SSH Manager
Manage SSH connections, config, keys, and remote server access.
Requirements
ssh,ssh-keygen(pre-installed on Linux/macOS)- No API keys needed
Instructions
List connections — Parse and display
~/.ssh/config:grep -E '^Host |HostName |User |Port |IdentityFile ' ~/.ssh/config 2>/dev/nullFormat as a table: Alias | Hostname | User | Port | Key File
Add new host — Gather details and append to config:
Host myserver HostName 192.168.1.100 User deploy Port 22 IdentityFile ~/.ssh/id_ed25519Always show the block and confirm before writing.
Edit host — Find the block, show current values, apply changes.
Remove host — Remove the
Hostblock. Always confirm before deleting. Back up config first.Generate SSH key:
ssh-keygen -t ed25519 -C "user@hostname" -f ~/.ssh/id_ed25519_myserverRecommend Ed25519 over RSA. Suggest a passphrase for security.
Key audit — List keys and check permissions:
ls -la ~/.ssh/id_* 2>/dev/null # Private keys must be 600, public keys 644 # ~/.ssh/ directory must be 700Test connection:
ssh -o ConnectTimeout=5 -o BatchMode=yes myserver exit 2>&1 && echo "✅ OK" || echo "❌ Failed"
Input Validation
Before writing to SSH config, validate all values:
- Hostname:
^[a-zA-Z0-9._-]+$only - Username:
^[a-zA-Z0-9_-]+$only - Port: numeric, 1–65535
- Reject any input containing shell metacharacters (
;,|,&,$,`)
Edge Cases
- Config doesn't exist: Create
~/.ssh/configwithchmod 644and~/.ssh/withchmod 700. - Duplicate host alias: Warn user — SSH uses first match. Suggest renaming.
- ProxyJump/bastion: Support
ProxyJumpdirective for jump hosts. - Wildcard hosts: Be careful with
Host *blocks — explain they apply globally.
Security
- Never display private key contents — only reference file paths.
- Back up
~/.ssh/configto~/.ssh/config.bakbefore any modification. - Verify permissions after changes:
chmod 700 ~/.ssh && chmod 644 ~/.ssh/config. - Recommend disabling password auth on servers (
PasswordAuthentication no). - Suggest
AddKeysToAgent yesfor convenience with passphrase-protected keys.