3 ms·
In addition to the traditional | way of adding public key to target hosts, ssh-copy-id [1] is a wrapper script (shipped by most distros, for macOS it is a separ
by terrywang 7y ago
In addition to the traditional | way of adding public key to target hosts, ssh-copy-id [1] is a wrapper script (shipped by most distros, for macOS it is a separate formula) which can be used to batch add a public key target hosts (love to use it prep for Ansible).
Put the target hosts in a file e.g. ssh_ducks
while read -r i; do ssh-copy-id -i /path/to/ops_ed25519.pub <user>@$i -f; done <ssh_ducks
storm (ssh like a boss), it works well when managing (~/.ssh/config) in CLI / scripts but it has an annoying bug [2] (not yet fixed) that will silently convert ssh_config Host keywords to lowercase (luckily ONLY arguments are case sensitive, NOT keywords, otherwise it'll be easier to detect), annoying.
Otherwise, for small to medium scale SSH access, I prefer to use jumpserver (open source 4A bastion / remote access gateway) behind VPN (WireGuard of course, for now, self-hosted or Tailscale), a lot easier to deploy in comparison to Teleport, user-friendly UI for average users.
[1]: https://github.com/openssh/openssh-portable/blob/master/contrib/ssh-copy-id https://github.com/openssh/openssh-portable/blob/master/cont...
[2]: https://github.com/emre/storm/issues/157 https://github.com/emre/storm/issues/157
- ryall 7y agoAnsible can prep a host for Ansible...