Files
tty7/docs/remote/ssh.mdx
T
l0ng-ai 00e1aa8218 docs: correct claims that no longer match the code
Audited every page under docs/ against the source. Fixes for what the
code actually does:

- agents: the status vocabulary is idle/working/waiting/done, not
  running/waiting/idle; hook rows grow a separate Uninstall button; the
  Settings table labels read "Copilot CLI" and "Grok Build"; Copy Session
  ID lives in the tab's context menu, not the pane's
- cli: `pane ls --all` reports the owning workspace id, not "tty7-cli";
  document bare `tty7 [PATH]` as the GUI launcher it is instead of listing
  it as unimplemented; note `active_tab` and the `diagnostics` array; wait
  also defaults to $TTY7_PANE
- git: the branch dropdown is a plain list with no search box and no
  stash-and-switch, and checkout is not a palette command; quote the diff
  overlay's own overflow notice rather than the sidebar's
- window: the unread marker tracks a finished agent turn, not any output;
  rows cannot be dragged across groups; the sidebar and `tty7 tab ls`
  resolve labels differently; drop Toggle Commit History and Checkout to
  from the palette's Git group; ~/.ssh/config aliases are not palette
  entries
- terminal: Ctrl+R dedups by command text and shows no directory; Esc does
  not dismiss a ghost suggestion; document Cmd+Enter
- remote: GSSAPI is an ordinary Auth choice, not a managed-connection-only
  mechanism
- fonts: Maple Mono NF CN leads the chain on Windows and Linux only; list
  the real per-platform defaults
- settings paths: the three Links settings and per-pane history were filed
  under the wrong sections
2026-08-11 14:35:54 +08:00

117 lines
4.3 KiB
Plaintext

---
title: "SSH"
description: "A native Rust SSH stack: quick connects, saved profiles, keychain credentials, jump hosts."
---
tty7 speaks SSH itself, over [russh](https://github.com/Eugeny/russh). It never
shells out to the `ssh` binary, and there is no compatibility mode that does.
That is what makes the rest possible: credentials in the OS keychain,
[SFTP](/remote/sftp) in a side panel, [port forwards](/remote/port-forwarding)
you can add mid-session, and authentication prompts drawn as sheets in the pane
instead of a password echoing into your shell.
<Frame caption="Placeholder — screenshot: an SSH connection sheet asking for a key passphrase inside a pane">
<img src="/images/placeholder.svg" alt="Connecting over SSH in tty7" />
</Frame>
## Four ways to connect
<AccordionGroup>
<Accordion title="QuickConnect — type an address">
Open the palette (<kbd>⌘ P</kbd>) and type an address. IPv6 works with
brackets.
```
me@devbox
me@devbox:2222
me@[2001:db8::1]:22
```
</Accordion>
<Accordion title="A saved profile">
Profiles live in **Settings → SSH → Hosts**. Start typing the name in the
palette, or open the *SSH: Manage Profiles…* command.
</Accordion>
<Accordion title="An alias from ~/.ssh/config">
Type an alias you already have and tty7 resolves it natively — common fields,
best effort — then connects over russh. **Settings → SSH → Import from
~/.ssh/config** turns aliases into real profiles.
<Note>
`Match`, `canonicalize*`, and GSSAPI directives are not supported, and
there is no fallback to the system `ssh` when one appears.
</Note>
</Accordion>
<Accordion title="A remote workspace">
The same connection can host whole workspaces on the far machine rather than
a single shell. [Remote workspaces →](/remote/workspaces)
</Accordion>
</AccordionGroup>
## Profiles
**Settings → SSH → Hosts** holds the full connection config. The basics:
| Field | |
|---|---|
| **Name** | A label for this connection |
| **Host** | Hostname or IP |
| **User** | Login user — blank resolves at connect time |
| **Auth** | *Auto* (tries every applicable method), *GSSAPI*, *Password*, *Key*, *Agent*, or *2FA* |
| **Jump host** | Another profile, or a `ProxyJump` chain |
| **Port forwarding** | Rules opened with the connection |
**Defaults** at the top of the list is inherited by every host, so a setting you
want everywhere is set once.
Passwords and key passphrases go in the **OS keychain**, never in
`config.json` and never on disk in plain text. **Forget Password** in a
profile's menu removes the stored one.
### Advanced
Behind **Advanced** on a profile, grouped:
| Group | Fields |
|---|---|
| **Authentication** | Identity files (one path per line, `%h`/`%r` expand), agent forwarding |
| **Proxies** | ProxyCommand (`%h`/`%p`/`%r` substituted), SOCKS5 proxy, HTTP proxy |
| **Algorithms** | KEX algorithms, ciphers, MACs, host-key algorithms, compression |
| **Connection** | Keepalive interval and count, connect timeout, X11 forwarding |
| **Session** | Shell integration, login scripts, skip banner |
Everything blank means "the library default", so you only fill in what you
actually need to override.
## Authentication prompts
Password, key passphrase, and 2FA prompts appear as sheets inside the pane, with
a **Remember (keychain)** option where it makes sense.
## Host keys
Host keys are verified against `known_hosts` by default. A first connection asks
you to confirm the fingerprint; a **changed** key is a much louder prompt that
makes you type `yes` to override, because that is what a changed key deserves.
**Settings → SSH → Security → Verify host keys** turns verification off
entirely. It is on for a reason.
Also under Security: **Warn before closing** a live connection, off by default.
## Reconnecting
<kbd>⌘ ⇧ R</kbd> — or *SSH: Reconnect* in the palette — restarts the session in
the current pane. Useful after a laptop sleeps or a network changes.
## What is not supported
- No fallback to the system `ssh` binary
- No `Match` or `canonicalize*` directives from `~/.ssh/config`
- No GSSAPI *directives* from `~/.ssh/config`. Kerberos `gssapi-with-mic` itself
is supported — pick **GSSAPI** in a profile's Auth field — it is just not
something the config-file resolution path reads