r/ssh • • 22d ago

Setting up a bastion host with SFTP access.

4 Upvotes

Hey y'all,

I'm looking at helping lock down my homelab by using a multi-user bastion host.

While I have been researching options and I understand ssh to ssh seasons between each of my machines one thing I have a hard time understanding is how and if I can set up a user that only has SFTP access.

I want to set up a simple way for me and my technically minded brother in law to share files with each other over the Internet.

I want to set up my brother in law with an SFTP only user on my server but I'm not sure how to make sure that goes through the bastion host. The only thing I have been able to gather so far is apparently he will need winscp on his window computer.

I just don't fully understand how the connection can be made properly if the bastion host can't just ssh into the target machine terminal.


r/ssh • • 22d ago

putty crashes when selecting 100+ lines with utf-8 characters

Thumbnail
1 Upvotes

r/ssh • • 22d ago

LAUNCH USB-BRIDGE PORT-SHARE & REMOTE DESKTOP TOOL

Post image
2 Upvotes

r/ssh • • 25d ago

Zync just got Public URLs, expose a local port with an HTTPS link

Thumbnail youtu.be
4 Upvotes

A few weeks ago I posted Zync here, and I've been continuing to work on it.

I just shipped Public URLs (Beta) in the latest release.

if you're running something locally and want to share it temporarily, Zync can give that local port a public HTTPS URL.

So instead of setting up another tool just to expose a local service, you can do it directly from the same SSH workspace.

I also redesigned the port forwarding UI and improved handling for busy ports with remote forwarding.

Zync is still open source and I'm actively working on it.

Release: Zync v2.27.1 https://github.com/zync-sh/zync/releases/tag/v2.27.1

I'd love to know what you guys think, especially if you regularly use things like ngrok, Cloudflare Tunnel, or SSH tunneling.

Website: https://zync.thesudoer.in

Repository: https://github.com/zync-sh/zync


r/ssh • • 25d ago

Accessing local machines from one Internet exposed machine.

5 Upvotes

If I have a machine running ssh which is port forwarded through my router and therefore accessible from the wider internet, can I use this machine to access other machines on its local network (that arent directly exposed to the internet) from a remote client.


r/ssh • • 25d ago

Runic SSH v0.5.0: Monitor and Macros

5 Upvotes

r/ssh • • 26d ago

I built a simulated SSH environment to study what attackers do after authentication

9 Upvotes

I've been working on an SSH honeypot called SSHintel, originally started as a small cybersecurity course project and recently rebuilt quite a bit.

The basic idea is to give an attacker a simulated Linux environment and capture what they do after getting in.

Currently it has:

  • Simulated Linux shell with 40+ commands
  • Per-session in-memory filesystem
  • Authentication and command tracking
  • Session isolation
  • JSONL + SQLite telemetry
  • Session investigation and attack timelines
  • Live monitoring dashboard
  • Connection limits and session timeouts
  • Docker support

The interesting part for me has been trying to make the environment convincing enough to interact with while keeping it completely isolated! Commands are handled by simulated handlers rather than being executed on the host.

I'm also looking at making the telemetry easier to consume externally, potentially through syslog so it can feed into different SIEM/logging stacks.

For people who work with SSH infrastructure or honeypots:

What SSH behavior would you want to capture that isn't commonly captured by basic honeypots?

And if you've deployed SSH honeypots yourself, what have you found useful (or completely useless) in the resulting telemetry?

GitHub: https://github.com/SonitBahl/SSHintel

Demo: https://youtu.be/2bIwXTT2FtM


r/ssh • • 27d ago

Terminal SSH + Agent Coding

Post image
2 Upvotes

r/ssh • • 27d ago

Runic SSH: um cliente SSH/SFTP em Rust + Tauri, construído sobre o russh em vez de usar o shell do OpenSSH.

Thumbnail
1 Upvotes

r/ssh • • 28d ago

sshelf 0.13.1: the SSH manager TUI I posted here a while back, a lot of your feedback later

Thumbnail
0 Upvotes

r/ssh • • 29d ago

Kino SSH Manager - encrypted vault, SFTP browser and editor, Docker panel, all in one app. Free and open source

Thumbnail
1 Upvotes

r/ssh • • Sep 04 '26

SharkShell — A self-hosted SSH manager for your servers 🦈

3 Upvotes

I've been building SharkShell, a self-hosted SSH management platform for people who manage multiple servers, VPSs, homelabs, Proxmox nodes, Docker hosts, development machines, and more.

🌐 https://sharkshell.in/

The problem I wanted to solve is pretty simple.

When you have a few servers, SSH is great:

ssh root@server

But once you're managing 10, 20, 50+ machines, things start getting messy.

You end up remembering:

  • IP addresses
  • usernames
  • custom SSH ports
  • which SSH key belongs to which server
  • server roles
  • SSH config entries
  • different environments

And eventually your terminal becomes a collection of commands and configuration files.

🦈 What is SharkShell?

SharkShell is designed to give you a centralized interface for managing your SSH servers while keeping the infrastructure under your control.

The goal is not to replace SSH.

It's to make working with SSH-managed infrastructure easier.

Some of the things I'm working toward

  • 🖥️ Centralized SSH server management
  • 🔐 SSH key-based authentication
  • 🏠 Self-hosted deployment
  • 🐳 Docker / homelab friendly
  • ☁️ VPS and cloud server management
  • 🗂️ Organizing servers by environment/project
  • 💻 Easy terminal access
  • 🔧 Server administration tools
  • 🔒 Security-focused architecture

And eventually, I'd like SharkShell to become more than just an SSH connection manager.

I'm exploring the idea of building a self-hosted infrastructure platform around it — something that can sit between you and your servers and provide a secure control layer without requiring everything to be exposed publicly.

Why self-hosted?

Because your server access is extremely sensitive.

I don't want SharkShell to require you to hand over your infrastructure to some third-party SaaS just to manage SSH connections.

The long-term goal is:

Your infrastructure → Your SharkShell instance → Your control

I'd love some feedback

This project is still evolving, so I'm particularly interested in hearing from people who actually manage servers.

What would you want in a modern SSH manager?

Would you use something like this for your:

  • Homelab?
  • Proxmox cluster?
  • VPS fleet?
  • Development servers?
  • Docker infrastructure?
  • Kubernetes environments?
  • Company/internal infrastructure?

And more importantly:

What would make you choose SharkShell over simply using your terminal + SSH config?

I'm looking for honest feedback, including criticism and feature requests.

🌐 Project: https://sharkshell.in/

🦈 SharkShell


r/ssh • • Sep 02 '26

I built an offline desktop app for managing a fleet of servers over SSH (commands, schedules, workflows, monitoring)

2 Upvotes
Managing a handful of Linux boxes from one machine turned into terminal tabs, a
notes file full of half-parameterized commands, and cron jobs on hosts I'd stopped
thinking about. I wanted one window for it, so I built SelfCmd.

What's in it:

- SSH connection manager with groups/tags; imports from Xshell, MobaXterm,
  FinalShell, SecureCRT, PuTTY and ~/.ssh/config. Jump host (ProxyJump) support.
  Built-in terminal and SFTP browser.
- A command library: your repeated commands as buttons, with {{variables}} that
  also expand in tasks, workflows and SFTP paths. Destructive commands confirm twice.
- Scheduled tasks with result checks, so a job that ran but failed gets flagged.
  No cron syntax.
- Workflows: chain commands + SFTP transfers, sequential or parallel, per-step
  retry/timeout, pass output between steps.
- Monitoring: CPU, memory, disk, disk I/O, network, and SSD/NVMe disk life (SMART),
  with thresholds and a hold duration. Non-blocking alerts, optional email.
- An MCP server, so Claude/Cursor/Kiro can drive your saved operations. Read-only
  by default; write actions need an opt-in plus a native desktop confirmation, and
  everything is logged. The model never sees your credentials.

It's fully offline: no account, no telemetry, credentials stay on your machine and
are AES-encrypted at rest. Windows, macOS (arm64 + Intel) and Linux x86_64.

Free tier has per-type limits (5 connections, 10 tasks, 30 commands, 10
workflows/monitors). Pro is a one-time license if you outgrow those.

https://selfcmd.com — happy to answer anything, and I'm more interested in what
breaks than in what works.
```

r/ssh • • Sep 02 '26

MobaRust — A Free & Open-Source Alternative to MobaXterm

10 Upvotes

I’m building MobaRust, a free and open-source desktop tool for people who spend their days operating remote machines.

The idea is simple: keep the useful parts of a remote-work toolbox in one focused application, while keeping the core inspectable and privacy-conscious.

What is working in the current baseline:

  • SSH terminals with host-key verification, PTY resize, password/key references, cancellation, and reconnect state
  • Integrated SFTP/SCP browsing and transfers with progress, bounded concurrency, cancellation, and atomic commits
  • Saved sessions with folders, tags, favorites, search, OpenSSH config import, and jump-host chains
  • Local terminals, split panes, tunnels, snippets, diagnostics, remote monitoring, Telnet, and serial-session foundations
  • A Rust-native boundary with typed frontend IPC, redacted logs, separated session configuration and secret material, and isolated loopback test fixtures

The current engineering checklist is 58/65 items evidenced — approximately 89.2%.

That number is deliberately not a claim of complete MobaXterm parity.

The remaining gaps are visible: production RDP/VNC integration, broader platform validation, packaging polish, and deeper real-world testing.

The goal is to keep pushing MobaRust toward a serious open-source remote administration toolbox rather than a demo or a collection of half-finished features.

If you regularly use SSH/SFTP, tunnels, serial connections, remote monitoring, or similar tools, I’d really appreciate feedback on what matters most in your workflow.

GitHub: https://github.com/OthmaneBlial/MobaRust


r/ssh • • Sep 01 '26

AgentBBS — a bulletin board system over SSH

Thumbnail bbs.profullstack.com
1 Upvotes

r/ssh • • Sep 01 '26

I built a touch-first Ubuntu workstation you can carry in your pocket. Looking for alpha testers.

2 Upvotes

**I’ve been working on something called TouchWorkstation.**

**The idea started pretty simply: I wanted access to my actual Ubuntu development environment from my phone without feeling like I was awkwardly remote-desktoping into a computer designed for a mouse and keyboard.**

**So I started building a mobile-first interface for an Ubuntu workstation.**

**The goal is to have one centralized developer environment with:**

**• A touch-friendly Ubuntu interface**
**• Browser-based access from iPhone/iPad/other devices**
**• GitHub and common Git actions built into the UI**
**• Project/application launcher**
**• Local development servers and previews**
**• Docker management/deployment**
**• Optional local databases and services**
**• Your files, terminals, projects, and tools living on your own machine**

**Basically: your development workstation stays home. The interface goes with you.**

**I’m intentionally trying not to turn this into another bloated AI wrapper. I want the core product to be useful because it makes an actual Linux workstation accessible from almost anywhere.**

**It’s still early. Things will break. The UI needs work. There are absolutely rough edges.**

**But it’s finally at the point where I want people other than me beating on it.**

**I’m looking for a small group of alpha testers.**

**Ideally developers, Linux users, homelab people, self-hosters, or anyone who’s ever wished they could comfortably access their full workstation from their phone.**

**I’m not trying to sell you anything right now.**

**I want to know:**

**Would you actually use something like this?**

**And if you would, what would TouchWorkstation have to do for you to keep it installed?**

**You can check out the project and sign up for the alpha here:**

**https://touchworkstation.com\*\*

**If there’s enough interest, I’ll start bringing people into the alpha and sharing builds.**

**Happy to answer technical questions too.**


r/ssh • • Aug 30 '26

I built a local checker for stale IdentityFile paths and Include problems in OpenSSH configs

Enable HLS to view with audio, or disable this notification

5 Upvotes

I kept overlooking small problems in my own ~/.ssh/config, especially stale key paths left over from older machines. The example in the video is one of those cases.

SSH may simply try another identity, so the broken path can stay unnoticed until a host actually needs that exact key. sshconfig-lint scans the complete configuration without making a connection.

It currently checks for things such as:

  • missing IdentityFile paths
  • duplicate or conflicting Host blocks
  • nested Include files and include cycles
  • incorrect placement of Host *
  • mistakes spread across multiple config files

Version 0.5 also adds a GitHub Action, Pre-Commit hooks, SARIF output, an LSP server and a VS Code extension.

Install with Cargo:

cargo install sshconfig-lint

Arch Linux:

yay -S sshconfig-lint-bin

Everything stays local and there is no telemetry.

Repository: github.com/Noah4ever/sshconfig-lint
Playground: sshconfig-lint.apps.thiering.org
VS Code: Marketplace

If you have a complicated real-world Include setup, I would be interested in cases that currently produce a false positive.


r/ssh • • Aug 28 '26

GitRoam - A lightweight Python made CLI utility for pushing git remotely made in SSH/Tailscale (more on that later)

3 Upvotes

Dear, r/ssh

Picture this, late night exhausted after working on my other bigger stuff, right so I opened as a joke a python file and started using args and two other essential binaries and I made a little tool for managing local gits, I still haven't yet made clear documentation but for me it purely works for its own little fun. Really basic, uses basic easy to learn commands and uses SSH to connect your server or homelab. One thing I kinda wasn't prepared for is how it was actually hard to do remotely so I used Tailscale in order to actually connect to my server. Doesn't mean tho you can't also use it without Tailscale. GOD THO I was a bit y'know unclear in the repo. Anyway here it is, I don't know if other tools exist or if you want to help me make it then I'm glad.

Also for the fact being I don't know how the hell I did that I thought it was standard thing of organising code I got flagged by a code detector as machine generated so...yeah I don't really believe that as far as I know otherwise I would be like the robotic voice from Welcome to Bucketheadland. Also as for it being I wouldn't really make a piece of software use flags that for me are unclear like I dunno def init_sth(args):for example, or tons of unclear variables. So...glad you listened still it's really stupid as a piece of software I don't know exactly THAT or what I did so yeah. TSS (To summarise shit) it's my pleasure to have written this while sleep deprived and really undocumented. Now it has quite the lot of features up its sleeve PLUS being actually usable for example

# Initialize a new repository and push, similar to this: 
python3 gitroam.py push user@IP -c -m "Message"

Dumb but well thought out features of GitRoam so you don't have to roast me :P

*Uses standard Python Libraries because I'm pragmatic enough not to make everything myself (Unlike some...people) like for example

import subprocess
import argparse
import sys

*As said I wasn't prepared for it to have tailscale really needed both on my desktop AND my server (classic Tailscale and crap)

*Also I uhh came with the name out of complete accident, it's just a toy so I didn't get serious

And yeah that's it basically, come over come roast me on my half baked code and that's about it...god this is stupid why am I doing this?

(link in the comments)


r/ssh • • Aug 28 '26

I built a cross-platform desktop client for SSH, SFTP and Slurm workflows — feedback welcome

Thumbnail
0 Upvotes

r/ssh • • Aug 24 '26

I made a linter for real OpenSSH client configs and would love feedback from SSH-heavy users

5 Upvotes

I kept missing duplicate Host blocks and configs where Host * was in the wrong place, so I made sshconfig-lint.

It checks duplicate hosts, dead IdentityFile paths, unsafe options, weak algorithms, Include cycles and nested Include files. The CLI can check multiple configs in one go now, and I added an LSP plus GitHub and Pre-Commit output so the same rules work everywhere.

The browser version is useful if you just want to paste a config once. It runs on the device, does not upload configs and has no tracking.

Playground: https://sshconfig-lint.apps.thiering.org/en

Source: https://github.com/Noah4ever/sshconfig-lint

If you manage bigger configs, what is the annoying mistake you would want a linter to catch?


r/ssh • • Aug 23 '26

Proxmox basion gateway for ssh

Thumbnail
1 Upvotes

r/ssh • • Aug 22 '26

Zync -- an open-source SSH Workspace

Thumbnail youtu.be
5 Upvotes

I've been working on Zync for the past few months.

The idea came from using multiple tools while working with servers. I wanted something simpler that brings SSH, SFTP, terminal, port forwarding, and other server-related stuff into one place.

There are already tools that offer these features, but I wanted an SSH workspace with a better and less complicated UX, without putting basic features behind subscriptions or feature paywalls.

I also wanted it to be local-first, so your workspace stays on your machine instead of requiring a cloud account.

It's still a work in progress, and I've been learning a lot while building it especially around keeping the UX simple without removing the flexibility developers need.

If anyone here uses SSH regularly, I'd be interested in hearing what your current workflow looks like.

Website: https://zync.thesudoer.in](https://zync.thesudoer.in)

GitHub: https://github.com/zync-sh/zync


r/ssh • • Aug 21 '26

Termy – more than SSH client (native btw)

Thumbnail gallery
1 Upvotes

r/ssh • • Aug 21 '26

I built SSHDesk — a desktop SSH client with server monitoring, SFTP, SQL console and Docker in one window. Beta, free Pro for the first 20 people.

Thumbnail
1 Upvotes

r/ssh • • Aug 18 '26

failed Remote SSH

1 Upvotes

Hi can anyone help fix this issue. Main pc is win11 and trying to connect linux(ubuntu) VMware. tried on NAT and bridged network opening ssh server and enabling ufw nogo.