Part 6 · 1 chapters · ~8 min

SSH

How SSH works (key exchange, host keys, user authentication), ed25519 keys and passphrases, ssh-agent and the macOS keychain, ~/.ssh/config for hosts, ProxyJump through bastions, agent forwarding risks, local and remote port forwarding, SSH certificates for teams, hardware keys, and modern alternatives (SSM Session Manager, Tailscale SSH, Teleport).

7

Keys, config and tunnels

code
ssh-keygen -t ed25519 -C "feranmi@laptop"           # private key stays local, with a passphrase
ssh-add --apple-use-keychain ~/.ssh/id_ed25519      # macOS: agent + keychain

# ~/.ssh/config
Host bastion
  HostName bastion.example.com
  User ops
Host db-*
  ProxyJump bastion                                  # hop through the bastion without agent forwarding
  User ubuntu
  IdentityFile ~/.ssh/id_ed25519

ssh db-primary                                       # connects via the bastion
ssh -N -L 5433:localhost:5432 db-primary             # local forward: psql -p 5433 reaches the remote Postgres
ssh -N -R 8080:localhost:3000 demo-box               # remote forward: expose a local dev server on demo-box

At team scale, long-lived keys copied into authorized_keys across many servers become impossible to audit or revoke. SSH certificates (short-lived, signed by a CA, as in Vault's SSH engine or Teleport) or identity-aware access (AWS SSM, Tailscale SSH) replace them (Config course).

AN SSH CONNECTION
host keys, user keys, and a tunnel
clientserverTCP :22, key exchange (curve25519)host key signaturecheck known_hosts (trust on first use)
swipe the figure sideways, or tap expand for full screen
1/4
the server proves itself
After key exchange, the server signs with its host key; the client compares it with known_hosts. A changed host key warning means a rebuilt server or an attack: never ignore it blindly.
host key in known_hostsheed the warning