| | |

LFCA 51 ๐Ÿง Connecting with SSH

The previous chapter explained what SSH is โ€” the protocol, the encryption, the key pairs, and the configuration. This chapter is about the everyday use: the commands that connect to a remote host, move files, run remote commands, forward ports, and copy keys. The ssh command is the entry point, and the scp, sftp, and rsync are the tools that build on it. The ~/.ssh/config file is the way to make the connections convenient โ€” the aliases, the per-host settings, the jump hosts, and the key files. This chapter covers the practical’s side: the ssh‘s syntax and options, the remote command’s execution, the scp‘s and the sftp‘s, the rsync‘s over the SSH, the agent’s forwarding, the ssh-keygen‘s and the ssh-copy-id‘s, the ProxyJump, the ControlMaster‘s connection’s reuse, and the patterns that make the remote work efficient. It builds on LFCA 50 and prepares the ground for the more advanced’s SSH’s material.

Key point: The ssh user@host is the basic’s, and the -p, the -i, the -L, the -R, the -D, the -J, the -v are the common’s options. The ssh user@host 'command' runs the command’s on the remote’s and returns the output’s. The scp is the SCP’s, and the sftp is the SFTP’s, and the rsync‘s is the delta’s. The ~/.ssh/config‘s is the alias’s, and the Host, the HostName, the User, the Port, the IdentityFile, the ProxyJump, the ForwardAgent, the ControlMaster, the ControlPath, the ControlPersist are the common’s. The ControlMaster‘s is the connection’s reuse’s, and the reuse’s is the performance’s. The ProxyJump‘s is the bastion’s, and the bastion’s is the internal’s. The ssh-copy-id‘s is the public’s key’s copy’s, and the copy’s is the passwordless’s.


The ssh‘s basic usage

The ssh user@host is the basic’s, and the basic’s is the connection’s.

ssh user@example.com
# The password's prompt, or the key's authentication.

The ssh user@example.com is the basic’s, and the basic’s is the connection’s. The user is the remote’s, and the example.com is the host’s. The two are the pair, and the pair is the connection’s.

Why the ssh‘s basic matters. The ssh‘s basic is the entry’s, and the entry’s is the first’s. The user@host is the pattern’s, and the pattern’s is the universal’s. The two are the pair, and the pair is the design’s.

The user’s omission. The ssh example.com omits the user, and the omitted’s is the local’s. The SSH uses the local’s username, and the local’s is the default’s.

ssh example.com  # the local's username

The ssh example.com is the omitted’s, and the omitted’s is the local’s. The two are the pair, and the pair is the convenience’s.

The port’s option. The ssh -p 2222 user@example.com is the port’s, and the port’s is the non-default’s.

ssh -p 2222 user@example.com

The ssh -p 2222 is the port’s, and the port’s is the 22’s alternative’s. The two are the pair, and the pair is the specific’s.

Why the port’s option matters. The port’s option is the non-default’s, and the non-default’s is the security’s. The 2222’s is the common’s, and the common’s is the hardening’s. The two are the pair, and the pair is the design’s.

The key’s option. The ssh -i ~/.ssh/id_ed25519 user@example.com is the key’s, and the key’s is the specific’s.

ssh -i ~/.ssh/id_ed25519 user@example.com

The ssh -i ~/.ssh/id_ed25519 is the key’s, and the key’s is the specific’s. The two are the pair, and the pair is the pattern’s.

Why the key’s option matters. The key’s option is the multi-key’s, and the multi-key’s is the common’s. The -i is the specific’s, and the specific’s is the choice’s. The two are the pair, and the pair is the design’s.

The verbose’s option. The ssh -v user@example.com is the verbose’s, and the verbose’s is the debug’s.

ssh -v user@example.com
# The debug's output.

The ssh -v user@example.com is the verbose’s, and the verbose’s is the debug’s. The -v, the -vv, the -vvv are the three, and the three are the detail’s. The two are the pair, and the pair is the diagnosis’s.

Why the verbose’s option matters. The verbose’s option is the debug’s, and the debug’s is the diagnosis’s. The -v is the connection’s, and the connection’s is the handshake’s. The two are the pair, and the pair is the pattern’s.

The identity’s option. The ssh -o IdentityFile=~/.ssh/id_ed25519 user@example.com is the identity’s, and the identity’s is the -o‘s.

ssh -o IdentityFile=~/.ssh/id_ed25519 user@example.com

The ssh -o IdentityFile=... is the identity’s, and the identity’s is the -o‘s. The two are the pair, and the pair is the pattern’s.

Why the -o‘s matters. The -o‘s is the arbitrary’s, and the arbitrary’s is the config’s. The -o‘s is the per-command’s, and the per-command’s is the specific’s. The two are the pair, and the pair is the design’s.


The remote command’s execution

The ssh user@host 'command' runs the command’s on the remote’s and returns the output’s.

ssh user@example.com 'uptime'
# 10:50:12 up 3 days,  2 users,  load average: 0.15, 0.10, 0.05

The ssh user@example.com 'uptime' is the remote’s, and the remote’s is the command’s. The uptime is the command’s, and the command’s is the remote’s. The two are the pair, and the pair is the pattern’s.

Why the remote command matters. The remote command is the automation’s, and the automation’s is the script’s. The remote command’s is the single’s, and the single’s is the fast’s. The two are the pair, and the pair is the design’s.

The command’s multiple. The ssh user@host 'cmd1; cmd2' is the multiple’s, and the multiple’s is the sequence’s.

ssh user@example.com 'cd /var/log && tail -n 20 syslog'

The ssh user@example.com 'cd /var/log && tail -n 20 syslog' is the multiple’s, and the multiple’s is the sequence’s. The two are the pair, and the pair is the pattern’s.

Why the command’s multiple matters. The command’s multiple is the sequence’s, and the sequence’s is the &&‘s or the ;‘s. The && is the conditional’s, and the ; is the unconditional’s. The two are the pair, and the pair is the design’s.

The command’s quoting. The ssh user@host 'echo "$HOME"' is the remote’s, and the remote’s is the single-quote’s.

ssh user@example.com 'echo "$HOME"'
# /home/user

The ssh user@example.com 'echo "$HOME"' is the remote’s, and the remote’s is the single-quote’s. The double-quote’s is the local’s, and the local’s is the interpolation’s. The two are the pair, and the pair is the distinction’s.

Why the quoting matters. The quoting is the local’s, and the local’s is the shell’s. The single-quote’s is the literal’s, and the double-quote’s is the local’s. The two are the pair, and the pair is the design’s.

The command’s heredoc. The ssh user@host << 'EOF' ... EOF is the heredoc’s, and the heredoc’s is the multi-line’s.

ssh user@example.com << 'EOF'
cd /var/log
tail -n 20 syslog
EOF

The ssh user@example.com << 'EOF' ... EOF is the heredoc’s, and the heredoc’s is the multi-line’s. The two are the pair, and the pair is the pattern’s.

Why the heredoc matters. The heredoc is the multi-line’s, and the multi-line’s is the readable’s. The 'EOF'‘s is the single-quote’s, and the single-quote’s is the local’s interpolation’s prevention’s. The two are the pair, and the pair is the design’s.

The command’s the no-tty’s. The ssh -T user@host is the no-tty’s, and the no-tty’s is the non-interactive’s.

ssh -T user@example.com 'ls -la'

The ssh -T is the no-tty’s, and the no-tty’s is the non-interactive’s. The two are the pair, and the pair is the pattern’s.

Why the no-tty matters. The no-tty is the non-interactive’s, and the non-interactive’s is the script’s. The -T is the no-allocate’s, and the no-allocate’s is the script’s. The two are the pair, and the pair is the design’s.

The command’s the exit’s code. The ssh user@host 'command'; echo $? is the exit’s, and the exit’s is the status’s.

ssh user@example.com 'exit 1'
echo $?
# 1

The ssh user@example.com 'exit 1' is the exit’s, and the exit’s is the status’s. The $? is the status’s, and the status’s is the script’s. The two are the pair, and the pair is the design’s.

Why the exit’s code matters. The exit’s code is the script’s, and the script’s is the conditional’s. The $? is the status’s, and the status’s is the if‘s. The two are the pair, and the pair is the design’s.


The scp‘s and the sftp‘s

The scp is the SCP’s, and the sftp is the SFTP’s.

The scp‘s basic. The scp file user@host:/path is the upload’s, and the scp user@host:/path file is the download’s.

scp file.txt user@example.com:/tmp/
scp user@example.com:/tmp/file.txt .

The scp file.txt user@example.com:/tmp/ is the upload’s, and the upload’s is the local’s-to-remote’s. The scp user@example.com:/tmp/file.txt . is the download’s, and the download’s is the remote’s-to-local’s. The two are the pair, and the pair is the pattern’s.

Why the scp matters. The scp is the file’s, and the file’s is the copy’s. The scp is the simple’s, and the simple’s is the fast’s. The two are the pair, and the pair is the design’s.

The scp‘s recursive. The scp -r dir user@host:/path is the recursive’s, and the recursive’s is the directory’s.

scp -r project/ user@example.com:/tmp/

The scp -r project/ is the recursive’s, and the recursive’s is the directory’s. The two are the pair, and the pair is the pattern’s.

Why the scp‘s recursive matters. The recursive’s is the directory’s, and the directory’s is the tree’s. The -r is the recursive’s, and the recursive’s is the directory’s. The two are the pair, and the pair is the design’s.

The scp‘s port. The scp -P 2222 file user@host:/path is the port’s, and the port’s is the non-default’s.

scp -P 2222 file.txt user@example.com:/tmp/

The scp -P 2222 is the port’s, and the port’s is the uppercase’s. The two are the pair, and the pair is the distinction’s.

Why the scp‘s port matters. The scp‘s port is the uppercase’s, and the uppercase’s is the distinction’s. The ssh‘s is the lowercase’s, and the lowercase’s is the -p‘s. The two are the pair, and the pair is the design’s.

The sftp‘s. The sftp user@host is the interactive’s, and the interactive’s is the session’s.

sftp user@example.com
# sftp> ls
# sftp> cd /tmp
# sftp> put file.txt
# sftp> get file.txt
# sftp> bye

The sftp user@example.com is the interactive’s, and the interactive’s is the session’s. The ls, the cd, the put, the get, the bye are the commands’s, and the commands’s is the session’s. The two are the pair, and the pair is the pattern’s.

Why the sftp matters. The sftp is the interactive’s, and the interactive’s is the browse’s. The sftp‘s is the ls‘s, and the ls‘s is the navigation’s. The two are the pair, and the pair is the design’s.

The rsync‘s over the SSH. The rsync -avz -e ssh file user@host:/path is the delta’s, and the delta’s is the efficient’s.

rsync -avz -e ssh project/ user@example.com:/tmp/project/
rsync -avz -e ssh user@example.com:/tmp/project/ ./project/

The rsync -avz -e ssh project/ is the upload’s, and the upload’s is the delta’s. The rsync -avz -e ssh user@example.com:/tmp/project/ ./project/ is the download’s, and the download’s is the delta’s. The two are the pair, and the pair is the pattern’s.

Why the rsync matters. The rsync is the delta’s, and the delta’s is the efficient’s. The rsync is the second’s sync’s, and the second’s sync’s is the changed’s. The two are the pair, and the pair is the design’s.

The rsync‘s trailing slash. The rsync -avz project/ user@host:/tmp/project/ is the trailing’s, and the trailing’s is the content’s.

rsync -avz project/ user@example.com:/tmp/project/   # the content's
rsync -avz project user@example.com:/tmp/project/    # the directory's

The rsync -avz project/ is the content’s, and the rsync -avz project is the directory’s. The trailing’s is the distinction’s, and the distinction’s is the design’s. The two are the pair, and the pair is the pattern’s.

Why the trailing slash matters. The trailing slash is the content’s, and the content’s is the inside’s. The no-trailing’s is the directory’s, and the directory’s is the itself’s. The two are the pair, and the pair is the design’s.


The ~/.ssh/config

The ~/.ssh/config is the alias’s, and the alias’s is the convenience’s.

Host example
    HostName example.com
    User alice
    Port 2222
    IdentityFile ~/.ssh/id_ed25519
    ServerAliveInterval 60
    ServerAliveCountMax 3

The Host example is the alias’s, and the alias’s is the ssh example‘s. The HostName, the User, the Port, the IdentityFile, the ServerAliveInterval, the ServerAliveCountMax are the settings’s, and the settings’s is the per-host’s. The two are the pair, and the pair is the config’s.

Why the ~/.ssh/config matters. The ~/.ssh/config is the alias’s, and the alias’s is the convenience’s. The ssh example is the alias’s, and the alias’s is the full’s replacement’s. The two are the pair, and the pair is the design’s.

The Host *‘s. The Host * is the all’s, and the all’s is the defaults’s.

Host *
    ServerAliveInterval 60
    ServerAliveCountMax 3
    HashKnownHosts yes

The Host * is the all’s, and the all’s is the defaults’s. The ServerAliveInterval, the ServerAliveCountMax, the HashKnownHosts are the defaults’s, and the defaults’s is the every-host’s. The two are the pair, and the pair is the config’s.

Why the Host * matters. The Host * is the all’s, and the all’s is the defaults’s. The Host * is the catch-all’s, and the catch-all’s is the bottom’s. The two are the pair, and the pair is the design’s.

The Match‘s. The Match is the conditional’s, and the conditional’s is the specific’s.

Match host *.example.com
    User alice

Match host *.internal
    User admin
    ProxyJump bastion

The Match host *.example.com is the conditional’s, and the conditional’s is the pattern’s. The Match host *.internal is the conditional’s, and the conditional’s is the internal’s. The two are the pair, and the pair is the config’s.

Why the Match matters. The Match is the conditional’s, and the conditional’s is the specific’s. The Match is the advanced’s, and the advanced’s is the pattern’s. The two are the pair, and the pair is the design’s.

The Include‘s. The Include is the file’s, and the file’s is the split’s.

Include ~/.ssh/config.d/*

The Include ~/.ssh/config.d/* is the file’s, and the file’s is the split’s. The two are the pair, and the pair is the organization’s.

Why the Include matters. The Include is the file’s, and the file’s is the split’s. The Include is the organization’s, and the organization’s is the maintainability’s. The two are the pair, and the pair is the design’s.

The config’s permission. The chmod 600 ~/.ssh/config is the permission’s, and the permission’s is the requirement’s.

chmod 600 ~/.ssh/config

The chmod 600 ~/.ssh/config is the permission’s, and the permission’s is the requirement’s. The two are the pair, and the pair is the security’s.

Why the config’s permission matters. The config’s permission is the requirement’s, and the requirement’s is the security’s. The SSH’s is the strict’s, and the strict’s is the permission’s. The two are the pair, and the pair is the design’s.


The ProxyJump

The ProxyJump is the bastion’s, and the bastion’s is the internal’s.

ssh -J user@bastion user@internal

The ssh -J user@bastion user@internal is the bastion’s, and the bastion’s is the jump’s. The -J is the modern’s, and the modern’s is the concise’s. The two are the pair, and the pair is the pattern’s.

Why the ProxyJump matters. The ProxyJump is the bastion’s, and the bastion’s is the internal’s. The ProxyJump is the multi-hop’s, and the multi-hop’s is the chain’s. The two are the pair, and the pair is the design’s.

The ProxyJump‘s config. The ProxyJump bastion is the config’s, and the config’s is the persistent’s.

Host internal
    HostName 10.0.0.5
    User alice
    ProxyJump bastion

The ProxyJump bastion is the config’s, and the config’s is the persistent’s. The two are the pair, and the pair is the pattern’s.

Why the ProxyJump‘s config matters. The ProxyJump‘s config is the persistent’s, and the persistent’s is the convenient’s. The ssh internal is the alias’s, and the alias’s is the full’s replacement’s. The two are the pair, and the pair is the design’s.

The ProxyJump‘s multiple. The ProxyJump bastion1,bastion2 is the multiple’s, and the multiple’s is the chain’s.

ssh -J user@bastion1,user@bastion2 user@internal

The ssh -J user@bastion1,user@bastion2 user@internal is the multiple’s, and the multiple’s is the chain’s. The two are the pair, and the pair is the pattern’s.

Why the ProxyJump‘s multiple matters. The ProxyJump‘s multiple is the chain’s, and the chain’s is the multi-hop’s. The two are the pair, and the pair is the design’s.

The ProxyCommand‘s legacy. The ProxyCommand ssh -W %h:%p bastion is the legacy’s, and the legacy’s is the ProxyJump‘s.

Host internal
    ProxyCommand ssh -W %h:%p bastion

The ProxyCommand ssh -W %h:%p bastion is the legacy’s, and the legacy’s is the ProxyJump‘s. The two are the pair, and the pair is the migration’s.

Why the ProxyCommand matters. The ProxyCommand is the legacy’s, and the legacy’s is the ProxyJump‘s. The ProxyJump is the modern’s, and the modern’s is the concise’s. The two are the pair, and the pair is the design’s.

The ProxyJump‘s the -W‘s. The -W is the netcat’s, and the netcat’s is the tunnel’s.

ssh -W internal:22 bastion

The ssh -W internal:22 bastion is the -W‘s, and the -W‘s is the netcat’s. The two are the pair, and the pair is the pattern’s.

Why the -W matters. The -W is the netcat’s, and the netcat’s is the tunnel’s. The -W is the ProxyCommand‘s, and the ProxyCommand‘s is the legacy’s. The two are the pair, and the pair is the design’s.


The ControlMaster‘s connection’s reuse

The ControlMaster is the connection’s reuse’s, and the reuse’s is the performance’s.

Host *
    ControlMaster auto
    ControlPath ~/.ssh/control-%r@%h:%p
    ControlPersist 10m

The ControlMaster auto is the reuse’s, and the reuse’s is the performance’s. The ControlPath is the socket’s, and the socket’s is the path’s. The ControlPersist 10m is the persist’s, and the persist’s is the duration’s. The three are the pair, and the pair is the config’s.

Why the ControlMaster matters. The ControlMaster is the reuse’s, and the reuse’s is the performance’s. The ControlMaster‘s is the first’s connection’s, and the first’s connection’s is the subsequent’s reuse’s. The two are the pair, and the pair is the design’s.

The ControlMaster‘s modes. The yes, the no, the auto, the ask are the four.

  • The yes: the first’s connection’s is the master’s.
  • The no: the default’s, the no-reuse’s.
  • The auto: the automatic’s, the master’s if the none’s.
  • The ask: the prompt’s.

The four are the modes’s, and the modes’s is the config’s. The two are the pair, and the pair is the design’s.

Why the ControlMaster‘s modes matter. The ControlMaster‘s modes are the four, and the four are the choice’s. The auto is the common’s, and the common’s is the convenient’s. The two are the pair, and the pair is the design’s.

The ControlPersist‘s. The ControlPersist 10m is the duration’s, and the duration’s is the persist’s.

ControlPersist 10m

The ControlPersist 10m is the 10-minute’s, and the 10-minute’s is the persist’s. The two are the pair, and the pair is the performance’s.

Why the ControlPersist matters. The ControlPersist is the duration’s, and the duration’s is the persist’s. The 10m is the 10-minute’s, and the 10-minute’s is the common’s. The two are the pair, and the pair is the design’s.

The ControlPath‘s. The ControlPath ~/.ssh/control-%r@%h:%p is the socket’s, and the socket’s is the path’s.

ControlPath ~/.ssh/control-%r@%h:%p

The ControlPath ~/.ssh/control-%r@%h:%p is the socket’s, and the socket’s is the path’s. The %r is the remote’s user’s, the %h is the host’s, the %p is the port’s. The three are the placeholders’s, and the placeholders’s is the unique’s. The two are the pair, and the pair is the design’s.

Why the ControlPath‘s placeholders matter. The ControlPath‘s placeholders are the %r, the %h, the %p. The three are the unique’s, and the unique’s is the per-host’s. The two are the pair, and the pair is the design’s.

The ControlMaster‘s benefit. The ControlMaster‘s benefit is the speed’s, and the speed’s is the multi-command’s.

time ssh example 'true'  # the first's
time ssh example 'true'  # the reuse's

The time ssh example 'true' is the first’s, and the first’s is the slow’s. The time ssh example 'true' is the reuse’s, and the reuse’s is the fast’s. The two are the pair, and the pair is the design’s.

Why the ControlMaster‘s benefit matters. The ControlMaster‘s benefit is the speed’s, and the speed’s is the multi-command’s. The ControlMaster‘s is the scp’s and the rsync’s, and the rsync’s is the fast’s. The two are the pair, and the pair is the design’s.


Complete Example Session

# ============================================
# PART 1: THE BASIC SSH
# ============================================

ssh user@example.com
ssh example.com
ssh -p 2222 user@example.com
ssh -i ~/.ssh/id_ed25519 user@example.com

# ============================================
# PART 2: THE REMOTE COMMAND
# ============================================

ssh user@example.com 'uptime'
ssh user@example.com 'cd /var/log && tail -n 20 syslog'

ssh user@example.com << 'EOF'
cd /var/log
tail -n 20 syslog
EOF

# ============================================
# PART 3: THE SCP'S
# ============================================

scp file.txt user@example.com:/tmp/
scp user@example.com:/tmp/file.txt .
scp -r project/ user@example.com:/tmp/

# ============================================
# PART 4: THE SFTP'S
# ============================================

sftp user@example.com
# sftp> ls
# sftp> cd /tmp
# sftp> put file.txt
# sftp> get file.txt
# sftp> bye

# ============================================
# PART 5: THE RSYNC'S
# ============================================

rsync -avz -e ssh project/ user@example.com:/tmp/project/
rsync -avz -e ssh user@example.com:/tmp/project/ ./project/

# ============================================
# PART 6: THE SSH CONFIG
# ============================================

# ~/.ssh/config
# Host example
#     HostName example.com
#     User alice
#     Port 2222
#     IdentityFile ~/.ssh/id_ed25519
#
# Host internal
#     HostName 10.0.0.5
#     User alice
#     ProxyJump bastion
#
# Host *
#     ServerAliveInterval 60
#     ServerAliveCountMax 3
#     ControlMaster auto
#     ControlPath ~/.ssh/control-%r@%h:%p
#     ControlPersist 10m

ssh example
ssh internal

# ============================================
# PART 7: THE PROXY JUMP
# ============================================

ssh -J user@bastion user@internal
ssh -J user@bastion1,user@bastion2 user@internal

# ============================================
# PART 8: THE CONTROL MASTER
# ============================================

time ssh example 'true'  # the first's
time ssh example 'true'  # the reuse's

# ============================================
# PART 9: THE SSH COPY ID
# ============================================

ssh-copy-id user@example.com
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@example.com

# ============================================
# PART 10: WHAT NOT TO DO
# ============================================

# Don't forget the -p on the scp
scp -p 2222 file.txt user@example.com:/tmp/  # โŒ the -p is the preserve'sโ”‚# โš ๏ธ

# Don't forget the trailing slash on the rsync
rsync -avz project user@example.com:/tmp/project/  # the directory'sโ”‚# โš ๏ธ

# Don't forget the ProxyJump for the internal's
ssh user@internal  # the unreachable's                       // โš ๏ธ

# Don't forget the ControlMaster's ControlPath
ControlMaster auto  # the default's path's                   // โš ๏ธ

# Don't forget the config's permission
chmod 644 ~/.ssh/config  # โŒ                                // โš ๏ธ

# Don't forget the remote command's quoting
ssh user@example.com echo $HOME  # the local's               // โš ๏ธ

The ten parts cover the basic ssh, the remote command, the scp, the sftp, the rsync, the SSH config, the ProxyJump, the ControlMaster, the ssh-copy-id, and the anti-patterns.


Quick Reference

The ssh‘s Options

OptionPurpose
-p PORTThe port’s
-i KEYThe key’s
-LThe local’s forward
-RThe remote’s forward
-DThe dynamic’s
-J HOSTThe jump’s
-vThe verbose’s
-TThe no-tty’s
-o KEY=VALUEThe arbitrary’s

The File’s Commands

CommandPurpose
scp file user@host:/pathThe upload’s
scp user@host:/path fileThe download’s
scp -r dir user@host:/pathThe recursive’s
scp -P 2222 file ...The port’s (the uppercase’s)
sftp user@hostThe interactive’s
rsync -avz -e ssh src dstThe delta’s

The ~/.ssh/config‘s Fields

FieldPurpose
HostThe alias’s
HostNameThe real’s host
UserThe username’s
PortThe port’s
IdentityFileThe key’s
ProxyJumpThe bastion’s
ForwardAgentThe agent’s
ServerAliveIntervalThe keepalive’s
ControlMasterThe reuse’s
ControlPathThe socket’s
ControlPersistThe persist’s

The ProxyJump‘s Forms

FormPurpose
-J bastionThe single’s
-J bastion1,bastion2The multiple’s
ProxyJump bastionThe config’s
ProxyCommand ssh -W %h:%p bastionThe legacy’s

The ControlMaster‘s Modes

ModeBehavior
yesThe master’s
noThe no-reuse’s
autoThe automatic’s
askThe prompt’s

Best Practices

โœ… Do This:

# Use the config for the aliases
ssh example                                                   # โœ…
# Use the ProxyJump for the bastion's
ssh -J user@bastion user@internal                             # โœ…
# Use the ControlMaster for the speed's
# ControlMaster auto, ControlPersist 10m                     # โœ…
# Use the remote command with the single-quote's
ssh user@example.com 'cd /var/log && tail -n 20 syslog'       # โœ…
# Use the trailing slash on the rsync's
rsync -avz project/ user@example.com:/tmp/project/            # โœ…
# Use the scp-copy-id for the key's
ssh-copy-id user@example.com                                  # โœ…
# Use the config's permission
chmod 600 ~/.ssh/config                                       # โœ…

โŒ Don’t Do This:

# Don't use the -p on the scp
scp -p 2222 file.txt user@example.com:/tmp/  # โŒ the -p is the preserve's // โš ๏ธ
# Don't forget the trailing slash on the rsync's
rsync -avz project user@example.com:/tmp/project/  # the directory's // โš ๏ธ
# Don't forget the ProxyJump for the internal's
ssh user@internal  # the unreachable's                          // โš ๏ธ
# Don't forget the ControlMaster's ControlPath
ControlMaster auto  # the default's path's                     // โš ๏ธ
# Don't forget the config's permission
chmod 644 ~/.ssh/config  # โŒ                                 // โš ๏ธ
# Don't forget the remote command's quoting
ssh user@example.com echo $HOME  # the local's                 // โš ๏ธ

Common Pitfalls

PitfallProblemSolution
The scp‘s -pThe preserve’sThe -P for the port
The rsync‘s no-trailing’sThe directory’sThe trailing’s
The missing ProxyJumpThe unreachableThe -J
The missing ControlPathThe default’sThe explicit’s
The config’s permissionThe refusalThe chmod 600
The remote command’s quotingThe local’sThe single-quote’s
The missing -TThe tty’sThe -T
The missing -iThe wrong key’sThe -i

Real-World Examples

1. The basic ssh

ssh user@example.com

2. The remote command

ssh user@example.com 'uptime'

3. The heredoc

ssh user@example.com << 'EOF'
cd /var/log
tail -n 20 syslog
EOF

4. The scp

scp file.txt user@example.com:/tmp/

5. The sftp

sftp user@example.com

6. The rsync

rsync -avz -e ssh project/ user@example.com:/tmp/project/

7. The config

Host example
    HostName example.com
    User alice

8. The ProxyJump

ssh -J user@bastion user@internal

9. The ControlMaster

ControlMaster auto
ControlPath ~/.ssh/control-%r@%h:%p
ControlPersist 10m

10. The ssh-copy-id

ssh-copy-id user@example.com

Visual: The ssh’s Syntax

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  ssh [options] [user@]host [command]         โ”‚
โ”‚   โ”‚                                           โ”‚
โ”‚   โ”œโ”€โ”€ -p PORT    the port's                  โ”‚
โ”‚   โ”œโ”€โ”€ -i KEY     the key's                   โ”‚
โ”‚   โ”œโ”€โ”€ -L         the local's forward         โ”‚
โ”‚   โ”œโ”€โ”€ -R         the remote's forward        โ”‚
โ”‚   โ”œโ”€โ”€ -D         the dynamic's               โ”‚
โ”‚   โ”œโ”€โ”€ -J HOST    the jump's                  โ”‚
โ”‚   โ”œโ”€โ”€ -v         the verbose's               โ”‚
โ”‚   โ””โ”€โ”€ -T         the no-tty's                โ”‚
โ”‚                                              โ”‚
โ”‚  ssh user@host 'command'                     โ”‚
โ”‚    โ†’ the remote's command's                  โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Visual: The File’s Transfer’s

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  LOCAL                    REMOTE             โ”‚
โ”‚    โ”‚                        โ”‚                โ”‚
โ”‚    โ”‚  scp file.txt โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–บ โ”‚  /tmp/         โ”‚
โ”‚    โ”‚                        โ”‚                โ”‚
โ”‚    โ”‚  โ—„โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€ scp /tmp/f  โ”‚                โ”‚
โ”‚    โ”‚                        โ”‚                โ”‚
โ”‚    โ”‚  rsync -avz โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ–บ โ”‚  the delta's  โ”‚
โ”‚    โ”‚                        โ”‚                โ”‚
โ”‚    โ”‚  sftp (the interactive's)โ”‚                โ”‚
โ”‚    โ”‚                        โ”‚                โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Visual: The ProxyJump

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  THE LOCAL                                   โ”‚
โ”‚    โ”‚                                         โ”‚
โ”‚    โ”‚  ssh -J bastion internal                โ”‚
โ”‚    โ–ผ                                         โ”‚
โ”‚  THE BASTION (the public's)                  โ”‚
โ”‚    โ”‚                                         โ”‚
โ”‚    โ”‚  the forward's                          โ”‚
โ”‚    โ–ผ                                         โ”‚
โ”‚  THE INTERNAL (the private's)                โ”‚
โ”‚                                              โ”‚
โ”‚  The bastion's is the public's, and the      โ”‚
โ”‚  internal's is the private's.                โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Visual: The ControlMaster

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  WITHOUT ControlMaster                       โ”‚
โ”‚    ssh example  โ†’ the full's handshake's     โ”‚
โ”‚    scp file     โ†’ the full's handshake's     โ”‚
โ”‚    ssh example  โ†’ the full's handshake's     โ”‚
โ”‚                                              โ”‚
โ”œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”ค
โ”‚  WITH ControlMaster                          โ”‚
โ”‚    ssh example  โ†’ the master's connection    โ”‚
โ”‚    scp file     โ†’ the reuse's                โ”‚
โ”‚    ssh example  โ†’ the reuse's                โ”‚
โ”‚                                              โ”‚
โ”‚  The reuse's is the fast's.                  โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Visual: The ssh’s Config

โ”Œโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”
โ”‚  ~/.ssh/config                               โ”‚
โ”‚    โ”‚                                         โ”‚
โ”‚    โ”œโ”€โ”€ Host *                                โ”‚
โ”‚    โ”‚     ServerAliveInterval 60              โ”‚
โ”‚    โ”‚     ControlMaster auto                  โ”‚
โ”‚    โ”‚     ControlPersist 10m                  โ”‚
โ”‚    โ”‚                                         โ”‚
โ”‚    โ”œโ”€โ”€ Host example                          โ”‚
โ”‚    โ”‚     HostName example.com                โ”‚
โ”‚    โ”‚     User alice                          โ”‚
โ”‚    โ”‚     Port 2222                           โ”‚
โ”‚    โ”‚                                         โ”‚
โ”‚    โ””โ”€โ”€ Host internal                         โ”‚
โ”‚          HostName 10.0.0.5                   โ”‚
โ”‚          User alice                          โ”‚
โ”‚          ProxyJump bastion                   โ”‚
โ”‚                                              โ”‚
โ”‚  The Host * is the defaults's, and the       โ”‚
โ”‚  specific's is the override's.               โ”‚
โ”‚                                              โ”‚
โ””โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”˜

Summary

ItemValue
The basicssh user@host
The portssh -p PORT
The keyssh -i KEY
The remote commandssh user@host 'command'
The uploadscp file user@host:/path
The downloadscp user@host:/path file
The interactivesftp user@host
The delta’srsync -avz -e ssh
The alias’s~/.ssh/config
The bastion’sProxyJump
The reuse’sControlMaster

Key takeaways:

  • The ssh user@host is the basic’s, and the user@host is the pattern’s โ€” the user’s omission is the local’s, and the -p and the -i are the common’s options
  • The ssh user@host 'command' runs the remote’s command’s โ€” the single-quote’s is the remote’s, and the double-quote’s is the local’s interpolation’s
  • The scp‘s is the simple’s, and the sftp‘s is the interactive’s โ€” the scp‘s -P is the port’s (the uppercase’s), and the -p is the preserve’s
  • The rsync‘s is the delta’s, and the trailing slash’s is the distinction’s โ€” the project/‘s is the content’s, and the project‘s is the directory’s
  • The ~/.ssh/config is the alias’s โ€” the Host, the HostName, the User, the Port, the IdentityFile are the common’s
  • The ProxyJump is the bastion’s โ€” the -J is the modern’s, and the ProxyCommand‘s -W is the legacy’s
  • The ControlMaster is the connection’s reuse’s โ€” the auto, the ControlPath, the ControlPersist are the three, and the reuse’s is the performance’s
  • The ssh-copy-id is the public’s key’s copy’s โ€” the copy’s is the passwordless’s, and the authorized_keys‘s is the result’s
  • The ServerAliveInterval is the keepalive’s โ€” the interval’s and the count’s are the two, and the two are the disconnect’s prevention’s
  • The config’s permission is the requirement’s โ€” the chmod 600 ~/.ssh/config is the security’s

Remember: The ssh‘s is the remote’s, and the scp‘s and the sftp‘s and the rsync‘s are the file’s. The ~/.ssh/config‘s is the alias’s, and the ProxyJump‘s is the bastion’s. The ControlMaster‘s is the reuse’s, and the ssh-copy-id‘s is the passwordless’s. The SSH’s is the daily’s, and the daily’s is the skill’s.


Stop using slow, ad-bloated tool sites! ๐Ÿคฎ

๐Ÿ”Ž Search “KandZ Tools” on Google to use many professional utilities for free.

KandZ.me is the ultimate minimalist hub for:
โœ… Finance (Mortgage, Interest, Inflation)
โœ… Tech (Base64, JSON, Dev Suite, IP)
โœ… Health (BMI, BMR, TDEE)
โœ… Productivity (Timer, Workspace, QR)

โšก๏ธ Fast & Private
๐Ÿ”’ No data leaves your device
๐Ÿ’Ž 100% Free

๐Ÿ”— Use it now: https://tools.kandz.me
๐Ÿ”– Bookmark itโ€”youโ€™ll need it later!