Skip to content
Glossary

Glossary

The words den uses, in one line each, with the page that explains them.

Bastion. The EC2 instance inside the private network that a tunnel goes through: den’s SSM transport forwards through it (ec2_instance_id), and an ssh transport uses a bastion host. See Environments.

den.lock. The file beside den.yaml that pins each runbook source to a commit. den runbook source sync checks out exactly those commits. See Runbook sources.

Engine. Two things share the word. In den’s code, the part of a tunnel that is specific to a store: where to forward, which credential to mint and how the user connects. In den.yaml, the engine: key of an RDS service, postgres or mysql, which picks the port the token is signed for, the client and where the token goes. See RDS.

Environment. A named set of connection settings (bastion, profiles, region) under environments:, which services and runbooks refer to with env:. See Environments.

Health check. A probe that proves traffic reaches the far side, rather than that something listens locally. For a tunnel, a host:port dialled through its SOCKS proxy; for a VPN, a host:port reachable only over it. See Tunnel and VPN.

IAM token. The short-lived credential den mints for a data store in place of a password (15 minutes for RDS, ElastiCache and MemoryDB). See Security model.

MCP. The Model Context Protocol. den mcp serves den to AI agents over it, so an agent can list services and open tunnels without ever seeing a credential. See den mcp.

Pane (panel). One of the screens in den’s left menu: Connect, Tunnel, Runbooks, AWS, VPN, Secrets, Create Env, Config, Help, Updates and Logs. h or ? lists the keys of the one you are in. See Shortcuts.

Runbook. A script of yours, in a folder with a runbook.yaml, that den runs with your AWS profile, region and live tunnel ports (DEN_PORT_*) already set. See Runbooks.

Sequence. Named runbooks run in order, stopping at the first failure. See Runbooks.

Service. Anything you connect from the Connect panel: a data store reached through a tunnel, or a Docker Compose stack. Declared under services:. See Configuration reference.

Source. A git repository of runbook folders, declared under runbooks.sources, whose runbooks appear as <source>/<name>. See Runbook sources.

SSO session. An [sso-session X] section of ~/.aws/config. Logging in to it authenticates every profile that uses it. See AWS SSO.

Token refresh. den re-mints an IAM token before it expires (every 13 minutes for a 15-minute token) and writes it where the client reads it. r mints one now. See RDS.

Transport. How den reaches the private network a service lives in: ssm (the default, a port-forward through the bastion), ssh, eice (an EC2 Instance Connect Endpoint) or kubectl. See Transports.

Trust. den’s memory of which runbooks from a source you have run, by the git tree of their folder. A new or changed runbook asks before it runs. See Runbook sources.

Tunnel. A local port that forwards to a private host. Every data store service is one, opened with an SSM port-forward and kept alive by den (readiness check, credential refresh, reconnect). tunnels: in den.yaml is the other kind, an SSH or SOCKS command you write. See Transports and Tunnel.

Last updated on