trust based on network location.

  4. RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3 (opens in a new tab)
    IETF / RFC Editor2018rfc-editor.org

    Certificate-based client authentication via CertificateRequest; server may abort with certificate_required.

External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.

Used in

Where Outbound-only tunnel shows up in practice

6 resources
GuideBeginner
All

Install Kimo Bridge with Docker

Run the bridge next to your database in minutes: outbound-only, read-only, revocable.

Arno Visser
10 min read
GuideAdvanced
All

Deploy Kimo Bridge on Kubernetes

Helm chart, secrets, high availability and network policies for production.

Arno Visser
10 min read
GuideIntermediate
All

The Kimo Bridge security model

What leaves your network, what never does, and how every query is authorized and audited.

Rhea Patel
10 min read
Whitepaper
All

Your Data, Your Rules

The hybrid analytics architecture behind Kimo Bridge: live query pushdown, optional cloud sync, and zero-trust by default.

Arno Visser
22 pages
ArticleProduct
All

Introducing Kimo Bridge: your data stays home

A small package you install next to your database opens a private, outbound-only bridge to Kimo. Query live, store nothing — or sync to our cloud when you want to.

Théo Marchand
7 min read

Your data officer is ready.

Connect a source — or install Kimo Bridge and keep data on your servers — then ask a question and get an answer you can audit.