GNU Screen Zero Trust
A shell script and configuration for running GNU Screen terminal sessions behind Cloudflare Zero Trust tunnels. It lets you attach to remote sessions without opening inbound firewall ports or managing public SSH keys.
How it works
Traditional remote access
Opening port 22 to the internet requires static IP allowlists or dedicated bastion hosts. If an SSH connection drops, running processes can terminate abruptly.
Cloudflare Zero Trust routing
Cloudflare Tunnel creates an outbound-only connection to Cloudflare edge nodes. Access policies verify identity and MFA before opening terminal access.
Key capabilities
- Screen multiplexing keeps services running in the background even if your local network connection drops.
- Cloudflared creates an outbound connection, so servers do not need public IP addresses or forwarded ports.
- Cloudflare Access enforces authentication policies (such as Google Workspace, GitHub, or one-time PINs) before terminal access is granted.
Quickstart and deployment
# 1. Clone the repository
git clone https://github.com/ihsanberahim/gnu-screens.git
cd gnu-screens
# 2. Configure environment credentials
cp .env.example .env
# 3. Launch secure tunnel service
./start-service.sh
Configuration options, token setup, and tunnel routing instructions are documented in the README on GitHub.
CanAI for WordPress
A WordPress plugin for authoring templates with Twig 3 and Tailwind CSS via MCP.