An outbound-only tunnel is a secure connection that a small agent inside a private network opens out to a remote service, which then sends requests back over that already-established connection. Nothing inside the network listens for inbound traffic. The service can reach internal systems without open firewall ports, a public IP address or an inbound VPN.
What is an outbound-only tunnel?
Exposing a database to a cloud service traditionally means opening an inbound port, allow-listing IP ranges and hoping nothing else finds it. An outbound-only tunnel inverts that. Cloudflare’s documentation describes the pattern well: a lightweight daemon in your infrastructure creates outbound-only connections to the provider’s network, so resources connect without a publicly routable IP, and you can configure your firewall to allow only those outbound connections and block all inbound traffic.1Source 1 · Cloudflare One docsCloudflare Tunneldevelopers.cloudflare.com The classic version is OpenSSH’s -R option, which forwards connections arriving at a port on the remote host back to the local side over the connection the client opened.2Source 2 · OpenBSD manual pagesssh(1): OpenSSH remote login clientman.openbsd.org
Scroll sideways to see the full diagram.
How does it compare with opening an inbound port or a VPN?
| Inbound port | Site-to-site VPN | Outbound-only tunnel | |
|---|---|---|---|
| Who initiates | The outside service | Either side | The agent inside your network |
| Firewall change | Open inbound port and allow-list | VPN gateway and routes | Allow one outbound destination |
| Exposure to scanning | Listening port is reachable | Gateway is reachable | No listening port |
| Scope of access | Whatever the port reaches | Often a whole subnet | Only what the agent is configured to reach |
| Revocation | Firewall change | Tear down VPN | Stop the agent or revoke its certificate |
Outbound-only does not mean trusted. Zero trust architecture, as NIST puts it, assumes no implicit trust based on network location.3Source 3 · National Institute of Standards and Technology, 2020SP 800-207: Zero Trust Architecturecsrc.nist.gov Each request through the tunnel should therefore be authenticated and authorized on its own merits. TLS 1.3 supports this in both directions: the server can send a CertificateRequest, and if the client presents no acceptable certificate the server can abort the handshake.4Source 4 · IETF / RFC Editor, 2018RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3rfc-editor.org
Common misconceptions
- “Outbound means one-way data.” Requests and responses both travel over the connection. What changes is who can start it.
- “No open port means no risk.” The remote side can still send requests. Limit them with a local policy, read-only credentials and rate limits.
- “A tunnel is the same as a VPN.” A VPN joins networks; an application tunnel exposes only the specific services its agent is set up to reach.
How Kimo Bridge uses an outbound-only tunnel
Kimo Bridge (kimo-bridge, image ghcr.io/getkimo/bridge) runs next to your database as a Docker container, a Helm chart or a single binary. It opens one outbound TLS connection to Kimo with mutual authentication. No inbound rules are needed. Database credentials stay on your server, every query is checked against a local policy, rate-limited and written to an audit log, and you can revoke access instantly. Install it with the Docker guide or the Kubernetes guide, review the security model, and manage bridges in the app.
Related terms
- Query pushdown: what travels through the tunnel instead of raw rows.
- Data residency: why keeping data behind your firewall matters.
- Row-level security: authorization inside the database.
Frequently asked questions
Why is it called a reverse tunnel?
Does an outbound-only tunnel work behind a corporate proxy?
How do I cut access immediately?
Sources
4 references- Cloudflare Tunnel (opens in a new tab)Cloudflare One docsdevelopers.cloudflare.com
Outbound-only connections from a local daemon; no publicly routable IP; block all inbound traffic.
- ssh(1): OpenSSH remote login client (opens in a new tab)OpenBSD manual pagesman.openbsd.org
-R remote forwarding: connections to a port on the remote host are forwarded to the local side.
- SP 800-207: Zero Trust Architecture (opens in a new tab)National Institute of Standards and Technology2020csrc.nist.gov
No implicit trust based on network location.
- RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3 (opens in a new tab)IETF / RFC Editor2018rfc-editor.org
Certificate-based client authentication via CertificateRequest; server may abort with certificate_required.
External sources were accessed at the time of writing. Kimo product details, customers and figures in examples are illustrative unless a source is cited.







