BEAM · CONNECTORS

Reach private databases and servers without opening a port.

A connector runs inside your network and dials out to Zaysa. Your team gets approved, time-bound access to what sits behind it, and nothing is exposed to the internet.

On every plan · Free includes 1

THE USUAL WAY

Private databases and servers, without the usual risks

Most teams reach private systems through an open port, a shared password and access nobody remembers to remove.

bastion · port 22 open to 0.0.0.0/0

A jump host listens on the internet.

DB_PASSWORD shared in #ops

One database password, pasted in chat, used by everyone.

ex-contractor · SSH key still works

Access is rarely removed when people leave.

who ran DROP TABLE?

No clear record of who connected to what.

Time-bound access for your team is on the Pro plan. See plans

What you are seeing
  1. 01Your network stays closed
  2. 02Paste one command
  3. 03It dials out
  4. 04Every command is signed
  5. 05Secrets sealed for this connector
  6. 06Approved access gets a ticket
  7. 07Access ends on its own

Example data.

How it works

Live in three steps

01

Add a connector

In Beam → Connectors, choose what it reaches first, name it after where it runs, then create it.

Add connectorBeam → Connectors
Database
VM (SSH)
Kubernetes
OpenShift
Name prod-vpc
Create →

Example data.

02

Run one command

Copy the command and paste it on a Linux machine with curl and root or sudo.

Linux machineprod-vpc
$ curl … BEAM_TOKEN=bmc_•••• … sh
connecting... online
●Waiting for "prod-vpc" to dial in…

Example data.

03

Add what it should reach

Add databases and servers to the same connector without reinstalling it.

prod-vpc● Online
Add databaseAdd SSHAdd K8s
│
orders-db
│
app-01
│
prod-cluster

Example data.

Outbound by design

Nothing listens on the internet

The connector opens outbound HTTPS on port 443 to zaysa.io. No inbound port or public IP is needed.

Internet
Your network
prod-vpc
10.0.0.0/8
Zaysa
outbound HTTPS · 443 ✓

Example data.

Enforced on the connector

Security you can check

Commands are signed and expire. The connector enforces its policy on every request, whoever sends it.

Command envelope15 min
kind: add-database
signature: Ed25519 ✓
expires: 15 min
used: once

Each installer pins Zaysa's public key.

Example data.

One container

What runs on your machine

The installer sets up one container that keeps its identity and attached targets when you run the command again to update.

Example install command · replace the placeholders in Zaysa
curl -fsSL https://zaysa.io/api/beam/install | BEAM_TOKEN=bmc_<your-token> BEAM_CONNECTOR_ID=<connector-id> BEAM_COMMAND_PUBKEY=<command-key> sh

Treat BEAM_TOKEN like a password.

On your machineWhat the installer sets up
RuntimePodman if present; Docker only when no runtime is found, using the system package manager first.
Token/etc/beam/token · readable only by the connector, not an environment variable.
Policy/etc/beam/policy.env · limits targets and capabilities on every request.
Imagezaysahq/beam-connector:1.0.4@sha256:b970d0f0…
Restartbeam-connector.service with systemd, or a self-restarting container.

Example data.

Attach targets later

One connector for the whole network

Add databases and servers to one connector later without reinstalling.

Free includes 1 connector, Pro 5, Business unlimited.

prod-vpc● Online
PostgreSQL
MySQL
MongoDB
Redis
SSH server
Kubernetes
OpenShift

Example data.

ON EVERY PLAN · ACCESS ON PRO

Private access your team can ask for

Free includes 1 connector, Pro 5, Business unlimited.

Connectors

Available on every plan for private targets.

Time-bound access

Team members can ask for access on Pro.

Database, SSH and Kubernetes access

Reach private systems without an inbound port.

Access Map

Review grants on Business.

Questions

Frequently asked questions

No. The connector opens outbound HTTPS on port 443 to zaysa.io. No inbound port or public IP is needed.

More in Beam

See what you run, and what it costs.

Free plan, no card needed.