# OpenZiti and terminators

**URL:** <https://openziti.discourse.group/t/openziti-and-terminators/400>\
**Category:** Building/Development\
**Created:** [April 13, 2022, 7:08am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400 "2022-04-13T07:08:01Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 7:08am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/1 "2022-04-13T07:08:01Z")

</div>

# Situation

I had three demos working

1. reflect client / server
2. desktop tunneller
3. mobile tunneller

So.. I thought to try the zitified ssh for a bit of fun.

I had everything setup.. except for the tunneller.. as this was the error I was getting

> FATAL error when dialing service name golang-zssh. unable to dial service 'golang-zssh': dial failed: service J-CGOlxhC has no terminators

Not having much idea this was.. I did some investigation in ZAC..

I saw this terminator.. though I had no idea how it was created.

 ![Screen Shot 2022-04-13 at 4.59.50 pm](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/465db24229fda383fb4e3ba64003902c8a79144f.png)

I noticed that the service was the original service for the reflect example.. not the ssh service that I created

> > so I tried to change it

 ![Screen Shot 2022-04-13 at 5.03.18 pm](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/0f7e061912d414036ac8fb6459038c3bf638ed9b.png)

> You cannot do this..

As it looked a bit funny.. not knowing what the hosted address was... I deleted it. 🙂

This broke everything.. and I needed to start from the top again.. which was ok.. because I wanted to know what created it.

> > well.. I worked it out.

when you start the server for the reflect example.. guess what.. it was **automatically** created.. and it assigned the service name provided.

go run simple-server.go "$HOME/golang.http.server.json" "golanghttp"

This gave me the ahah moment..

> > when you want to create the zitified ssh example.. you need to stop this .. and restart it with a new service name

Well I think that is what you need to do.. I will know more in a few more minutes 🙂

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 7:09am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/2 "2022-04-13T07:09:22Z")

</div>

Ahh… also… when you stop the server… the **terminator** is automatically deleted 🙂

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 7:35am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/3 "2022-04-13T07:35:49Z")

</div>

well.. I must be close.. but it did not work.. I think I have tracked down the problem... but don't know what it all means

This is what the service looks like for the zzh demo

 ![Screen Shot 2022-04-13 at 5.27.30 pm](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/5999029b90e0bbd607687447f306c70c38ad5194.jpeg)

However... when I watched one of the demo videos.. it was configured as follows

 ![Screen Shot 2022-04-12 at 9.57.48 pm](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/b7236c0f37637714cbaa6310f13ef1ba2a139039.jpeg)

I am not really sure what went wrong.. here are the commands that I used..

> I am skipping the creation and enrolling of identities as this has all been completed successfully.

ziti edge create config golang-host.v1 host.v1 '{"protocol":"tcp", "address":"localhost","port":22, "listenOptions": {"bindUsingEdgeIdentity":true}}'

ziti edge create service golang-zssh --configs golang-host.v1

ziti edge create service-policy golang-zssh-binding Bind --service-roles '@golang-zssh' --identity-roles '@golang.http.server'

ziti edge create service-policy golang-zssh-dialing Dial --service-roles '@golang-zssh' --identity-roles '@golang.http.ssh.client'

> policy advisor  
> I have run this for both identities and services.. no problems were identified

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 7:41am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/4 "2022-04-13T07:41:06Z")

</div>

This is what was returned when I put the zssh into debug

zssh opc@ip -d -s golang-zssh -c …json -i … key  
INFO username set to: opc  
INFO targetIdentity set to: ip  
INFO connection to edge router using api session token 7d0bb8be-1411-4652-825b-4c7d1c7aaf63  
**FATAL error when dialing service name golang-zssh. unable to dial service** ‘golang-zssh’: dial failed: service WufXhXoAg has no terminators for identity ip

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 7:42am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/5 "2022-04-13T07:42:16Z")

</div>

I know the terminator exists because I can see it in ZAC

 ![Screen Shot 2022-04-13 at 5.41.55 pm](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/95174d2e5e430db53176403444e048789dd80bcf.png)

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 13, 2022, 10:18am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/6 "2022-04-13T10:18:55Z")

</div>

> INFO targetIdentity set to: ip

Do you have an identity named "ip"? When you use zssh, you will need to provide the name of the identity as the target. Looking at the commands you ran from above - would expect you to issue this zssh:

```auto
zssh opc@golang.http.server -d -s golang-zssh -c …json -i … key

```

you are instructing zssh to dial the identity named 'ip' in your example. I think you want to tell it to dial the identity named "golang.http.server" instead.

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 13, 2022, 10:24am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/7 "2022-04-13T10:24:33Z")

</div>

> [@markamind](#):
>
> dial failed: service WufXhXoAg has no terminators for identity ip

further proof is provided in that message. In my experience (and I have a lot of this experience because this is a particularly common problem) if you are seeing a "no terminators" message it means:

1. you somehow are instructing openziti to dial the wrong identity
2. the identity you correctly specified is actually not online

In this case it's both of these are true. Because you're using the wrong identity in the command - that identity is offline and has no terminators... Makes sense but - it's not "smacking you in the face" obvious what that error means.

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 11:05am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/8 "2022-04-13T11:05:05Z")

</div>

brilliant.. that has provided some selleys to fill in a few more gaps.

I fixed the dialing of the identity.. but still unable to work out how to debug the terminator..

> FATAL error when dialing service name golang-zssh. unable to dial service 'golang-zssh': dial failed: service WufXhXoAg has no terminators for identity golang.http.server

How do you create one..?

I think I have something wrong.. as I am unsure what you need to have configured on the server...

I could not work this bit out.. I have the app installed on the client... but what do you need installed on the server..?

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 11:17am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/9 "2022-04-13T11:17:52Z")

</div>

I am taking a closer look through this video… I think my problem starts at 35.40… I am not 100% sure what to enter in those fields

[![](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/6c9c11af7c40dd243aad4948ce9d5b43ecee17da.jpeg "SSH Safety without a Public Bastion") ](https://www.youtube.com/watch?v=oSlwZcwZcsU)

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 11:28am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/10 "2022-04-13T11:28:40Z")

</div>

I think I have it… just need another 20 min… watch this space.

What twigged for me… was the need for a separate identity for the server… so almost there

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 13, 2022, 11:57am UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/11 "2022-04-13T11:57:08Z")

</div>

> [@markamind](#):
>
> need for a separate identity for the server

You definitely don't 'need' a different identity. I abuse my identities all the time (using them in different apps just like you are doing before "cleaning up" by making a better/more accurately named identity)

You will not need to create a terminator manually. The `ziti-edge-tunnel` you run on the target zssh server machine will do that on your behalf. That's actually what the "bind" configuration does....

#### how that bind config is working

when you run ziti-edge-tunnel, it **is** an OpenZiti sdk-based application. As we wrote it - it knows to look for those pre-installed **config types** (intercept.v1/host.v1/etc). In this case it needs to find a "host.v1" config with "bindUsingEdgeIdentity=true". When it finds this config on a given service - like 'zssh' - then the ziti-edge-tunnel will make a "dynamic terminator" for you when the tunneller binds that service... So by simply running `ziti-edge-tunnel` with a known identity, and giving that identity "bind" access to a service, when the `ziti-edge-tunnel` comes online you'll see a terminator manifest...

If the terminator is binding "as the identity" you'll see the identity name listed:

```bash
ziti edge list terminators
id: 7G1P service: kubeA.prometheus.svc router: ip-172-31-42-64-edge-router binding: edge address: hosted:3e2a3840-7ee4-4f30-8b50-af8abf17b007 identity: kubeA.prometheus cost: 0 precedence: default dynamic-cost: 2

```

Here you can see my identity that was bound is `identity: kubeA.prometheus`

If I turn off that application - the terminator will be removed.

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 12:13pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/12 "2022-04-13T12:13:47Z")

</div>

Still getting a bit stuck… for some reason… when I enroll an identity… it does not show up as enrolled in ZAC… its worked for everything else… so not sure what I am doing wrong… it says it was successful… and the JSON file was created… but its not showing a green dot?

Any tips?

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 12:23pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/13 "2022-04-13T12:23:01Z")

</div>

getting closer… I realised that both identities have been successfully resolved… though I am still getting issues with the terminator… will keep you posted

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 12:26pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/14 "2022-04-13T12:26:07Z")

</div>

This is the error

> error when dialing service name ssh\_server. unable to dial service 'ssh\_server': dial failed: service QOFOXnUf8h has no terminators

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 13, 2022, 12:28pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/15 "2022-04-13T12:28:26Z")

</div>

> [@markamind](#):
>
> but its not showing a green dot?

That indicates it's got an API Session / Session. API session means it's been online in the last "n" minutes (depending on what your config is like, 10m I think is the default). Session means it's sent some kind of traffic (#1 below). If the identity isn't being used they will show up as grey. (#2 below)

 ![image](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/4a2f4a58f897dc13572b6d5d0da835054a18da35.png)

To see if it's been enrolled look at the 'token' column (#3 above)

I see you have made a new service: `ssh_server`. Does this serivce have a config associated to it? Does that config use "bindUsingEdgeIdentity"? Is the `ziti-edge-tunnel` running using that identity?

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 12:32pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/16 "2022-04-13T12:32:25Z")

</div>

I created the config via ZAC… and tried do the same as in the video… I did not see any option to select “bindUsingEdgeIdentity

Also… I am not sure how to check if `ziti-edge-tunnel` is running

Is this another step… I may have missed this in the video

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [April 13, 2022, 12:33pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/17 "2022-04-13T12:33:15Z")

</div>

AAAhhhh. Sometimes the ZAC needs, let’s say, “encouragement” to add a new feature… Things can get missed. I betcha that’s the problem.

Make the service with the ziti cli for now and see

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 12:33pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/18 "2022-04-13T12:33:19Z")

</div>

ahh… so you use ziti-edge-tunnel to enrol the server identity

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 12:40pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/19 "2022-04-13T12:40:33Z")

</div>

> [@markamind](#):
>
> ziti-edge-tunne

found it...

> > this is what I am missing.. so I download this on the server.. and use this to enroll the server identity

> **[Releases · openziti/ziti-tunnel-sdk-c](https://github.com/openziti/ziti-tunnel-sdk-c/releases)**
>
> Contribute to openziti/ziti-tunnel-sdk-c development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![markamind](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/markamind/32/157_2.png) [@markamind](https://openziti.discourse.group/u/markamind)\
**Post date:** [April 13, 2022, 1:01pm UTC](https://openziti.discourse.group/t/openziti-and-terminators/400/20 "2022-04-13T13:01:20Z")

</div>

I missed quite a few things… but now have my terminator… but for some reason its not connected to the ssh\_server service…

steps missed were

1. download and install the ziti tunneller on the server

2. use the following command to enroll the server identity

sudo ./ziti-edge-tunnel enroll --jwt ssh\_server.jwt --identity ./ssh\_server.json

1. use the following command to run the tunneller service

sudo ./ziti-edge-tunnel run --identity ./ssh\_server.json

 ![Screen Shot 2022-04-13 at 10.57.33 pm](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/1X/37e339103c1891489261bf007c5db7d4119374cd.png)

However… I am still missing something

FATAL error when dialing service name ssh\_server. unable to dial service ‘ssh\_server’: dial failed: service QOFOXnUf8h has no terminators for identity ssh.client.ziti

[Next page](https://openziti.discourse.group/t/openziti-and-terminators/400.md?page=2)
