SSH cheat sheet
Connect to servers securely. Replace names in angle brackets.
Connect
ssh user@host- Connect to a server
ssh -p 2222 user@host- Use a non-default port
ssh -i ~/.ssh/id_ed25519 user@host- Choose a key
ssh -v user@host- Verbose output for debugging (-vvv for more)
ssh user@host "uptime"- Run one command and return
Keys
ssh-keygen -t ed25519 -C "you@example.com"- Create a modern key pair
ssh-copy-id user@host- Install your public key on a server
chmod 600 ~/.ssh/id_ed25519- Required permissions for the private key
ssh-add ~/.ssh/id_ed25519- Load a key into the agent
ssh-keygen -lf ~/.ssh/id_ed25519.pub- Show a key fingerprint
Config file (~/.ssh/config)
Host web- Alias to use as: ssh web
HostName 203.0.113.5- Real address
User deploy- Login name
IdentityFile ~/.ssh/id_ed25519- Key for this host
Port 2222- Port for this host
Copy files
scp file.txt user@host:/tmp/- Copy a file to a server
scp user@host:/var/log/app.log .- Copy a file from a server
rsync -avz ./site/ user@host:/var/www/site/- Sync a folder efficiently
Tunnels
ssh -L 8080:localhost:80 user@host- Local port 8080 reaches port 80 on the server side
ssh -R 9000:localhost:3000 user@host- Expose your local port 3000 on the server as 9000
ssh -D 1080 user@host- Open a SOCKS proxy on port 1080
ssh -J jump@bastion user@private-host- Connect through a jump host
Learn it properly