grep -rl "ssh" ./blog

SSH Guides

Remote access done properly: keys instead of passwords, client configuration, hardening the server, and tunneling traffic through an existing connection.

18 articles

CrowdSec vs Fail2ban: Blocking Attackers on Linux Servers Fail2ban bans IPs that fail too often in your logs. CrowdSec does the same and shares signals with every other CrowdSec user. How each works, setup for SSH, the bouncer model, privacy trade-offs, and which to run. Two-Factor Authentication for SSH: TOTP Codes and FIDO2 Security Keys Add a second factor to SSH logins two ways: time-based one-time codes with pam_google_authenticator, or hardware-backed ed25519-sk keys on a YubiKey. Exact sshd configuration, how to avoid locking yourself out, and which to choose. sshfs and rclone mount: Mounting Remote Storage as a Local Folder Mount a server's files over SSH with sshfs, or cloud storage like S3, Backblaze B2, and Google Drive with rclone mount, and use them like any local directory. Setup, fstab and systemd mounts, caching, and when a sync is better than a mount. PAM Explained: How Linux Actually Decides Who Gets In Every login, sudo and ssh session runs through a stack of PAM modules before it succeeds. The four module types, what required and sufficient really do, why order changes the outcome, and how to edit it without locking yourself out. Remote LUKS Unlock with Dropbear in the initramfs An encrypted server cannot boot unattended because something must type the passphrase. Putting a tiny SSH server in the initramfs lets you type it from anywhere. SSH Certificate Authorities: Access Control That Scales How SSH certificates replace authorized_keys sprawl, why they solve revocation and host key verification at once, and how to set up a CA properly. Ansible Basics: Configuration Management Without Agents How Ansible pushes configuration over SSH, what idempotency means in practice, and how to write your first inventory and playbook without adopting a whole methodology. rsync Explained: Flags, Trailing Slashes, and Not Deleting Your Data How the delta algorithm works, what the trailing slash actually changes, why --delete needs --dry-run first, and the flag combinations for backups, mirrors, and migrations. screen vs tmux: Which Terminal Multiplexer Why a multiplexer keeps your session alive when SSH drops, where screen still wins, and how to reattach to the session you left running last week. ssh-agent and Agent Forwarding Explained How ssh-agent holds your decrypted keys, why agent forwarding is convenient and risky, and what ProxyJump does instead. The First Ten Minutes on a New Linux Server A fresh VPS is reachable from the entire internet within seconds of provisioning. Here is the short, ordered list of things to do before you install anything else. SSH Keys Explained: Generating, Using, and Not Losing Them Password authentication over SSH is a liability on any internet-facing server. Key authentication is better in every way and takes two minutes to set up. Here is how keys work, which type to generate, and how to manage them properly. SSH Tunneling Explained: Local, Remote, and Dynamic Port Forwarding SSH can carry more than shells. With -L, -R, and -D it forwards ports through encrypted tunnels, reaching firewalled services, exposing local apps, and acting as a instant SOCKS proxy. tmux Basics for Beginners tmux lets you run terminal sessions that survive disconnects and split a single terminal into multiple panes. This guide covers sessions, windows, panes, and the detach/reattach workflow that makes tmux essential for remote work over SSH. Fail2Ban Setup Fail2ban monitors log files for repeated authentication failures and automatically bans the offending IP addresses using firewall rules. This guide covers installation, configuration, and managing jails for SSH, nginx, and other services. SCP vs SFTP vs rsync SCP, SFTP, and rsync are the three main tools for transferring files over SSH on Linux. This guide covers when to use each, how they work, and practical command examples for common transfer scenarios. SSH Beginner's Guide SSH (Secure Shell) lets you log into remote Linux systems, run commands, and transfer files over an encrypted connection. This guide covers key-based authentication, the SSH config file, port forwarding, and common SSH patterns. SSH Hardening Guide SSH is the most commonly attacked service on internet-facing Linux servers. This guide covers every important sshd_config setting, key management practices, and tools like fail2ban to reduce your exposure.