4 ms·
And in your ~/.ssh/config that's the ProxyJump directive. Adding a proper configuration for the bastion/jump host and for the target host means you can just to
by davb 6y ago
And in your ~/.ssh/config that's the ProxyJump directive. Adding a proper configuration for the bastion/jump host and for the target host means you can just to "ssh target".
In my case, I usually do "ssh target -t tmux -2 att" to attach to my tmux session, then when I detach it will close the SSH connection (and all of my tunnels).
- mmalone 6y agoThat `tmux` bit is clever. Wonder if you could do that in a `ForceCommand` or something like that so you don’t need to type that part either?
- mod 6y ago(Not OP) I personally don't type my advanced commands, I alias them. So I would use "ssh-target" as my alias there.
- chrisweekly 6y agoSame -- and I comment them heavily, so when (like today per this thread) I learn more about said advanced options, I'm "forced" to update my "docs". Always be capturing your knowledge! :)
- xelxebar 6y agoA combination of `RemoteCommand` and `RequestTTY` should do the trick: Host <host> ... RequestTTY yes RemoteCommand tty The problem is that this will mess up your one-off command invocations of ssh, git ssh connections, etc: $ ssh <host> ls Cannot execute command-line and remote command. However, we can use `Match` blocks to get around that! There are a thousand ways to skin this cat, but one way is to use an environment variable, here `t` for "tmux". Put this at the end of your config: Match exec "test ${t:-0} = 1" RequestTTY yes RemoteCommand tmux has-session && tmux attach-session || tmux and the following Just Work, reattaching tmux sessions as necessary: $ t=1 ssh <host> $ ssh <host> ls
- mmalone 6y agoNice. `Match exec` is one of my favorite things. It's too bad the command being passed to `ssh` (if there is one) isn't available as a `TOKEN` (as far as I can tell). That would put a bow on everything.
- pletnes 6y agoI simply have two configs for machines I ssh to often - one to the «normal shell» and one to a tmux instance with standard name.
- memco 6y agoIncidentally, I just filed a ticket because ProxyJump is not a known keyword in VScode’s SSH config autocomplete. It’s such a handy tool. Only landed in OpenSSH 7.3 in 2016 so it’s not that surprising it isn’t well known.
- jerf 6y agoJust in general, look up .ssh/config and configure it. A lot of software uses ssh to do various things. You can pull a lot of neat tricks with SSH config coming in through a bastion on a non-standard port to a host machine into a shell executed in a docker container with the right .ssh/config, aliased to "machine", and the you can use anything that can run on SSH to "machine" with all that fancy configuration. Check your favorite editor; good odds it can edit files through that mess, or give you a remote directory explorer, or whatever.
- fulafel 6y agoWord of warning: using jump hosts shift your mindset towards building an internal network with lax security, the crunchy outside/soft tasty inside security antipattern. (Yes you don't intend it at the start, but the realities of your later evaluations of where to invest effort security-wise will leave the internal network to rot since you won't think of the scenarios of how it would be compromised)
- Symbiote 6y agoIsn't that typically already the mindset, since most people set up networks with non-routable (10, 192.168 etc) IP addresses?
- fulafel 6y agoIt's a chicken-and-egg situation, yep. But the world seems to be moving towards zero trust networks, distaste towards complexity and opacity brought on by ambiguous rfc1918 addresses, and wide availability of ipv6.