Tools
SSH Cheat Sheet — Keys, Connections, and Tunnels
SSH is how you reach remote machines securely. This reference covers connecting, key management, the config file that saves you typing, and tunnelling.
Put it into practice with the matching tool.
Calculate chmod permissions →Advertisement
Connecting
ssh user@hostConnect to a hostssh -p 2222 user@hostUse a non-default portssh -i ~/.ssh/key user@hostUse a specific private keyssh user@host "ls -la"Run one command and exitssh -v user@hostVerbose — the first step when debuggingssh -A user@hostForward your agent — use only on hosts you trustssh -J jump@bastion user@hostConnect through a jump host~.Type this on a new line to kill a frozen sessionKeys
ssh-keygen -t ed25519 -C "[email protected]"Generate a modern key pairssh-keygen -t rsa -b 4096RSA, for systems that do not support ed25519ssh-copy-id user@hostInstall your public key on the serverssh-keygen -p -f ~/.ssh/id_ed25519Change a key's passphrasessh-keygen -l -f key.pubShow a key's fingerprintssh-keygen -y -f key > key.pubRecover the public key from a private keyssh-add ~/.ssh/id_ed25519Add a key to the running agentssh-add -lList keys the agent currently holds~/.ssh/config
Host myserverA short alias — then just: ssh myserver HostName 203.0.113.10The real address User deployDefault username Port 2222Default port IdentityFile ~/.ssh/deploy_keyKey to use for this host ProxyJump bastionAlways connect via a jump host ServerAliveInterval 60Keep idle connections from droppingHost *Settings applied to every hostPort forwarding
-L 8080:localhost:80Local — reach a remote service at localhost:8080-L 5432:db.internal:5432Reach a database only the server can see-R 9000:localhost:3000Remote — expose your local port on the server-D 1080Dynamic — a SOCKS proxy through the server-NNo remote command — tunnel only-fDrop into the background once connectedCopying files
scp file user@host:/path/Copy a file to the serverscp user@host:/path/file .Copy a file from the serverscp -r dir user@host:/path/Copy a directoryrsync -avz dir/ user@host:/path/Sync — faster and resumablersync -avz --delete src/ host:/dst/Mirror, removing files deleted locallysftp user@hostInteractive file transfer sessionPermissions & troubleshooting
chmod 700 ~/.sshSSH refuses to work if this is too openchmod 600 ~/.ssh/id_ed25519Private keys must not be group/world readablechmod 644 ~/.ssh/authorized_keysPublic key list on the serverssh-keygen -R hostRemove a stale host key after a rebuildPermission denied (publickey)Key not installed, wrong key, or bad permissions