Skip to content

Ssh

14 pages
  • SSH key best practices

    In Posts 838 words 4 min

    LinuxSshSecurity

    SSH keys are the de facto standard for authenticating to infrastructure, but poor management turns every deployment into a potential vulnerability. This note collects proven practices: from key generation to revocation and rotation without service …

    SSH keys are the de facto standard for authenticating to infrastructure, but poor management turns every deployment into a potential vulnerability. This note collects proven practices: from key generation to revocation and rotation without service …

  • scp — Secure Copy Over SSH

    In Posts 446 words 3 min

    LinuxSshDevopsSecurityNetworking

    scp — a utility for copying files over SSH using the SSH protocol. It works from the terminal, requires no extra server setup — just a running sshd and working authentication. In an era of rsync and bat, SCP survives as a simple tool for one-off …

    scp — a utility for copying files over SSH using the SSH protocol. It works from the terminal, requires no extra server setup — just a running sshd and working authentication. In an era of rsync and bat, SCP survives as a simple tool for one-off …

  • fail2ban: SSH Jail Configuration

    In Posts 490 words 3 min

    LinuxSshSecurityDevops

    Securing SSH against brute-force attacks is one of the first steps in hardening any server. fail2ban scans logs, detects repeated failed login attempts, and blocks the source via iptables or nftables. This note covers the sshd jail — from …

    Securing SSH against brute-force attacks is one of the first steps in hardening any server. fail2ban scans logs, detects repeated failed login attempts, and blocks the source via iptables or nftables. This note covers the sshd jail — from …

  • tmux on Prod After Screen

    In Posts 701 words 4 min

    LinuxDevopsSsh

    Why We Switched from Screen to tmux Screen was our primary tool for about five years. After migrating the cluster to new servers it became obvious: screen drops sessions on SSH disconnect when hardstatus isn’t configured, and screen -r recovery …

    Why We Switched from Screen to tmux Screen was our primary tool for about five years. After migrating the cluster to new servers it became obvious: screen drops sessions on SSH disconnect when hardstatus isn’t configured, and screen -r recovery …

  • Setting Up Your Own SSH Bastion Server

    In Posts 768 words 4 min

    LinuxSshSecurityDevopsNetworking

    Why You Need a Bastion and Where It Lives A bastion is the single entry point into a private network segment. Instead of exposing SSH on every server to the internet, you funnel traffic through one hardened host with a strict access policy. Typical …

    Why You Need a Bastion and Where It Lives A bastion is the single entry point into a private network segment. Instead of exposing SSH on every server to the internet, you funnel traffic through one hardened host with a strict access policy. Typical …

  • Rsync: Backing Up a Directory Over SSH

    In Posts 414 words 2 min

    LinuxSshDevopsSecurity

    Rsync: Backing Up a Directory Over SSH The classic way to copy a directory to a remote machine is rsync over SSH. No extra ports to open, traffic is encrypted, and the tool itself handles incremental transfers and metadata preservation. One command …

    Rsync: Backing Up a Directory Over SSH The classic way to copy a directory to a remote machine is rsync over SSH. No extra ports to open, traffic is encrypted, and the tool itself handles incremental transfers and metadata preservation. One command …

  • ProxyJump and bastion hosts via ~/.ssh/config

    In Posts 695 words 4 min

    SshDevopsSecurityLinuxNetworking

    Sometimes a server sits in a private network with no public IP. The only entry point is a bastion host with a public address. Typing ssh -J user@bastion user@private every time gets old fast. Here’s how to configure everything in ~/.ssh/config so you …

    Sometimes a server sits in a private network with no public IP. The only entry point is a bastion host with a public address. Typing ssh -J user@bastion user@private every time gets old fast. Here’s how to configure everything in ~/.ssh/config so you …

  • sshd_config: baseline for a test stand

    In Posts 531 words 3 min

    SshSecurityLinuxDevops

    SSH access to a test stand often gets opened in a hurry, and then the logs fill with brute-force attempts. A baseline sshd_config that blocks common attack vectors fits into five parameters and twenty minutes. Why Change Defaults …

    SSH access to a test stand often gets opened in a hurry, and then the logs fill with brute-force attempts. A baseline sshd_config that blocks common attack vectors fits into five parameters and twenty minutes. Why Change Defaults …

  • SSH Config: Wildcards and Dynamic Variable Substitution

    In Posts 831 words 4 min

    SshSecurityDevopsLinux

    SSH reads ~/.ssh/config line by line, but without variables the file quickly becomes copy-paste hell. Here’s how Host patterns, Match exec, and substitution tokens like %h, %r, %l cut config size by orders of magnitude while covering real scenarios — …

    SSH reads ~/.ssh/config line by line, but without variables the file quickly becomes copy-paste hell. Here’s how Host patterns, Match exec, and substitution tokens like %h, %r, %l cut config size by orders of magnitude while covering real scenarios — …

  • SSH Escape Sequences: Reviving a Frozen Terminal

    In Posts 731 words 4 min

    SshLinuxDevopsTroubleshooting

    SSH session froze, Ctrl+C does nothing, Ctrl+D spits out garbage — familiar situation. Before closing the terminal and losing the session, try built-in escape sequences. They operate at the SSH client level before data reaches the remote host. How to …

    SSH session froze, Ctrl+C does nothing, Ctrl+D spits out garbage — familiar situation. Before closing the terminal and losing the session, try built-in escape sequences. They operate at the SSH client level before data reaches the remote host. How to …

  • SSH certificates instead of authorized_keys

    In Posts 892 words 5 min

    SshSecurityLinuxDevops

    authorized_keys works fine for a handful of servers. Once you hit a dozen, it becomes a liability. Onboarding a new developer means manually distributing their public key across every machine. SSH certificates flip this model: one CA signs all public …

    authorized_keys works fine for a handful of servers. Once you hit a dozen, it becomes a liability. Onboarding a new developer means manually distributing their public key across every machine. SSH certificates flip this model: one CA signs all public …

  • Too many authentication failures: SSH ran out of tries

    In Posts 776 words 4 min

    SshOpensshLinuxDevopsSecurity

    Received disconnect from 10.0.0.5 port 22:2: Too many authentication failures followed by Permission denied (publickey) is not a broken server, and it is not necessarily a wrong password. The client spent the attempt budget while walking agent keys …

    Received disconnect from 10.0.0.5 port 22:2: Too many authentication failures followed by Permission denied (publickey) is not a broken server, and it is not necessarily a wrong password. The client spent the attempt budget while walking agent keys …

  • GNU Screen: sessions that survive an SSH drop

    In Posts 1112 words 6 min

    ScreenLinuxSshTerminalDevops

    A long apt upgrade, a migration, a build — then the laptop sleeps. SSH dies, the process gets SIGHUP and dies with it. GNU Screen keeps the terminal on the server: disconnect, come back, the work is still there. It is not a nohup replacement and not …

    A long apt upgrade, a migration, a build — then the laptop sleeps. SSH dies, the process gets SIGHUP and dies with it. GNU Screen keeps the terminal on the server: disconnect, come back, the work is still there. It is not a nohup replacement and not …

  • ssh-connection-manager: a TUI for hosts in ~/.ssh/config

    In Posts 447 words 3 min

    SshDevopsPythonTuiOpenssh

    When ~/.ssh/config holds dozens of stands, bastions, and jump hosts, memorizing aliases stops being fun. ssh-connection-manager is a TUI on top of ordinary OpenSSH: a host list, a filter, a connect via the system ssh, and a way to append a new block …

    When ~/.ssh/config holds dozens of stands, bastions, and jump hosts, memorizing aliases stops being fun. ssh-connection-manager is a TUI on top of ordinary OpenSSH: a host list, a filter, a connect via the system ssh, and a way to append a new block …