Remote debug of a Java App using SSH tunneling (without opening server ports)

Sometimes production code misbehave and it’s complex to replicate the same conditions on test/stage environment. We have almost all ports of our server closed (as it should be), so IMHO the best option is to open a ssh tunnel.

This is my receipt:

On the server I start the java virtual machine with debug parameters:

java -Xdebug -Xrunjdwp:transport=dt_socket,server=y,address=9000 \
  -jar myproduct-jar-with-dependencies.jar &> console.out &

You can check the VM is listen to connections using netstat:

$ netstat -an | grep LISTEN
tcp*   LISTEN
tcp*   LISTEN
tcp*   LISTEN
tcp*   LISTEN
tcp*   LISTEN
tcp   :::80           :::*        LISTEN
tcp   :::22           :::*        LISTEN

On the development machine I open the tunnel with the server, having only SSH(22) port opened

ssh -f [email protected] -L 9000: -N

The -L parameter is a little bit confusing, the syntax is -L <local-port>:<remote-host>:<remote-port> so basically what we are doing here is saying:

  1. Listen on local (develop machine) port 9000
  2. Forward any connection to localhost, port 9000 of the remote machine (server)

Now everything is configured you can attach your IDE to remote server:

  1. Open your Eclipse
  2. Go to Run > Debug Configurations
  3. Create a new Remote Java Application
  4. Configure Host: localhost and Port: 9000 Debug Configurations
  5. Hit Debug button
  6. When you finish your job, just disconnect Eclipse Disconnect Button

Happy Debugging!


Gustavo Arjones

Always Learning, Geek, Curious