Skip to content
You're viewing the v2 docs. Looking for v1?Go to v1 docs
Docs
Testsigma
Popular questions
↑↓ to navigate↵ to selectesc to close
Book a demo

Testsigma Tunnel

Testsigma Tunnel runs tests against a private server URL or a locally hosted application, using the operating systems, browsers, and screen resolutions available in Testsigma’s cloud. It opens a secure connection from your machine to Testsigma over WebSocket, HTTPS, and SSH, so a corporate firewall or proxy does not have to be opened up, and no public internet access is needed.

Five parts make up the connection.

ComponentWhat it does
Testsigma Tunnel ClientThe binary you install on a machine that can reach your application. It authenticates with the key you supply when it starts
Authentication ServerProcesses the client’s authentication request and assigns it a tunnel connect server
Testsigma Tunnel ServerA virtual machine or container in a Testsigma data center. It carries an HTTP and TCP proxy that forwards requests from test executors, and the TCP server the client connects to
REST API client or browserThe automation environment, which uses the tunnel server as its proxy
Remote addressThe server URL you are testing, whether localhost, a privately hosted site, or a public one

The tunnel client inside your network connecting through the API gateway to the auth and proxy servers, which drive the browser VMs

The client holds a bidirectional tunnel open between Testsigma and the remote address.

RequirementSpecification
Operating systemWindows XP or later, macOS 10.10 or later, or Ubuntu 12.04 or later
CPUx64, or ARM in 32-bit and 64-bit
Memory2 GB or more
Disk space100 MB free to install, 500 MB recommended
NetworkA stable internet connection
FirewallNothing restricting the client’s outbound traffic. The tunnel accepts no inbound connections, so no ingress rule is needed

Go to Settings > Testsigma Tunnel, which walks through 3 steps: install the tunnel, run it in a terminal, and verify the connection.

Click the Download icon beside Documentation Link and select your platform and architecture. Mac, Windows, Linux, Debian, and RPM each offer amd64 and arm64; Docker links to its own instructions. Or take the direct download for your machine:

Platformamd64arm64
macOS
Windows
Linux
Debian
RPM

The authentication key comes from Settings > API Keys.

  1. Extract the ZIP to a directory of your choice.

  2. Go to that directory and start the client, passing the key on the command line:

    Terminal window
    ./TestsigmaTunnel --key="<API_KEY>" --tunnel-name "<TUNNEL_NAME>"

Or set the key and the other parameters in the args.yaml file beside the binary, then start it with ./TestsigmaTunnel:

key: "<your-authentication-key>"
tunnel-name: ""
connections: 10
inactive-timeout: 300
verbose: false

The client prints a success message and the tunnel name when it starts. Use that name when you set up a live or automated test. Press Ctrl+C to stop it.

The binary takes the same 5 settings on macOS, Windows, and Linux, as command-line flags or in args.yaml. Docker passes them as environment variables, and Kubernetes as Helm values.

SettingDefaultWhat it does
keyYour authentication key, from Settings > API Keys
tunnel-nameGeneratedThe name you reference when running tests
connections10Connections the client establishes
inactive-timeout300Seconds of inactivity before the tunnel closes
verbosefalseDebug logging

For an automated test, open the test case, click Run, select the Test Lab and Test Machine in the Ad-Hoc Run overlay, click Desired Capabilities, and add the tunnel name:

KeyData typeValue
testsigmaLab.tunnelNameString<tunnel_name>

The Desired Capabilities section with testsigmaLab.tunnelName set to a tunnel name

For live REST API testing, open the REST API step, go to Settings, and enter the tunnel name in Tunnel Name.

The Settings tab of a REST API step, with the Testsigma Connect Tunnel name field

Why can’t a cloud device reach my application?

Section titled “Why can’t a cloud device reach my application?”

Cloud labs run outside your network, so an application on a local development server is unreachable through a proxy, a VPN, or a firewall. To check, open the application URL on a workstation outside your company network, without a VPN. If it loads there, cloud devices can run against it. If it does not, use the tunnel, or run on local devices instead.

Do I need to whitelist Testsigma’s IP addresses?

Section titled “Do I need to whitelist Testsigma’s IP addresses?”

Not for the tunnel. It opens an outbound connection and accepts none inbound, so no ingress rule is needed. Whitelisting is a separate route that works for an internet-reachable application but cannot reach a locally hosted one.

Why does my test go to the cloud when the tunnel is running?

Section titled “Why does my test go to the cloud when the tunnel is running?”

The tunnel name is missing from the run. Add testsigmaLab.tunnelName under Desired Capabilities, or enter the name in the REST API step’s Settings.

tunnel-name was left empty, so the client generates one at startup. Set it in args.yaml, on the command line, or through tunnel.tunnelName on Kubernetes.

Was this page helpful?