The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Connect to a host | ssh deploy@example.com | View examples |
| Use a non-default port | ssh -p 2222 deploy@example.com | View examples |
| Use a host alias | ssh production | View examples |
| Inspect effective configuration | ssh -G production | View examples |
| Show a public-key fingerprint | ssh-keygen -lf ~/.ssh/id_ed25519.pub | View examples |
| Generate an Ed25519 key | ssh-keygen -t ed25519 -a 64 -C 'deploy access' | View examples |
| Load a key into the agent | ssh-add ~/.ssh/id_ed25519 | View examples |
| Forward a local port | ssh -N -L 127.0.0.1:15432:db.internal:5432 bastion | View examples |
| Forward a remote port | ssh -N -R 127.0.0.1:18080:localhost:8080 server | View examples |
| Copy one file | scp -- report.pdf deploy@example.com:/srv/reports/ | View examples |
| Open an SFTP session | sftp deploy@example.com | View examples |
| Trace connection setup | ssh -vvv production | View examples |
SSH secures transport but still requires authentic host verification and careful credential handling. Use per-host configuration, modern keys protected by passphrases, exact forwarding addresses, and verbose diagnostics before weakening checks. Treat first-contact host keys as an identity decision.
Step by step
Detailed examples
Put stable connection policy in ssh_config
Per-user ~/.ssh/config can define HostName, User, Port, IdentityFile, and ProxyJump. Protect it and private keys from other users. Host aliases reduce repeated flags and centralize changes; inspect the resolved result with ssh -G.
Host production
HostName app.example.com
User deploy
Port 2222
IdentityFile ~/.ssh/id_ed25519
IdentitiesOnly yes Protect private keys and verify fingerprints
Ed25519 is a strong default where supported. A passphrase protects a copied private-key file; an agent caches decrypted use for a session. Share only the .pub file, verify fingerprints through a trusted channel, and rotate authorized_keys entries deliberately.
ssh-keygen -t ed25519 -a 64 -C 'deploy access'
ssh-keygen -lf ~/.ssh/id_ed25519.pub
ssh-add ~/.ssh/id_ed25519 Bind tunnels to the narrowest interface
-L opens a listener on the client; -R opens one on the server. Explicit 127.0.0.1 prevents unintended network exposure. -N requests no remote command, and ExitOnForwardFailure makes setup fail when forwarding cannot be established. Forwarding is access and must be authorized.
ssh -N -o ExitOnForwardFailure=yes \
-L 127.0.0.1:15432:db.internal:5432 \
bastion Use SFTP semantics and stage sensitive deployments
Modern scp uses SFTP by default, but shell and path interpretation still warrant quoting and an option terminator for local operands. For repeatable directory synchronization consider rsync over SSH. Upload to a staging name, validate checksums and ownership, then move atomically where possible.
sha256sum -- report.pdf
scp -- report.pdf deploy@example.com:/srv/reports/report.pdf.pending
ssh deploy@example.com 'sha256sum -- /srv/reports/report.pdf.pending' Diagnose without disabling host authentication
Host keys authenticate servers. A changed key may be a legitimate rebuild or an attack; verify it through an independent channel before editing known_hosts. Use ssh -G for configuration and -vvv for negotiation. Do not normalize StrictHostKeyChecking=no as a troubleshooting step.
ssh -G production | sed -n '1,40p'
ssh-keygen -F app.example.com
ssh -vvv production Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



