Browse and search documentation

Bastion and remote access

Start ChronoTerminal or a managed connection from a specific asset, complete MFA and review session, account and recording state.

For: Host operators and account administratorsReviewed:
On this page

Choose a connection path

Remote connect from the asset list prefers an available managed SSH account. If no account is available and the Agent is online, the Agent terminal can be used. Target, account and authorization checks still apply to every connection.

PathPrerequisites
Managed SSHA registered system account, reachable target and appropriate access; an online Agent is not required
Agent terminalAn online target Agent and resource-specific connection permission
File transfer or remote desktopThe relevant protocol, managed account, target environment and access are ready

Register the first Linux account

  1. An account and credential administrator opens Remote connect on the target asset, or Account management → System accounts → Register account.
  2. Verify the exact host, then enter the actual username and password or private key in the dedicated form, never in notes, URLs or tickets.
  3. Follow the connectivity and account-registration steps. The platform handles standard address selection and connection setup; an administrator handles nonstandard ports or networks explicitly.
  4. If the host fingerprint changes, verify a reinstall or replacement with the host owner before replacing existing trust.

Start and end a session

  1. Select the target and available connection method, then check host identity, project and account.
  2. Complete recent MFA. Environments with additional access policies may require approval; follow progress in the same session instead of submitting duplicates.
  3. Work in ChronoTerminal after connecting. Selection copy, native paste and in-session search support daily use; review pasted content and the target first.
  4. Exit when finished and confirm the session has ended. Reconnect through the normal flow after idle timeout or authorization expiry rather than reusing expired access.

Understand session records

Recording required describes a policy, not an existing recording. A session ending before connection may have no recording. Playback also depends on saved data and separate playback access.

File transfer, desktops and databases have protocol-specific limits. A structured read-only database workspace is not arbitrary SQL access or a full database client; use the operations actually provided.

Something differs from your environment?

Send your deployment version, page and a redacted description so we can investigate and update the guide.

weiwendi@aiops.red