---
title: "GNU Screen Zero Trust – Ihsan Berahim"
canonical: "https://ihsanberahim.com/lab/gnu-screens/"
updated: "2026-10-10T16:57:05Z"
---

# GNU Screen Zero Trust – Ihsan Berahim

Cloudflare Zero Trust v1.0 • Open Source

# GNU Screen Zero Trust

A shell script and configuration for running GNU Screen terminal sessions behind Cloudflare Zero Trust tunnels. It lets you attach to remote sessions without opening inbound firewall ports or managing public SSH keys.

[ View on GitHub ](https://github.com/ihsanberahim/gnu-screens) [ Quickstart guide](#quickstart)

## How it works

### Traditional remote access

Opening port 22 to the internet requires static IP allowlists or dedicated bastion hosts. If an SSH connection drops, running processes can terminate abruptly.

### Cloudflare Zero Trust routing

Cloudflare Tunnel creates an outbound-only connection to Cloudflare edge nodes. Access policies verify identity and MFA before opening terminal access.

### Key capabilities

- Screen multiplexing keeps services running in the background even if your local network connection drops.
- Cloudflared creates an outbound connection, so servers do not need public IP addresses or forwarded ports.
- Cloudflare Access enforces authentication policies (such as Google Workspace, GitHub, or one-time PINs) before terminal access is granted.

## Quickstart and deployment

   bash github.com/ihsanberahim/gnu-screens

```
<span class="text-slate-500"># 1. Clone the repository</span>
git clone https://github.com/ihsanberahim/gnu-screens.git
cd gnu-screens

<span class="text-slate-500"># 2. Configure environment credentials</span>
cp .env.example .env

<span class="text-slate-500"># 3. Launch secure tunnel service</span>
./start-service.sh
```

Configuration options, token setup, and tunnel routing instructions are documented in the [README on GitHub](https://github.com/ihsanberahim/gnu-screens#readme).

Next project in Lab### CanAI for WordPress

A WordPress plugin for authoring templates with Twig 3 and Tailwind CSS via MCP.

[View project ](https://ihsanberahim.com/lab/canai/)

## Structured data

```json
[
    {
        "@type": "BreadcrumbList",
        "itemListElement": [
            {
                "@type": "ListItem",
                "position": 1,
                "name": "Home",
                "item": "https://ihsanberahim.com/"
            },
            {
                "@type": "ListItem",
                "position": 2,
                "name": "Lab",
                "item": "https://ihsanberahim.com/lab/"
            },
            {
                "@type": "ListItem",
                "position": 3,
                "name": "GNU Screen Zero Trust",
                "item": "https://ihsanberahim.com/lab/gnu-screens/"
            }
        ]
    },
    {
        "@type": "SoftwareSourceCode",
        "name": "GNU Screen Zero Trust",
        "url": "https://ihsanberahim.com/lab/gnu-screens/",
        "codeRepository": "https://github.com/ihsanberahim/gnu-screens",
        "programmingLanguage": "Bash",
        "description": "A shell script and configuration for running GNU Screen terminal sessions behind Cloudflare Zero Trust tunnels without opening inbound ports.",
        "author": {
            "@type": "Person",
            "name": "Ihsan Berahim",
            "jobTitle": "Ai Innovation Lead",
            "url": "https://ihsanberahim.com/#about"
        }
    }
]
```

<!-- WP Optimize page cache - https://teamupdraft.com/wp-optimize/ - Page not served from cache  -->
