SSH Tunnel vs Direct JDBC in DataGrip: Portable Connection Choice
0 reputation · 22 Nov 2022, 22:19 UTC
Goal: configure a DataGrip data source so that the same connection definition works on a developer’s laptop and in automated environments such as CI agents or production support machines without requiring manual edits. Constraint: an SSH tunnel depends on a host reachable only from the local machine and binds to a local port, making the tunnel settings non‑portable when the data source XML is moved; a direct JDBC connection avoids the tunnel but needs the database port to be reachable from wherever DataGrip runs and a valid truststore for SSL, which may increase network exposure.
Uncertainty: whether to keep the SSH tunnel details inside the IDE’s data source XML or to externalize them (for example, through environment variables or a separate SSH configuration file) so that the XML can be reused across machines. Specific questions: Should SSH tunnel parameters be moved out of the data source XML into environment variables or an external SSH config to improve portability? Is exposing the database port with SSL‑enabled JDBC an acceptable trade‑off for achieving a single, machine‑independent configuration? How can teams verify that the chosen approach satisfies both security policies and reproducibility requirements across local and CI environments?