feat(managed-ne): add bastion SSH protocol proxy hop type

Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-06-05 10:47:52 +08:00
parent e62f4f2c74
commit d3d7f62a02
15 changed files with 348 additions and 19 deletions

View file

@ -195,11 +195,21 @@ const en = {
huawei: "Huawei device (CLI jump)",
cisco: "Cisco device (CLI jump)",
linux: "Linux server (SSH tunnel)",
bastion: "Bastion host (SSH protocol proxy)",
},
zteHint: "Run ssh/telnet on the ZTE device to reach the target; target credentials use secondary auth.",
huaweiHint: "Run telnet / stelnet (SSH) on the Huawei hop; stelnet is SSH. Target credentials use secondary auth.",
ciscoHint: "Run Cisco ssh -vrf / telnet /vrf jump commands; target credentials use secondary auth.",
linuxHint: "SSH to the Linux bastion, then direct-tcpip tunnel to target IP:port (ProxyJump-style).",
bastionHint:
"SSH with composite username via bastion protocol proxy. Example: user@account@target_ip@bastion_host; password is the bastion/Vault password. JumpServer/CBH often use port 2222.",
targetAuthMode: "Target credentials",
targetAuthBastionManaged: "Bastion-managed (target password optional)",
targetAuthManual: "Manual (secondary auth after connect)",
targetAuthHint: "Bastion-managed needs only bastion password; manual mode requires target NE password.",
usernameTemplate: "SSH username template",
templateHintBastion:
"Default {hop_user}@{target_user}@{target_ip}@{hop_host}. Same when left blank.",
host: "Jump host",
port: "Jump port",
protocol: "Jump protocol",
@ -221,6 +231,7 @@ const en = {
huawei: "Huawei hop",
cisco: "Cisco hop",
linux: "Linux hop",
bastion: "Bastion",
},
hostRequired: "Jump host is required",
userRequired: "Jump username is required",

View file

@ -193,11 +193,21 @@ const zh = {
huawei: "华为设备(CLI 跳登)",
cisco: "思科设备(CLI 跳登)",
linux: "Linux 服务器(SSH 隧道)",
bastion: "堡垒机(SSH 协议代理)",
},
zteHint: "在 ZTE 设备上执行 ssh/telnet 命令跳转到目标,目标账号由二次认证输入。",
huaweiHint: "在华为设备上执行 telnet / stelnet(SSH)跳登;stelnet 即 SSH。目标账号由二次认证输入。",
ciscoHint: "在思科设备上执行 ssh -vrf / telnet /vrf 跳登,目标账号由二次认证输入。",
linuxHint: "先 SSH 登录 Linux 跳板,经 direct-tcpip 隧道连接目标 IP:端口(等同 ProxyJump)。",
bastionHint:
"SSH 复合用户名直连堡垒机,由堡垒机协议代理到目标。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27;密码为 Vault/堡垒机密码。JumpServer/CBH 常用端口 2222。",
targetAuthMode: "目标凭据",
targetAuthBastionManaged: "堡垒机托管(目标密码可留空)",
targetAuthManual: "手动输入(连接后二次认证)",
targetAuthHint: "堡垒机托管时仅需堡垒机密码;手动模式需填写目标网元密码。",
usernameTemplate: "SSH 用户名模板",
templateHintBastion:
"默认 {hop_user}@{target_user}@{target_ip}@{hop_host}。留空时后端同样规则。示例:ZTE-TSM@ca-oper@114.0.44.11@10.34.145.27。",
host: "跳板地址",
port: "跳板端口",
protocol: "跳板协议",
@ -219,6 +229,7 @@ const zh = {
huawei: "华为跳板",
cisco: "思科跳板",
linux: "Linux跳板",
bastion: "堡垒机",
},
hostRequired: "请填写跳板地址",
userRequired: "请填写跳板用户名",