SSH Basics in Practical DevSecOps Labs: Connecting and Running Remote Commands
Secure Shell (SSH) is used throughout the Practical DevSecOps labs to connect to remote machines, run commands, and automate tasks. This article covers the essential SSH skills for lab exercises.
Table of Contents
Connecting to a Remote Machine
To log into a remote machine:
ssh -i ~/.ssh/id_rsa root@prod-$STUDENT_ID
| Argument | Purpose |
|---|---|
-i ~/.ssh/id_rsa |
Specifies the private key for authentication |
root |
The user to log in as |
prod-$STUDENT_ID |
The hostname of the remote server |
Host authenticity prompt
On first connection:
The authenticity of host 'prod-$STUDENT_ID (10.x.x.x)' can't be established.
Are you sure you want to continue connecting (yes/no)?
Type yes to proceed. This adds the server's fingerprint to ~/.ssh/known_hosts.
Skipping the prompt for automation
To avoid the interactive prompt when running automated commands:
ssh-keyscan -H prod-$STUDENT_ID >> ~/.ssh/known_hosts
This pre-populates the known hosts file with the server's fingerprint.
Verifying your connection
hostname # confirms you're on the remote machine
exit # logs out and returns to your original machine
Running Remote Commands
You can run a single command on a remote machine without opening an interactive session:
ssh root@prod-$STUDENT_ID "hostname"
Everything inside the quotes is executed on the remote machine:
prod-$STUDENT_ID
This is useful for automated scripts that need to execute commands on remote servers.
SSH Key Setup (Review)
This section is for reference only. Do not practice these steps in the lab, as they may disrupt your lab infrastructure.
How SSH key-based authentication works
-
Configure the SSH server — Edit
/etc/ssh/sshd_config:RSAAuthentication yes PubKeyAuthentication yesRestart the service:
service sshd restart -
Generate a key pair (if one doesn't exist):
ssh-keygen -t rsaPrivate key:
~/.ssh/id_rsa| Public key:~/.ssh/id_rsa.pub -
Copy the public key to the remote server:
ssh-copy-id -i ~/.ssh/id_rsa.pub user@targetserver
Key concepts
| Concept | Description |
|---|---|
| Private key | Never shared. Used for authentication. |
| Public key | Placed on remote servers in ~/.ssh/authorized_keys. |
| ssh-copy-id | Automates copying the public key to the target server. |
For detailed SSH key management including ssh-add and the authentication agent, see the SSH Key Management & Authentication Agent guide.
Common Questions
| Question | Answer |
|---|---|
| How do I run multiple commands remotely? | Separate them with ; or &&: ssh root@host "cmd1 && cmd2". |
| Can I run a local script on a remote machine? | Use ssh root@host "bash -s" < script.sh to pipe a local script remotely. |
| Why do I see "Permission denied (publickey)"? | The private key doesn't match a public key on the remote server, or the key isn't specified with -i. |
| How do I disconnect from SSH? | Type exit or press Ctrl + D. |
Is ssh-keyscan safe? |
It does not encrypt the host key. For production use, verify the fingerprint manually. In labs, it's safe and recommended. |
Wrap-Up
SSH is the primary method for connecting to remote machines in the Practical DevSecOps labs. Master interactive connections, remote command execution, and host key management to smoothly navigate every exercise that requires server access.