LFCA 51 ๐ง Connecting with SSH
The previous chapter explained what SSH is โ the protocol, the encryption, the key pairs, and the configuration. This chapter is about the everyday use: the commands that connect to a remote host, move files, run remote commands, forward ports, and copy keys. The ssh command is the entry point, and the scp, sftp, and rsync are the tools that build on it. The ~/.ssh/config file is the way to make the connections convenient โ the aliases, the per-host settings, the jump hosts, and the key files. This chapter covers the practical’s side: the ssh‘s syntax and options, the remote command’s execution, the scp‘s and the sftp‘s, the rsync‘s over the SSH, the agent’s forwarding, the ssh-keygen‘s and the ssh-copy-id‘s, the ProxyJump, the ControlMaster‘s connection’s reuse, and the patterns that make the remote work efficient. It builds on LFCA 50 and prepares the ground for the more advanced’s SSH’s material.
Key point: The ssh user@host is the basic’s, and the -p, the -i, the -L, the -R, the -D, the -J, the -v are the common’s options. The ssh user@host 'command' runs the command’s on the remote’s and returns the output’s. The scp is the SCP’s, and the sftp is the SFTP’s, and the rsync‘s is the delta’s. The ~/.ssh/config‘s is the alias’s, and the Host, the HostName, the User, the Port, the IdentityFile, the ProxyJump, the ForwardAgent, the ControlMaster, the ControlPath, the ControlPersist are the common’s. The ControlMaster‘s is the connection’s reuse’s, and the reuse’s is the performance’s. The ProxyJump‘s is the bastion’s, and the bastion’s is the internal’s. The ssh-copy-id‘s is the public’s key’s copy’s, and the copy’s is the passwordless’s.
The ssh‘s basic usage
The ssh user@host is the basic’s, and the basic’s is the connection’s.
ssh user@example.com
# The password's prompt, or the key's authentication.
The ssh user@example.com is the basic’s, and the basic’s is the connection’s. The user is the remote’s, and the example.com is the host’s. The two are the pair, and the pair is the connection’s.
Why the ssh‘s basic matters. The ssh‘s basic is the entry’s, and the entry’s is the first’s. The user@host is the pattern’s, and the pattern’s is the universal’s. The two are the pair, and the pair is the design’s.
The user’s omission. The ssh example.com omits the user, and the omitted’s is the local’s. The SSH uses the local’s username, and the local’s is the default’s.
ssh example.com # the local's username
The ssh example.com is the omitted’s, and the omitted’s is the local’s. The two are the pair, and the pair is the convenience’s.
The port’s option. The ssh -p 2222 user@example.com is the port’s, and the port’s is the non-default’s.
ssh -p 2222 user@example.com
The ssh -p 2222 is the port’s, and the port’s is the 22’s alternative’s. The two are the pair, and the pair is the specific’s.
Why the port’s option matters. The port’s option is the non-default’s, and the non-default’s is the security’s. The 2222’s is the common’s, and the common’s is the hardening’s. The two are the pair, and the pair is the design’s.
The key’s option. The ssh -i ~/.ssh/id_ed25519 user@example.com is the key’s, and the key’s is the specific’s.
ssh -i ~/.ssh/id_ed25519 user@example.com
The ssh -i ~/.ssh/id_ed25519 is the key’s, and the key’s is the specific’s. The two are the pair, and the pair is the pattern’s.
Why the key’s option matters. The key’s option is the multi-key’s, and the multi-key’s is the common’s. The -i is the specific’s, and the specific’s is the choice’s. The two are the pair, and the pair is the design’s.
The verbose’s option. The ssh -v user@example.com is the verbose’s, and the verbose’s is the debug’s.
ssh -v user@example.com
# The debug's output.
The ssh -v user@example.com is the verbose’s, and the verbose’s is the debug’s. The -v, the -vv, the -vvv are the three, and the three are the detail’s. The two are the pair, and the pair is the diagnosis’s.
Why the verbose’s option matters. The verbose’s option is the debug’s, and the debug’s is the diagnosis’s. The -v is the connection’s, and the connection’s is the handshake’s. The two are the pair, and the pair is the pattern’s.
The identity’s option. The ssh -o IdentityFile=~/.ssh/id_ed25519 user@example.com is the identity’s, and the identity’s is the -o‘s.
ssh -o IdentityFile=~/.ssh/id_ed25519 user@example.com
The ssh -o IdentityFile=... is the identity’s, and the identity’s is the -o‘s. The two are the pair, and the pair is the pattern’s.
Why the -o‘s matters. The -o‘s is the arbitrary’s, and the arbitrary’s is the config’s. The -o‘s is the per-command’s, and the per-command’s is the specific’s. The two are the pair, and the pair is the design’s.
The remote command’s execution
The ssh user@host 'command' runs the command’s on the remote’s and returns the output’s.
ssh user@example.com 'uptime'
# 10:50:12 up 3 days, 2 users, load average: 0.15, 0.10, 0.05
The ssh user@example.com 'uptime' is the remote’s, and the remote’s is the command’s. The uptime is the command’s, and the command’s is the remote’s. The two are the pair, and the pair is the pattern’s.
Why the remote command matters. The remote command is the automation’s, and the automation’s is the script’s. The remote command’s is the single’s, and the single’s is the fast’s. The two are the pair, and the pair is the design’s.
The command’s multiple. The ssh user@host 'cmd1; cmd2' is the multiple’s, and the multiple’s is the sequence’s.
ssh user@example.com 'cd /var/log && tail -n 20 syslog'
The ssh user@example.com 'cd /var/log && tail -n 20 syslog' is the multiple’s, and the multiple’s is the sequence’s. The two are the pair, and the pair is the pattern’s.
Why the command’s multiple matters. The command’s multiple is the sequence’s, and the sequence’s is the &&‘s or the ;‘s. The && is the conditional’s, and the ; is the unconditional’s. The two are the pair, and the pair is the design’s.
The command’s quoting. The ssh user@host 'echo "$HOME"' is the remote’s, and the remote’s is the single-quote’s.
ssh user@example.com 'echo "$HOME"'
# /home/user
The ssh user@example.com 'echo "$HOME"' is the remote’s, and the remote’s is the single-quote’s. The double-quote’s is the local’s, and the local’s is the interpolation’s. The two are the pair, and the pair is the distinction’s.
Why the quoting matters. The quoting is the local’s, and the local’s is the shell’s. The single-quote’s is the literal’s, and the double-quote’s is the local’s. The two are the pair, and the pair is the design’s.
The command’s heredoc. The ssh user@host << 'EOF' ... EOF is the heredoc’s, and the heredoc’s is the multi-line’s.
ssh user@example.com << 'EOF'
cd /var/log
tail -n 20 syslog
EOF
The ssh user@example.com << 'EOF' ... EOF is the heredoc’s, and the heredoc’s is the multi-line’s. The two are the pair, and the pair is the pattern’s.
Why the heredoc matters. The heredoc is the multi-line’s, and the multi-line’s is the readable’s. The 'EOF'‘s is the single-quote’s, and the single-quote’s is the local’s interpolation’s prevention’s. The two are the pair, and the pair is the design’s.
The command’s the no-tty’s. The ssh -T user@host is the no-tty’s, and the no-tty’s is the non-interactive’s.
ssh -T user@example.com 'ls -la'
The ssh -T is the no-tty’s, and the no-tty’s is the non-interactive’s. The two are the pair, and the pair is the pattern’s.
Why the no-tty matters. The no-tty is the non-interactive’s, and the non-interactive’s is the script’s. The -T is the no-allocate’s, and the no-allocate’s is the script’s. The two are the pair, and the pair is the design’s.
The command’s the exit’s code. The ssh user@host 'command'; echo $? is the exit’s, and the exit’s is the status’s.
ssh user@example.com 'exit 1'
echo $?
# 1
The ssh user@example.com 'exit 1' is the exit’s, and the exit’s is the status’s. The $? is the status’s, and the status’s is the script’s. The two are the pair, and the pair is the design’s.
Why the exit’s code matters. The exit’s code is the script’s, and the script’s is the conditional’s. The $? is the status’s, and the status’s is the if‘s. The two are the pair, and the pair is the design’s.
The scp‘s and the sftp‘s
The scp is the SCP’s, and the sftp is the SFTP’s.
The scp‘s basic. The scp file user@host:/path is the upload’s, and the scp user@host:/path file is the download’s.
scp file.txt user@example.com:/tmp/
scp user@example.com:/tmp/file.txt .
The scp file.txt user@example.com:/tmp/ is the upload’s, and the upload’s is the local’s-to-remote’s. The scp user@example.com:/tmp/file.txt . is the download’s, and the download’s is the remote’s-to-local’s. The two are the pair, and the pair is the pattern’s.
Why the scp matters. The scp is the file’s, and the file’s is the copy’s. The scp is the simple’s, and the simple’s is the fast’s. The two are the pair, and the pair is the design’s.
The scp‘s recursive. The scp -r dir user@host:/path is the recursive’s, and the recursive’s is the directory’s.
scp -r project/ user@example.com:/tmp/
The scp -r project/ is the recursive’s, and the recursive’s is the directory’s. The two are the pair, and the pair is the pattern’s.
Why the scp‘s recursive matters. The recursive’s is the directory’s, and the directory’s is the tree’s. The -r is the recursive’s, and the recursive’s is the directory’s. The two are the pair, and the pair is the design’s.
The scp‘s port. The scp -P 2222 file user@host:/path is the port’s, and the port’s is the non-default’s.
scp -P 2222 file.txt user@example.com:/tmp/
The scp -P 2222 is the port’s, and the port’s is the uppercase’s. The two are the pair, and the pair is the distinction’s.
Why the scp‘s port matters. The scp‘s port is the uppercase’s, and the uppercase’s is the distinction’s. The ssh‘s is the lowercase’s, and the lowercase’s is the -p‘s. The two are the pair, and the pair is the design’s.
The sftp‘s. The sftp user@host is the interactive’s, and the interactive’s is the session’s.
sftp user@example.com
# sftp> ls
# sftp> cd /tmp
# sftp> put file.txt
# sftp> get file.txt
# sftp> bye
The sftp user@example.com is the interactive’s, and the interactive’s is the session’s. The ls, the cd, the put, the get, the bye are the commands’s, and the commands’s is the session’s. The two are the pair, and the pair is the pattern’s.
Why the sftp matters. The sftp is the interactive’s, and the interactive’s is the browse’s. The sftp‘s is the ls‘s, and the ls‘s is the navigation’s. The two are the pair, and the pair is the design’s.
The rsync‘s over the SSH. The rsync -avz -e ssh file user@host:/path is the delta’s, and the delta’s is the efficient’s.
rsync -avz -e ssh project/ user@example.com:/tmp/project/
rsync -avz -e ssh user@example.com:/tmp/project/ ./project/
The rsync -avz -e ssh project/ is the upload’s, and the upload’s is the delta’s. The rsync -avz -e ssh user@example.com:/tmp/project/ ./project/ is the download’s, and the download’s is the delta’s. The two are the pair, and the pair is the pattern’s.
Why the rsync matters. The rsync is the delta’s, and the delta’s is the efficient’s. The rsync is the second’s sync’s, and the second’s sync’s is the changed’s. The two are the pair, and the pair is the design’s.
The rsync‘s trailing slash. The rsync -avz project/ user@host:/tmp/project/ is the trailing’s, and the trailing’s is the content’s.
rsync -avz project/ user@example.com:/tmp/project/ # the content's
rsync -avz project user@example.com:/tmp/project/ # the directory's
The rsync -avz project/ is the content’s, and the rsync -avz project is the directory’s. The trailing’s is the distinction’s, and the distinction’s is the design’s. The two are the pair, and the pair is the pattern’s.
Why the trailing slash matters. The trailing slash is the content’s, and the content’s is the inside’s. The no-trailing’s is the directory’s, and the directory’s is the itself’s. The two are the pair, and the pair is the design’s.
The ~/.ssh/config
The ~/.ssh/config is the alias’s, and the alias’s is the convenience’s.
Host example
HostName example.com
User alice
Port 2222
IdentityFile ~/.ssh/id_ed25519
ServerAliveInterval 60
ServerAliveCountMax 3
The Host example is the alias’s, and the alias’s is the ssh example‘s. The HostName, the User, the Port, the IdentityFile, the ServerAliveInterval, the ServerAliveCountMax are the settings’s, and the settings’s is the per-host’s. The two are the pair, and the pair is the config’s.
Why the ~/.ssh/config matters. The ~/.ssh/config is the alias’s, and the alias’s is the convenience’s. The ssh example is the alias’s, and the alias’s is the full’s replacement’s. The two are the pair, and the pair is the design’s.
The Host *‘s. The Host * is the all’s, and the all’s is the defaults’s.
Host *
ServerAliveInterval 60
ServerAliveCountMax 3
HashKnownHosts yes
The Host * is the all’s, and the all’s is the defaults’s. The ServerAliveInterval, the ServerAliveCountMax, the HashKnownHosts are the defaults’s, and the defaults’s is the every-host’s. The two are the pair, and the pair is the config’s.
Why the Host * matters. The Host * is the all’s, and the all’s is the defaults’s. The Host * is the catch-all’s, and the catch-all’s is the bottom’s. The two are the pair, and the pair is the design’s.
The Match‘s. The Match is the conditional’s, and the conditional’s is the specific’s.
Match host *.example.com
User alice
Match host *.internal
User admin
ProxyJump bastion
The Match host *.example.com is the conditional’s, and the conditional’s is the pattern’s. The Match host *.internal is the conditional’s, and the conditional’s is the internal’s. The two are the pair, and the pair is the config’s.
Why the Match matters. The Match is the conditional’s, and the conditional’s is the specific’s. The Match is the advanced’s, and the advanced’s is the pattern’s. The two are the pair, and the pair is the design’s.
The Include‘s. The Include is the file’s, and the file’s is the split’s.
Include ~/.ssh/config.d/*
The Include ~/.ssh/config.d/* is the file’s, and the file’s is the split’s. The two are the pair, and the pair is the organization’s.
Why the Include matters. The Include is the file’s, and the file’s is the split’s. The Include is the organization’s, and the organization’s is the maintainability’s. The two are the pair, and the pair is the design’s.
The config’s permission. The chmod 600 ~/.ssh/config is the permission’s, and the permission’s is the requirement’s.
chmod 600 ~/.ssh/config
The chmod 600 ~/.ssh/config is the permission’s, and the permission’s is the requirement’s. The two are the pair, and the pair is the security’s.
Why the config’s permission matters. The config’s permission is the requirement’s, and the requirement’s is the security’s. The SSH’s is the strict’s, and the strict’s is the permission’s. The two are the pair, and the pair is the design’s.
The ProxyJump
The ProxyJump is the bastion’s, and the bastion’s is the internal’s.
ssh -J user@bastion user@internal
The ssh -J user@bastion user@internal is the bastion’s, and the bastion’s is the jump’s. The -J is the modern’s, and the modern’s is the concise’s. The two are the pair, and the pair is the pattern’s.
Why the ProxyJump matters. The ProxyJump is the bastion’s, and the bastion’s is the internal’s. The ProxyJump is the multi-hop’s, and the multi-hop’s is the chain’s. The two are the pair, and the pair is the design’s.
The ProxyJump‘s config. The ProxyJump bastion is the config’s, and the config’s is the persistent’s.
Host internal
HostName 10.0.0.5
User alice
ProxyJump bastion
The ProxyJump bastion is the config’s, and the config’s is the persistent’s. The two are the pair, and the pair is the pattern’s.
Why the ProxyJump‘s config matters. The ProxyJump‘s config is the persistent’s, and the persistent’s is the convenient’s. The ssh internal is the alias’s, and the alias’s is the full’s replacement’s. The two are the pair, and the pair is the design’s.
The ProxyJump‘s multiple. The ProxyJump bastion1,bastion2 is the multiple’s, and the multiple’s is the chain’s.
ssh -J user@bastion1,user@bastion2 user@internal
The ssh -J user@bastion1,user@bastion2 user@internal is the multiple’s, and the multiple’s is the chain’s. The two are the pair, and the pair is the pattern’s.
Why the ProxyJump‘s multiple matters. The ProxyJump‘s multiple is the chain’s, and the chain’s is the multi-hop’s. The two are the pair, and the pair is the design’s.
The ProxyCommand‘s legacy. The ProxyCommand ssh -W %h:%p bastion is the legacy’s, and the legacy’s is the ProxyJump‘s.
Host internal
ProxyCommand ssh -W %h:%p bastion
The ProxyCommand ssh -W %h:%p bastion is the legacy’s, and the legacy’s is the ProxyJump‘s. The two are the pair, and the pair is the migration’s.
Why the ProxyCommand matters. The ProxyCommand is the legacy’s, and the legacy’s is the ProxyJump‘s. The ProxyJump is the modern’s, and the modern’s is the concise’s. The two are the pair, and the pair is the design’s.
The ProxyJump‘s the -W‘s. The -W is the netcat’s, and the netcat’s is the tunnel’s.
ssh -W internal:22 bastion
The ssh -W internal:22 bastion is the -W‘s, and the -W‘s is the netcat’s. The two are the pair, and the pair is the pattern’s.
Why the -W matters. The -W is the netcat’s, and the netcat’s is the tunnel’s. The -W is the ProxyCommand‘s, and the ProxyCommand‘s is the legacy’s. The two are the pair, and the pair is the design’s.
The ControlMaster‘s connection’s reuse
The ControlMaster is the connection’s reuse’s, and the reuse’s is the performance’s.
Host *
ControlMaster auto
ControlPath ~/.ssh/control-%r@%h:%p
ControlPersist 10m
The ControlMaster auto is the reuse’s, and the reuse’s is the performance’s. The ControlPath is the socket’s, and the socket’s is the path’s. The ControlPersist 10m is the persist’s, and the persist’s is the duration’s. The three are the pair, and the pair is the config’s.
Why the ControlMaster matters. The ControlMaster is the reuse’s, and the reuse’s is the performance’s. The ControlMaster‘s is the first’s connection’s, and the first’s connection’s is the subsequent’s reuse’s. The two are the pair, and the pair is the design’s.
The ControlMaster‘s modes. The yes, the no, the auto, the ask are the four.
- The
yes: the first’s connection’s is the master’s. - The
no: the default’s, the no-reuse’s. - The
auto: the automatic’s, the master’s if the none’s. - The
ask: the prompt’s.
The four are the modes’s, and the modes’s is the config’s. The two are the pair, and the pair is the design’s.
Why the ControlMaster‘s modes matter. The ControlMaster‘s modes are the four, and the four are the choice’s. The auto is the common’s, and the common’s is the convenient’s. The two are the pair, and the pair is the design’s.
The ControlPersist‘s. The ControlPersist 10m is the duration’s, and the duration’s is the persist’s.
ControlPersist 10m
The ControlPersist 10m is the 10-minute’s, and the 10-minute’s is the persist’s. The two are the pair, and the pair is the performance’s.
Why the ControlPersist matters. The ControlPersist is the duration’s, and the duration’s is the persist’s. The 10m is the 10-minute’s, and the 10-minute’s is the common’s. The two are the pair, and the pair is the design’s.
The ControlPath‘s. The ControlPath ~/.ssh/control-%r@%h:%p is the socket’s, and the socket’s is the path’s.
ControlPath ~/.ssh/control-%r@%h:%p
The ControlPath ~/.ssh/control-%r@%h:%p is the socket’s, and the socket’s is the path’s. The %r is the remote’s user’s, the %h is the host’s, the %p is the port’s. The three are the placeholders’s, and the placeholders’s is the unique’s. The two are the pair, and the pair is the design’s.
Why the ControlPath‘s placeholders matter. The ControlPath‘s placeholders are the %r, the %h, the %p. The three are the unique’s, and the unique’s is the per-host’s. The two are the pair, and the pair is the design’s.
The ControlMaster‘s benefit. The ControlMaster‘s benefit is the speed’s, and the speed’s is the multi-command’s.
time ssh example 'true' # the first's
time ssh example 'true' # the reuse's
The time ssh example 'true' is the first’s, and the first’s is the slow’s. The time ssh example 'true' is the reuse’s, and the reuse’s is the fast’s. The two are the pair, and the pair is the design’s.
Why the ControlMaster‘s benefit matters. The ControlMaster‘s benefit is the speed’s, and the speed’s is the multi-command’s. The ControlMaster‘s is the scp’s and the rsync’s, and the rsync’s is the fast’s. The two are the pair, and the pair is the design’s.
Complete Example Session
# ============================================
# PART 1: THE BASIC SSH
# ============================================
ssh user@example.com
ssh example.com
ssh -p 2222 user@example.com
ssh -i ~/.ssh/id_ed25519 user@example.com
# ============================================
# PART 2: THE REMOTE COMMAND
# ============================================
ssh user@example.com 'uptime'
ssh user@example.com 'cd /var/log && tail -n 20 syslog'
ssh user@example.com << 'EOF'
cd /var/log
tail -n 20 syslog
EOF
# ============================================
# PART 3: THE SCP'S
# ============================================
scp file.txt user@example.com:/tmp/
scp user@example.com:/tmp/file.txt .
scp -r project/ user@example.com:/tmp/
# ============================================
# PART 4: THE SFTP'S
# ============================================
sftp user@example.com
# sftp> ls
# sftp> cd /tmp
# sftp> put file.txt
# sftp> get file.txt
# sftp> bye
# ============================================
# PART 5: THE RSYNC'S
# ============================================
rsync -avz -e ssh project/ user@example.com:/tmp/project/
rsync -avz -e ssh user@example.com:/tmp/project/ ./project/
# ============================================
# PART 6: THE SSH CONFIG
# ============================================
# ~/.ssh/config
# Host example
# HostName example.com
# User alice
# Port 2222
# IdentityFile ~/.ssh/id_ed25519
#
# Host internal
# HostName 10.0.0.5
# User alice
# ProxyJump bastion
#
# Host *
# ServerAliveInterval 60
# ServerAliveCountMax 3
# ControlMaster auto
# ControlPath ~/.ssh/control-%r@%h:%p
# ControlPersist 10m
ssh example
ssh internal
# ============================================
# PART 7: THE PROXY JUMP
# ============================================
ssh -J user@bastion user@internal
ssh -J user@bastion1,user@bastion2 user@internal
# ============================================
# PART 8: THE CONTROL MASTER
# ============================================
time ssh example 'true' # the first's
time ssh example 'true' # the reuse's
# ============================================
# PART 9: THE SSH COPY ID
# ============================================
ssh-copy-id user@example.com
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@example.com
# ============================================
# PART 10: WHAT NOT TO DO
# ============================================
# Don't forget the -p on the scp
scp -p 2222 file.txt user@example.com:/tmp/ # โ the -p is the preserve'sโ# โ ๏ธ
# Don't forget the trailing slash on the rsync
rsync -avz project user@example.com:/tmp/project/ # the directory'sโ# โ ๏ธ
# Don't forget the ProxyJump for the internal's
ssh user@internal # the unreachable's // โ ๏ธ
# Don't forget the ControlMaster's ControlPath
ControlMaster auto # the default's path's // โ ๏ธ
# Don't forget the config's permission
chmod 644 ~/.ssh/config # โ // โ ๏ธ
# Don't forget the remote command's quoting
ssh user@example.com echo $HOME # the local's // โ ๏ธ
The ten parts cover the basic ssh, the remote command, the scp, the sftp, the rsync, the SSH config, the ProxyJump, the ControlMaster, the ssh-copy-id, and the anti-patterns.
Quick Reference
The ssh‘s Options
| Option | Purpose |
|---|---|
-p PORT | The port’s |
-i KEY | The key’s |
-L | The local’s forward |
-R | The remote’s forward |
-D | The dynamic’s |
-J HOST | The jump’s |
-v | The verbose’s |
-T | The no-tty’s |
-o KEY=VALUE | The arbitrary’s |
The File’s Commands
| Command | Purpose |
|---|---|
scp file user@host:/path | The upload’s |
scp user@host:/path file | The download’s |
scp -r dir user@host:/path | The recursive’s |
scp -P 2222 file ... | The port’s (the uppercase’s) |
sftp user@host | The interactive’s |
rsync -avz -e ssh src dst | The delta’s |
The ~/.ssh/config‘s Fields
| Field | Purpose |
|---|---|
Host | The alias’s |
HostName | The real’s host |
User | The username’s |
Port | The port’s |
IdentityFile | The key’s |
ProxyJump | The bastion’s |
ForwardAgent | The agent’s |
ServerAliveInterval | The keepalive’s |
ControlMaster | The reuse’s |
ControlPath | The socket’s |
ControlPersist | The persist’s |
The ProxyJump‘s Forms
| Form | Purpose |
|---|---|
-J bastion | The single’s |
-J bastion1,bastion2 | The multiple’s |
ProxyJump bastion | The config’s |
ProxyCommand ssh -W %h:%p bastion | The legacy’s |
The ControlMaster‘s Modes
| Mode | Behavior |
|---|---|
yes | The master’s |
no | The no-reuse’s |
auto | The automatic’s |
ask | The prompt’s |
Best Practices
โ Do This:
# Use the config for the aliases
ssh example # โ
# Use the ProxyJump for the bastion's
ssh -J user@bastion user@internal # โ
# Use the ControlMaster for the speed's
# ControlMaster auto, ControlPersist 10m # โ
# Use the remote command with the single-quote's
ssh user@example.com 'cd /var/log && tail -n 20 syslog' # โ
# Use the trailing slash on the rsync's
rsync -avz project/ user@example.com:/tmp/project/ # โ
# Use the scp-copy-id for the key's
ssh-copy-id user@example.com # โ
# Use the config's permission
chmod 600 ~/.ssh/config # โ
โ Don’t Do This:
# Don't use the -p on the scp
scp -p 2222 file.txt user@example.com:/tmp/ # โ the -p is the preserve's // โ ๏ธ
# Don't forget the trailing slash on the rsync's
rsync -avz project user@example.com:/tmp/project/ # the directory's // โ ๏ธ
# Don't forget the ProxyJump for the internal's
ssh user@internal # the unreachable's // โ ๏ธ
# Don't forget the ControlMaster's ControlPath
ControlMaster auto # the default's path's // โ ๏ธ
# Don't forget the config's permission
chmod 644 ~/.ssh/config # โ // โ ๏ธ
# Don't forget the remote command's quoting
ssh user@example.com echo $HOME # the local's // โ ๏ธ
Common Pitfalls
| Pitfall | Problem | Solution |
|---|---|---|
The scp‘s -p | The preserve’s | The -P for the port |
The rsync‘s no-trailing’s | The directory’s | The trailing’s |
The missing ProxyJump | The unreachable | The -J |
The missing ControlPath | The default’s | The explicit’s |
| The config’s permission | The refusal | The chmod 600 |
| The remote command’s quoting | The local’s | The single-quote’s |
The missing -T | The tty’s | The -T |
The missing -i | The wrong key’s | The -i |
Real-World Examples
1. The basic ssh
ssh user@example.com
2. The remote command
ssh user@example.com 'uptime'
3. The heredoc
ssh user@example.com << 'EOF'
cd /var/log
tail -n 20 syslog
EOF
4. The scp
scp file.txt user@example.com:/tmp/
5. The sftp
sftp user@example.com
6. The rsync
rsync -avz -e ssh project/ user@example.com:/tmp/project/
7. The config
Host example
HostName example.com
User alice
8. The ProxyJump
ssh -J user@bastion user@internal
9. The ControlMaster
ControlMaster auto
ControlPath ~/.ssh/control-%r@%h:%p
ControlPersist 10m
10. The ssh-copy-id
ssh-copy-id user@example.com
Visual: The ssh’s Syntax
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ssh [options] [user@]host [command] โ
โ โ โ
โ โโโ -p PORT the port's โ
โ โโโ -i KEY the key's โ
โ โโโ -L the local's forward โ
โ โโโ -R the remote's forward โ
โ โโโ -D the dynamic's โ
โ โโโ -J HOST the jump's โ
โ โโโ -v the verbose's โ
โ โโโ -T the no-tty's โ
โ โ
โ ssh user@host 'command' โ
โ โ the remote's command's โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Visual: The File’s Transfer’s
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ LOCAL REMOTE โ
โ โ โ โ
โ โ scp file.txt โโโโโโโโโบ โ /tmp/ โ
โ โ โ โ
โ โ โโโโโโโโโ scp /tmp/f โ โ
โ โ โ โ
โ โ rsync -avz โโโโโโโโโโโบ โ the delta's โ
โ โ โ โ
โ โ sftp (the interactive's)โ โ
โ โ โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Visual: The ProxyJump
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ THE LOCAL โ
โ โ โ
โ โ ssh -J bastion internal โ
โ โผ โ
โ THE BASTION (the public's) โ
โ โ โ
โ โ the forward's โ
โ โผ โ
โ THE INTERNAL (the private's) โ
โ โ
โ The bastion's is the public's, and the โ
โ internal's is the private's. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Visual: The ControlMaster
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ WITHOUT ControlMaster โ
โ ssh example โ the full's handshake's โ
โ scp file โ the full's handshake's โ
โ ssh example โ the full's handshake's โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค
โ WITH ControlMaster โ
โ ssh example โ the master's connection โ
โ scp file โ the reuse's โ
โ ssh example โ the reuse's โ
โ โ
โ The reuse's is the fast's. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Visual: The ssh’s Config
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ ~/.ssh/config โ
โ โ โ
โ โโโ Host * โ
โ โ ServerAliveInterval 60 โ
โ โ ControlMaster auto โ
โ โ ControlPersist 10m โ
โ โ โ
โ โโโ Host example โ
โ โ HostName example.com โ
โ โ User alice โ
โ โ Port 2222 โ
โ โ โ
โ โโโ Host internal โ
โ HostName 10.0.0.5 โ
โ User alice โ
โ ProxyJump bastion โ
โ โ
โ The Host * is the defaults's, and the โ
โ specific's is the override's. โ
โ โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
Summary
| Item | Value |
|---|---|
| The basic | ssh user@host |
| The port | ssh -p PORT |
| The key | ssh -i KEY |
| The remote command | ssh user@host 'command' |
| The upload | scp file user@host:/path |
| The download | scp user@host:/path file |
| The interactive | sftp user@host |
| The delta’s | rsync -avz -e ssh |
| The alias’s | ~/.ssh/config |
| The bastion’s | ProxyJump |
| The reuse’s | ControlMaster |
Key takeaways:
- The
ssh user@hostis the basic’s, and theuser@hostis the pattern’s โ the user’s omission is the local’s, and the-pand the-iare the common’s options - The
ssh user@host 'command'runs the remote’s command’s โ the single-quote’s is the remote’s, and the double-quote’s is the local’s interpolation’s - The
scp‘s is the simple’s, and thesftp‘s is the interactive’s โ thescp‘s-Pis the port’s (the uppercase’s), and the-pis the preserve’s - The
rsync‘s is the delta’s, and the trailing slash’s is the distinction’s โ theproject/‘s is the content’s, and theproject‘s is the directory’s - The
~/.ssh/configis the alias’s โ theHost, theHostName, theUser, thePort, theIdentityFileare the common’s - The
ProxyJumpis the bastion’s โ the-Jis the modern’s, and theProxyCommand‘s-Wis the legacy’s - The
ControlMasteris the connection’s reuse’s โ theauto, theControlPath, theControlPersistare the three, and the reuse’s is the performance’s - The
ssh-copy-idis the public’s key’s copy’s โ the copy’s is the passwordless’s, and theauthorized_keys‘s is the result’s - The
ServerAliveIntervalis the keepalive’s โ the interval’s and the count’s are the two, and the two are the disconnect’s prevention’s - The config’s permission is the requirement’s โ the
chmod 600 ~/.ssh/configis the security’s
Remember: The ssh‘s is the remote’s, and the scp‘s and the sftp‘s and the rsync‘s are the file’s. The ~/.ssh/config‘s is the alias’s, and the ProxyJump‘s is the bastion’s. The ControlMaster‘s is the reuse’s, and the ssh-copy-id‘s is the passwordless’s. The SSH’s is the daily’s, and the daily’s is the skill’s.
Stop using slow, ad-bloated tool sites! ๐คฎ
๐ Search “KandZ Tools” on Google to use many professional utilities for free.
KandZ.me is the ultimate minimalist hub for:
โ
Finance (Mortgage, Interest, Inflation)
โ
Tech (Base64, JSON, Dev Suite, IP)
โ
Health (BMI, BMR, TDEE)
โ
Productivity (Timer, Workspace, QR)
โก๏ธ Fast & Private
๐ No data leaves your device
๐ 100% Free
๐ Use it now: https://tools.kandz.me
๐ Bookmark itโyouโll need it later!