elefcode
← All cheat sheets

Tools

SSH Cheat Sheet — Keys, Connections, and Tunnels

SSH is how you reach remote machines securely. This reference covers connecting, key management, the config file that saves you typing, and tunnelling.

Put it into practice with the matching tool.

Calculate chmod permissions →

Advertisement

Connecting

ssh user@hostConnect to a host
ssh -p 2222 user@hostUse a non-default port
ssh -i ~/.ssh/key user@hostUse a specific private key
ssh user@host "ls -la"Run one command and exit
ssh -v user@hostVerbose — the first step when debugging
ssh -A user@hostForward your agent — use only on hosts you trust
ssh -J jump@bastion user@hostConnect through a jump host
~.Type this on a new line to kill a frozen session

Keys

ssh-keygen -t ed25519 -C "[email protected]"Generate a modern key pair
ssh-keygen -t rsa -b 4096RSA, for systems that do not support ed25519
ssh-copy-id user@hostInstall your public key on the server
ssh-keygen -p -f ~/.ssh/id_ed25519Change a key's passphrase
ssh-keygen -l -f key.pubShow a key's fingerprint
ssh-keygen -y -f key > key.pubRecover the public key from a private key
ssh-add ~/.ssh/id_ed25519Add a key to the running agent
ssh-add -lList keys the agent currently holds

~/.ssh/config

Host myserverA short alias — then just: ssh myserver
HostName 203.0.113.10The real address
User deployDefault username
Port 2222Default port
IdentityFile ~/.ssh/deploy_keyKey to use for this host
ProxyJump bastionAlways connect via a jump host
ServerAliveInterval 60Keep idle connections from dropping
Host *Settings applied to every host

Port forwarding

-L 8080:localhost:80Local — reach a remote service at localhost:8080
-L 5432:db.internal:5432Reach a database only the server can see
-R 9000:localhost:3000Remote — expose your local port on the server
-D 1080Dynamic — a SOCKS proxy through the server
-NNo remote command — tunnel only
-fDrop into the background once connected

Copying files

scp file user@host:/path/Copy a file to the server
scp user@host:/path/file .Copy a file from the server
scp -r dir user@host:/path/Copy a directory
rsync -avz dir/ user@host:/path/Sync — faster and resumable
rsync -avz --delete src/ host:/dst/Mirror, removing files deleted locally
sftp user@hostInteractive file transfer session

Permissions & troubleshooting

chmod 700 ~/.sshSSH refuses to work if this is too open
chmod 600 ~/.ssh/id_ed25519Private keys must not be group/world readable
chmod 644 ~/.ssh/authorized_keysPublic key list on the server
ssh-keygen -R hostRemove a stale host key after a rebuild
Permission denied (publickey)Key not installed, wrong key, or bad permissions

More cheat sheets