Gateway connection fails after SSH key expiration
0 reputation · 07 Oct 2025, 05:44 UTC
Gateway connection fails after SSH key expiration
JetBrains Gateway relies on the local SSH agent to provide authentication credentials for remote development. When an SSH key is issued with a short time‑to‑live (TTL) and the key expires while a session is active, the Gateway reports an authentication error and disconnects the IDE backend. The exact error message shown is:
Authentication failed: key has expired
The goal is to keep a continuous remote development session without requiring a full Gateway restart when the key TTL lapses, while still enforcing least‑privilege access for the remote user. Constraints include:
- The IDE backend runs under the authenticated OS user and must have write access only to its own cache directory (
~/.cache/JetBrains). - SSH key rotation or renewal must not elevate privileges beyond the user’s own account.
- Automatic key refresh would need to be handled by the Gateway client, not by the remote server.
Unresolved behavior:
- Does JetBrains Gateway automatically detect and reload a refreshed key from the SSH agent without a full reconnect?
- What configuration options, if any, allow the client to poll the SSH agent for key changes?
- Is there a documented best practice for using short‑lived keys with Gateway while maintaining least‑privilege access?
These questions seek to clarify the current capabilities and recommended workflow for managing expiring SSH credentials in JetBrains Gateway.