Skip to content

Make SSH ProxyCommand helpers like cloudflared work reliably #11

Description

@kingel

Hermes Desktop already works well for the normal SSH-first cases it is built around: direct hosts, SSH aliases, localhost, LAN/public IP, VPN, and Tailscale, as long as standard ssh from the Mac can reach the host.

This issue is about a narrower case: SSH setups that depend on a local ProxyCommand helper such as cloudflared.

In these setups, the app launches /usr/bin/ssh and relies on the local SSH config, but the helper binary also needs to be resolvable from the app environment. If cloudflared is only available in an interactive shell PATH and not in the GUI app context, SSH can fail even though the same config appears to work from Terminal.

Why this matters:

  • Cloudflare Tunnel / Access SSH is a legitimate workflow
  • users should not need to abandon the app just because their SSH route depends on a local helper binary

Likely fix direction:

  • improve support for SSH config flows that rely on local ProxyCommand helpers
  • make local helper resolution more reliable from the app context
  • improve user-facing guidance when a helper like cloudflared is missing from the effective PATH

Practical workaround today:

  • use the absolute path to cloudflared in ProxyCommand
  • or make sure cloudflared is installed in a path visible to GUI-launched apps, not only to an interactive shell

So this remains a valid issue, but it is best understood as a ProxyCommand helper environment case rather than a general SSH compatibility problem.

Activity

  1. dodo-reach commented on May 14, 2026

    @dodo-reach
    Owner

    Thanks for reporting this, and sorry this has stayed open without a clearer follow-up.

    I checked it again against the current app behavior. This still looks like a real issue, but it is a fairly specific one: Hermes Desktop already works well for the normal SSH paths most users rely on, and this case is specifically about SSH configs that depend on a local ProxyCommand helper such as cloudflared.

    The good news is that there is usually a simple workaround today: instead of relying on cloudflared being found through your interactive shell PATH, point ProxyCommand to the absolute path of the cloudflared binary, or install it in a location that is visible to GUI-launched apps on macOS as well.

    So I am keeping this open, but I want to frame it correctly for others who land here: this is not a sign that Hermes Desktop is broadly broken for SSH. It is a narrower environment-resolution case around local helper binaries used by ProxyCommand.

    I do want to improve this, because Cloudflare Access is a legitimate setup and the app should handle it more gracefully.

  2. changed the title [-]Cloudflared support[/-] [+]Make SSH ProxyCommand helpers like cloudflared work reliably[/+] on May 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions