# Error when running zrok private share from a script

**URL:** <https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707>\
**Category:** zrok\
**Created:** [October 14, 2023, 10:09pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707 "2023-10-14T22:09:03Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![twisteddog99](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/twisteddog99/32/1120_2.png) [@twisteddog99](https://openziti.discourse.group/u/twisteddog99)\
**Post date:** [October 14, 2023, 10:09pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/1 "2023-10-14T22:09:03Z")

</div>

I'm trying to set up consistent remote access to a linux machine via ssh over zrok:

Run on remote: `zrok share private --backend-mode tcpTunnel 127.0.0.1:22`  
Run on local `zrok access private xxxxx`  
Run on local in another terminal: `ssh -p 9191 uname@127.0.0.1`  
This works great and I can happily use ssh.

However, when I run the share command in my startup script like this:  
`nohup zrok share private --backend-mode tcpTunnel 127.0.0.1:22 &`  
or

```auto
screen
zrok share private --backend-mode tcpTunnel 127.0.0.1:22

```

I get a

```auto
kex_exchange_identification: read: Connection reset by peer
Connection reset by 127.0.0.1 port 9191

```

error when trying to ssh in.  
This error also appears in the local zrok window:

```auto
│[5.113] ERROR zrok/endpoints/tcpTunnel.(*Frontend).accept: error │
│dialing 'mubutnn93yev': unable to dial service 'mubutnn93yev': dial failed: │
│service 2U0JVJKVbl8R5uZXxgxaGC has no terminators │

```

Why is this, and is there a smarter way to start the zrok share programmatically that anyone uses already?  
Cheers,  
T

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [October 14, 2023, 10:32pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/2 "2023-10-14T22:32:14Z")

</div>

I suspect you need the `--headless` option in `zrok share private` so it only logs and doesn't try to display the terminal UI.

Another option is using Docker with network mode "host" so the zrok container can "see" your Docker host's 127.0.0.1:22. Here's a guide: [Docker Private Share | Zrok](https://docs.zrok.io/docs/guides/docker-share/docker_private_share_guide/). The Docker container uses the `--headless` option too, and has the added benefit of providing process management for things like auto-start after a reboot, which you could also achieve by creating a systemd service definition if you prefer to avoid Docker.

If you do feel like using Docker and you get to the part about downloading the Compose file for the share, then you can edit this part to have `network_mode: host`.

```yaml
  zrok-private-share:
    network_mode: host
    image: docker.io/openziti/zrok
    command: share private --headless --backend-mode tcpTunnel 127.0.0.1:22
    depends_on:
      zrok-enable:
        condition: service_completed_successfully
    volumes:
      - zrok_env:/mnt/.zrok
    environment:
      HOME: /mnt
      PFXLOG_NO_JSON: "true"

```

This doesn't mean you have to use Docker on the `ssh` client side, but you could if you want.

---

<div class="post-metadata">

**Author:** ![twisteddog99](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/twisteddog99/32/1120_2.png) [@twisteddog99](https://openziti.discourse.group/u/twisteddog99)\
**Post date:** [January 11, 2024, 9:07pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/3 "2024-01-11T21:07:49Z")

</div>

I'm trying to run a very similar command on my work mac for the same reason (remote ssh control):

```auto
zrok share private --headless --backend-mode tcpTunnel 127.0.0.1:22

```

and am getting the same "service has no terminators" error on the client side.

Why could this be?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 11, 2024, 9:15pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/4 "2024-01-11T21:15:24Z")

</div>

"service has no terminators" is very odd. Does it happen every time? This error is one that comes from the underlying OpenZiti overlay network, but it's very much unexpected. Are you self-hosting zrok or are you using the [zrok.io](http://zrok.io) SaaS offering?

---

<div class="post-metadata">

**Author:** ![qrkourier](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/qrkourier/32/52_2.png) [@qrkourier](https://openziti.discourse.group/u/qrkourier)\
**Post date:** [January 11, 2024, 9:16pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/5 "2024-01-11T21:16:43Z")

</div>

> [@twisteddog99](#):
>
> and am getting the same "service has no terminators" error on the client side.

I think this means the no terminators error was emitted when you ran something like this.

```bash
zrok access private --headless cdthz0z5fzzx

```

---

<div class="post-metadata">

**Author:** ![twisteddog99](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/twisteddog99/32/1120_2.png) [@twisteddog99](https://openziti.discourse.group/u/twisteddog99)\
**Post date:** [January 11, 2024, 9:23pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/6 "2024-01-11T21:23:06Z")

</div>

I'm using the [zrok.io](http://zrok.io) network, I can see that the host machine is being accessed by the client via [api.zrok.io](http://api.zrok.io) but no traffic shows up in the graph.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 11, 2024, 9:24pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/7 "2024-01-11T21:24:47Z")

</div>

Yeah, that's really unexpected then. Can you reproduce it every time?

I wonder if it might be that your script is operating too fast? That's probably what it is... Can you loop the script a few times if you get that error with a sleep in between and see what happens? It probably takes 5-15 seconds for a share to get created. (ASSUMING you're creating a share then trying to access it immediately)

---

<div class="post-metadata">

**Author:** ![twisteddog99](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/twisteddog99/32/1120_2.png) [@twisteddog99](https://openziti.discourse.group/u/twisteddog99)\
**Post date:** [January 11, 2024, 9:26pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/8 "2024-01-11T21:26:49Z")

</div>

You mean the script on the host side?  
Right now I'm running the command in terminal as a test, not seeing any output in the host console (even with -v argument) when I run the client access command.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 11, 2024, 9:29pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/9 "2024-01-11T21:29:33Z")

</div>

I must admit, I haven't really ascertained exactly what your flow looks like yet. I am expecting you're running a command to create a share somewhere, then running the script to access the share and that accessing of the share is the one that's failing because the 'create' process is taking a bit of time?

But, we can level-set and I can just ask, "exactly what are you doing and how"? Can you share the script and methodology so that I can test it myself and replicate the problem? If you can reproduce it, it's a good chance I can reproduce it and it'll let me understand what you're doing and how.

Can you give me the script/steps to reproduce and I'll try with my env?

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 11, 2024, 9:32pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/10 "2024-01-11T21:32:54Z")

</div>

I have someone else who is reporting the same erorr at this time. [zrok.io](http://zrok.io) might be having "a blip"...

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 11, 2024, 9:42pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/11 "2024-01-11T21:42:01Z")

</div>

yeah. zrok is having an issue at this moment. i'm getting the same issue... I'll post back after we get it sorted.

---

<div class="post-metadata">

**Author:** ![twisteddog99](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/twisteddog99/32/1120_2.png) [@twisteddog99](https://openziti.discourse.group/u/twisteddog99)\
**Post date:** [January 11, 2024, 9:46pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/12 "2024-01-11T21:46:07Z")

</div>

Yes, sorry.  
My exact workflow:

1. Enable remote management in settings on work computer ("server", mac mini M2 Ventura 13.4)
2. Test ssh on local network from personal computer ("client", macbook pro M2 Sonoma 14.2) using the following command: `ssh macminiusername@macminihostname.local`, enter password and confirm that ssh server is running on the server mac.
3. Download zrok arm64 binary on server mac, move to applications folder and add to path
4. Enable zrok with token from [api.zrok.io](http://api.zrok.io) on server mac.
5. Run on server mac: `zrok reserve private --backend-mode tcpTunnel 127.0.0.1:22` and get reserved share token
6. Run on server mac: `zrok share reserved xxxxxx`, zrok fires up
7. Run on client mac: `zrok access private xxxxx, connection window opens, dotted line appears between the share and the access nodes on [api.zrok.io](http://api.zrok.io).
8. Run on client mac in new terminal: `nc 127.0.0.1 9191`, command exits with a blank string
9. Go back to zrok window on 1st terminal and read error:

```auto
ERROR zrok/endpoints/tcpTunnel.(*Frontend).accept: error dialing │
│'xxxxxxxxxxx': unable to dial service 'xxxxxxxxxxx': dial failed: service │
│xxxxxxxxxxxxxxxx has no terminators

```

Thanks for the quick responses

Edit:  
Just saw your response and can try again after the reboot, thanks again.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 11, 2024, 9:48pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/13 "2024-01-11T21:48:02Z")

</div>

Thanks for that.

Ok, things should be back and operational hopefully. Things are working on my side again. We had an OpenZiti overlay network upgrade today and it would seem as though something happened to cause this issue with zrok...

We'll be investigating the issue to determine what happened, adding more alerts etc...

Thanks for bringing this to our attention! Please try again and lemme know if it's fixed.

---

<div class="post-metadata">

**Author:** ![twisteddog99](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/twisteddog99/32/1120_2.png) [@twisteddog99](https://openziti.discourse.group/u/twisteddog99)\
**Post date:** [January 11, 2024, 10:24pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/14 "2024-01-11T22:24:01Z")

</div>

Working now, cheers and thank you.

---

<div class="post-metadata">

**Author:** ![twisteddog99](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/twisteddog99/32/1120_2.png) [@twisteddog99](https://openziti.discourse.group/u/twisteddog99)\
**Post date:** [January 12, 2024, 7:27pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/15 "2024-01-12T19:27:23Z")

</div>

Hi guys,  
After it working well yesterday, I am unable to get the zrok ssh connection going today.  
Getting the same `service xxx has no terminators` message.  
Any leads?  
Best,  
T

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 12, 2024, 7:33pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/16 "2024-01-12T19:33:45Z")

</div>

Hi @twisteddog99. I think we're experiencing some "unexpected success" that's putting strain on zrok in certain places. We're working through it, adding alerts, trying to find issues, etc. We move fast, so we should be able to figure out what is happening and fix it soon. Until then, we appreciate your patience with us as we work through it... 😕

---

<div class="post-metadata">

**Author:** ![twisteddog99](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/twisteddog99/32/1120_2.png) [@twisteddog99](https://openziti.discourse.group/u/twisteddog99)\
**Post date:** [January 13, 2024, 8:06pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/17 "2024-01-13T20:06:42Z")

</div>

Ok and thanks @TheLumberjack.  
Do you think self-hosting would be a temporary solution?  
T

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [January 13, 2024, 9:35pm UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/18 "2024-01-13T21:35:11Z")

</div>

We have added additional health checking in the last few days. Those checks have indicated things have been working properly but sure, it's possible another issue crops up. You could self-host, sure, that's always an option but I'd be interested in knowing if you're experiencing issues that we're not noticing? That'd be really good information for us since it'd indicate we missed a problem with the new monitoring (a gap we'd surely like to fix if that were the case).

Are you running into more troubles today? I've been using it all day myself playing around for home-lab stuff and it's been fine for me, personally, but maybe you're hitting an issue I'm not.

---

<div class="post-metadata">

**Author:** ![GDistel](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/gdistel/32/3804_2.png) [@GDistel](https://openziti.discourse.group/u/GDistel)\
**Post date:** [October 5, 2025, 1:35am UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/19 "2025-10-05T01:35:26Z")

</div>

I am getting the same issue. After reading through the thread it would seem an operational issue on the OpenZiti network?

We have not done any change. Things were just working.

This is about accessing a private share (ssh through tcp tunneling)

---

<div class="post-metadata">

**Author:** ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)\
**Post date:** [October 5, 2025, 3:30am UTC](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707/20 "2025-10-05T03:30:55Z")

</div>

I don’t know that we’re aware of any current operational issues.

Can you describe in more detail what the problem is that you’re running into? Log messages from `zrok access` and `zrok share` would be helpful.

[Next page](https://openziti.discourse.group/t/error-when-running-zrok-private-share-from-a-script/1707.md?page=2)
