Part 6 · 1 chapters · ~8 min
SSH
How SSH works (key exchange, host keys, user authentication), ed25519 keys and passphrases, ssh-agent and the macOS keychain, ~/.ssh/config for hosts, ProxyJump through bastions, agent forwarding risks, local and remote port forwarding, SSH certificates for teams, hardware keys, and modern alternatives (SSM Session Manager, Tailscale SSH, Teleport).
7
Keys, config and tunnels
code
ssh-keygen -t ed25519 -C "feranmi@laptop" # private key stays local, with a passphrase ssh-add --apple-use-keychain ~/.ssh/id_ed25519 # macOS: agent + keychain # ~/.ssh/config Host bastion HostName bastion.example.com User ops Host db-* ProxyJump bastion # hop through the bastion without agent forwarding User ubuntu IdentityFile ~/.ssh/id_ed25519 ssh db-primary # connects via the bastion ssh -N -L 5433:localhost:5432 db-primary # local forward: psql -p 5433 reaches the remote Postgres ssh -N -R 8080:localhost:3000 demo-box # remote forward: expose a local dev server on demo-box
At team scale, long-lived keys copied into authorized_keys across many servers become impossible to audit or revoke. SSH certificates (short-lived, signed by a CA, as in Vault's SSH engine or Teleport) or identity-aware access (AWS SSM, Tailscale SSH) replace them (Config course).
AN SSH CONNECTION
host keys, user keys, and a tunnel
swipe the figure sideways, or tap expand for full screen
1/4
the server proves itself
After key exchange, the server signs with its host key; the client compares it with known_hosts. A changed host key warning means a rebuilt server or an attack: never ignore it blindly.
host key in known_hostsheed the warning