Core Event
This article presents an SSH reverse tunnel solution for accessing GPU servers without public IP. Key facts:
- Protocol: SSH reverse tunnel via a public server as jump host
- Use case: AIGC development including ComfyUI and model training
- Tools: SSH
-Rflag, autossh for auto-reconnection - Deployment: systemd service for auto-start on boot
- No interaction: Key reuse + auto-SSH setup
Technical Details and Cost Comparison
Network topology:
| |
The reverse tunnel works because the GPU instance initiates the connection to the public server. Key insights:
- Only port 22 (SSH) needs to be open on the jump server—no need to open 8188 (ComfyUI) in security groups
- SSH tunnels are encrypted natively, more stable than third-party tools
- Cost Comparison: A ¥99/year Alibaba Cloud Light Server suffices as jump host, far cheaper than cloud GPU instances
The script supports multi-instance deployment with dynamic port allocation:
- SSH port: 2222 + INDEX - 1
- ComfyUI port: 8188 + INDEX - 1
Configuration
Enable IP forwarding on the Aliyun jump server:
| |
No additional ports need to be opened in security groups since traffic flows through SSH.
Recommendations
Ready to deploy if:
- You already have a public jump host (Aliyun ECS or similar)
- Frequent access to internal ComfyUI or VS Code Remote
- Dissatisfied with third-party tunnel stability
Wait if:
- No public jump host available (needs separate ECS purchase)
- Non-technical background (requires SSH/key/script familiarity)
- Occasional access only (tunnel overhead outweighs benefits)
Final Thoughts
SSH reverse tunneling is a classic NAT-penetration pattern, requiring no extra software. For AIGC developers, this solution significantly improves GPU server accessibility at minimal cost.
