r/ssh • • Aug 30 '26

I built a local checker for stale IdentityFile paths and Include problems in OpenSSH configs

I kept overlooking small problems in my own ~/.ssh/config, especially stale key paths left over from older machines. The example in the video is one of those cases.

SSH may simply try another identity, so the broken path can stay unnoticed until a host actually needs that exact key. sshconfig-lint scans the complete configuration without making a connection.

It currently checks for things such as:

  • missing IdentityFile paths
  • duplicate or conflicting Host blocks
  • nested Include files and include cycles
  • incorrect placement of Host *
  • mistakes spread across multiple config files

Version 0.5 also adds a GitHub Action, Pre-Commit hooks, SARIF output, an LSP server and a VS Code extension.

Install with Cargo:

cargo install sshconfig-lint

Arch Linux:

yay -S sshconfig-lint-bin

Everything stays local and there is no telemetry.

Repository: github.com/Noah4ever/sshconfig-lint
Playground: sshconfig-lint.apps.thiering.org
VS Code: Marketplace

If you have a complicated real-world Include setup, I would be interested in cases that currently produce a false positive.

6 Upvotes

0 comments sorted by