Join our Newsletter — 33% off our NHI Course

Local MCP servers over SSH tunnels: are your controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Pomerium says Hosted Clusters in Pomerium Zero let local MCP servers expose a public HTTPS endpoint over an SSH reverse tunnel, removing tunnel setup, TLS work, and ephemeral URL handling so frontier models can call tools directly. The real shift is that MCP access now hinges on identity and policy decisions at runtime, not just network reachability.

Editorial analysis by NHI Mgmt Group, based on content published by Pomerium: “Hosted Clusters in Pomerium Zero & MCP Hacking (endpoints from localhost via ssh)”.

Key questions

Q: What breaks when private MCP servers are reachable only through shared tunnels?

A: Governance breaks when the access path can move traffic but cannot attribute the request to a person or enforce policy at the tool boundary.

Q: Why do mixed public and private MCP tools create governance risk?

A: They collapse different trust levels into one runtime surface.

Q: How should teams handle secrets in MCP development workflows?

A: Treat secrets in MCP configs, scripts, and templates as operational credentials, not temporary developer clutter.

Practitioner guidance

  • Govern MCP exposure as a managed access path Treat any public endpoint for a local MCP server as an explicit access channel with ownership, approval, and revocation rules.
  • Separate development convenience from persistent trust Do not let temporary tunnel workflows become the default pattern for tool access.
  • Inventory secrets used in MCP configuration Scan local MCP configs, templates, and helper scripts for embedded API keys, tokens, or other credentials that make the tunnel path usable.

Bottom line: Public exposure of local MCP servers changes the problem from simple connectivity to governed identity and policy enforcement.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 5 hours ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21367
 

Public MCP reachability is an identity problem before it is a networking problem. Once a local server can be called by a frontier model, the question shifts from transport setup to who or what is authorised to invoke tools. That matters because MCP collapses the distance between a local developer environment and a remotely reachable execution surface. The practitioner conclusion is simple: treat model-to-tool access as governed identity traffic, not as a convenience feature.

A few things that frame the scale:

A question worth separating out:

Q: How do you know whether MCP exposure is still controlled?

A: You know it is controlled when every reachable endpoint has a named owner, a specific caller identity, explicit tool limits, and a documented offboarding path. If the team cannot answer who can call it, which tools they can use, and when access expires, the exposure is not controlled.

👉 Read our full editorial: Hosted clusters for local MCP servers change identity assumptions



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21367
 

Hosted MCP exposure turns local development into an identity problem, not just a networking problem. Once a localhost tool is published through a public HTTPS endpoint, network reachability becomes the easy part. The harder question is whether the access path has an accountable identity, a policy decision, and a reviewable control point. Practitioners should treat MCP publishing as governed access provisioning, not as temporary plumbing.

A few things that frame the scale:

  • 24,008 unique secrets were exposed in MCP configuration files in 2025 alone, the protocol's first year of widespread adoption, according to the State of Secrets Sprawl 2026.

A question worth separating out:

Q: When should organisations retire an exposed MCP tunnel?

A: Retire it as soon as the local server is no longer the active owner of that access path, such as after a rebuild, handoff, or project shutdown. The tunnel is part of the service lifecycle, so teardown should happen with offboarding rather than later. That prevents temporary exposure from becoming a standing route to the tool.

👉 Read our full editorial: Hosted clusters for local MCP servers change identity assumptions


This post was modified 5 hours ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.