Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
sshroute — Network-aware SSH router - routes connections to different IPs/ports/keys/jump hosts based on active VPN or network | Kitploit
Tools/GitHubGitHub/thereisnotime/sshroute
General Purpose UtilitiesScripting & AutomationNetwork SecurityUtilities & Frameworks
GitHubthereisnotime/sshroute

sshroute

Network-aware SSH router - routes connections to different IPs/ports/keys/jump hosts based on active VPN or network

View Repository
202428 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

sshroute

CI Code OpenSpec Security
CI
Release
OpenSpec Badge
Scorecard
Latest Release
codecov
Go Report Card
Go Reference
Specs
Requirements
Tasks
Open Changes
OpenSSF Scorecard
CII Best Practices
License: Apache 2.0

Network-aware SSH router. Detects your active network or VPN and automatically selects the right host, port, identity file, and jump host for each SSH connection — without touching ~/.ssh/config.

How it works

Define each logical host once with a default profile and optional per-network overrides. On every connection, sshroute detects which network you're on (VPN, office LAN, WireGuard peer, etc.) and resolves the correct SSH parameters before handing off to the real /usr/bin/ssh.

ssh myserver
  → sshroute detects: corp-vpn is active
  → resolves: 10.100.0.50:2222 via bastion.corp.internal
  → exec /usr/bin/ssh -p 2222 -i ~/.ssh/corp_key -J bastion.corp.internal 10.100.0.50

Why sshroute?

For homelabbers

Your lab probably has at least two realities: you're either sitting at home on the LAN, or you're away and coming in over WireGuard or another VPN. The problem is ~/.ssh/config doesn't know which one you're in — so you end up with separate aliases (server-lan, server-vpn), or a jump host that only works half the time, or you just memorize IPs.

sshroute solves this by detecting your current network before every connection. When the WireGuard interface is up and the peer route exists, it connects directly to the tunnel IP. When you're on the LAN, it uses the local address. When neither is reachable, it falls back to the public hostname. One alias, three realities, zero manual switching.

It also intercepts SSH transparently — git push, rsync, scp all go through it automatically once you set up shadow mode. No wrappers, no shell functions, no thinking.

For corporate environments

Enterprise networks are worse. You have the public internet, maybe a site-to-site VPN, maybe a personal VPN split-tunnel, and inside that you have different jump hosts depending on which environment you're targeting — dev, staging, prod, each with their own bastion and key. Keeping this straight in ~/.ssh/config means either one enormous config that breaks whenever infra changes, or you write a script that everyone on the team maintains differently.

sshroute lets you define the routing logic declaratively, keep it in a versioned YAML file, and share it across the team. The same config works for everyone — the right network is detected automatically based on what interfaces or routes are active on each machine. Keys, ports, users, and jump hosts resolve without the user having to think about it.

How it compares

Feature~/.ssh/configWireGuard-onlyTeleport / Boundarysshroute
Detects your current network❌❌❌✅
Picks the best path automatically❌❌❌✅
Falls back on connection failure❌❌✅✅
Auto-reconnect + re-route on drop❌⚠️ tunnel roams⚠️ via fixed proxy✅
One command per host, any location❌⚠️ VPN must be up✅✅
Config size for 10 hosts × 4 paths📄 ~600 lines📄 ~600 lines + VPN config📄 server-side config📄 ~60 lines
Roaming mobile devices⚠️ manual aliases⚠️ VPN required✅✅
Jump host auto-chaining⚠️ manual -J➖ n/a✅✅
Works with scp / rsync / git / Ansible✅✅⚠️ partial✅
No server-side install on targets✅❌❌✅
No auth server or daemon to run✅❌❌✅
No client agent✅❌❌✅
Open source, fully self-hosted✅✅⚠️ open-core✅

Teleport and Boundary are a different category — they add access control, audit logs, and certificate-based auth on top of routing. If that's what you need, use them. sshroute is for when you want the routing intelligence without the operational overhead of running a central auth server.

Installation

Binary download

Download the latest release from GitHub Releases. Binaries are available for Linux, macOS, and Android on AMD64 and ARM64.

Go install

go install github.com/thereisnotime/sshroute@latest

Android (Termux)

Download the android_arm64 tarball from GitHub Releases, extract, and place the binary in ~/.local/bin:

mkdir -p ~/.local/bin
curl -Lo "$TMPDIR/sshroute.tar.gz" \
  https://github.com/thereisnotime/sshroute/releases/latest/download/sshroute_android_arm64.tar.gz
tar -xzf "$TMPDIR/sshroute.tar.gz" -C ~/.local/bin sshroute
chmod +x ~/.local/bin/sshroute

Add ~/.local/bin to your PATH in ~/.bashrc or ~/.profile if it isn't already:

echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

Alternatively, compile from source with Termux's Go. Because the official Go toolchain doesn't publish android/arm64 binaries, set GOTOOLCHAIN=local to use what Termux ships:

Download Tool