ssh

package
v0.52.6 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 15 Imported by: 0

Documentation

Overview

Package ssh provides SSH operations for remote system management.

Index

Constants

View Source
const (
	// ReasonHostKeyRequired means no expected host key was supplied and the
	// explicit first-contact mode was not requested.
	ReasonHostKeyRequired = "ssh_host_key_required"
	// ReasonHostKeyInvalid means the supplied host key is not one OpenSSH
	// public key.
	ReasonHostKeyInvalid = "ssh_host_key_invalid"
	// ReasonHostKeyMismatch means the target presented a different host key
	// than the one the caller pinned.
	ReasonHostKeyMismatch = "ssh_host_key_mismatch"
	// ReasonHostKeyUnreachable means first-contact pinning could not observe a
	// host key at all.
	ReasonHostKeyUnreachable = "ssh_host_key_unreachable"
)

Typed reasons for refusing an SSH target before any operation runs.

Variables

View Source
var HostKeyProbe = ProbeHostKey

HostKeyProbe observes the host key a target presents. It is a variable so tests can stand in for the network.

Functions

func HostKeyAlgorithmsFor added in v0.52.5

func HostKeyAlgorithmsFor(key ssh.PublicKey) []string

HostKeyAlgorithmsFor returns the SSH host key signature algorithms a probe must offer to be shown the given key. A client that offers its defaults is shown ECDSA or RSA first by a stock sshd, which holds several host keys, so a pinned ed25519 key would be reported as a mismatch.

func HostKeyReason added in v0.52.5

func HostKeyReason(err error) string

HostKeyReason returns the typed reason of a host key refusal, or "".

func ParseHostKey added in v0.52.5

func ParseHostKey(line string) (ssh.PublicKey, error)

ParseHostKey parses one OpenSSH public key line (authorized_keys format, the shape Techstack persists at enrolment).

func Ping

func Ping(host string, port int, timeout time.Duration) bool

Ping checks if the host is reachable

func ProbeHostKey added in v0.52.5

func ProbeHostKey(ctx context.Context, host string, port int, timeout time.Duration, algorithms []string) (ssh.PublicKey, error)

ProbeHostKey completes the SSH key exchange with host:port, captures the presented host key and aborts before any authentication. algorithms limits the host key signature algorithms offered to the server; nil keeps the library defaults.

func SSHVerificationFailed added in v0.52.5

func SSHVerificationFailed(output string) bool

SSHVerificationFailed reports whether ssh(1) output names a host key verification refusal, so retry loops stop instead of waiting for a host that will never match.

Types

type Client

type Client struct {
	// contains filtered or unexported fields
}

Client handles SSH connections

func NewClient

func NewClient(opts ...ClientOption) *Client

NewClient creates a new SSH client

func (*Client) CheckPort

func (c *Client) CheckPort(ctx context.Context, port int) bool

CheckPort checks if a port is available

func (*Client) Close

func (c *Client) Close() error

Close closes the SSH connection

func (*Client) Connect

func (c *Client) Connect() error

Connect establishes an SSH connection

func (*Client) CopyFile

func (c *Client) CopyFile(ctx context.Context, localPath, remotePath string) error

CopyFile copies a file to the remote host

func (*Client) DirExists

func (c *Client) DirExists(ctx context.Context, remotePath string) bool

DirExists checks if a directory exists on the remote host

func (*Client) FileExists

func (c *Client) FileExists(ctx context.Context, remotePath string) bool

FileExists checks if a file exists on the remote host

func (*Client) GetHost

func (c *Client) GetHost() string

GetHost returns the host

func (*Client) GetSystemInfo

func (c *Client) GetSystemInfo(ctx context.Context) (*models.SystemInfo, error)

GetSystemInfo retrieves system information from the remote host

func (*Client) IsConnected

func (c *Client) IsConnected() bool

IsConnected returns whether the client is connected

func (*Client) MkdirAll

func (c *Client) MkdirAll(ctx context.Context, remotePath string) error

MkdirAll creates a directory and parents on the remote host

func (*Client) ReadFile

func (c *Client) ReadFile(ctx context.Context, remotePath string) ([]byte, error)

ReadFile reads a file from the remote host

func (*Client) Run

func (c *Client) Run(ctx context.Context, command string) (string, string, error)

Run executes a command on the remote host

func (*Client) RunWithSudo

func (c *Client) RunWithSudo(ctx context.Context, command string) (string, string, error)

RunWithSudo runs a command with sudo. Multi-line commands are wrapped in sudo bash -c to ensure all lines run with elevated privileges.

func (*Client) WriteFile

func (c *Client) WriteFile(ctx context.Context, remotePath string, content []byte, mode os.FileMode) error

WriteFile writes content to a file on the remote host

type ClientOption

type ClientOption func(*Client)

ClientOption configures the SSH client

func WithAutoAddHostKeys

func WithAutoAddHostKeys(auto bool) ClientOption

WithAutoAddHostKeys automatically adds unknown host keys

func WithHost

func WithHost(host string) ClientOption

WithHost sets the SSH host

func WithKeyPath

func WithKeyPath(keyPath string) ClientOption

WithKeyPath sets the SSH key path

func WithKnownHostsPath

func WithKnownHostsPath(path string) ClientOption

WithKnownHostsPath sets custom known_hosts file path

func WithPort

func WithPort(port int) ClientOption

WithPort sets the SSH port

func WithSSHTimeout

func WithSSHTimeout(timeout time.Duration) ClientOption

WithSSHTimeout sets the connection timeout

func WithUser

func WithUser(user string) ClientOption

WithUser sets the SSH user

type HostKeyError added in v0.52.5

type HostKeyError struct {
	Reason   string
	Address  string
	Expected string
	Observed string
	Err      error
}

HostKeyError is the typed refusal for host key pinning. It never carries the private key material, only public fingerprints.

func (*HostKeyError) Error added in v0.52.5

func (e *HostKeyError) Error() string

func (*HostKeyError) Unwrap added in v0.52.5

func (e *HostKeyError) Unwrap() error

type HostKeyPin added in v0.52.5

type HostKeyPin struct {
	Key         ssh.PublicKey
	Fingerprint string
	Address     string
	// FirstContact is true when the key was observed rather than supplied by
	// the caller. Callers must record this in the operation receipt.
	FirstContact bool
}

HostKeyPin is the host key every later SSH connection to the target must present.

func ResolveHostKey added in v0.52.5

func ResolveHostKey(ctx context.Context, host string, port int, expected string, firstContact bool) (*HostKeyPin, error)

ResolveHostKey returns the pin every connection to host:port must satisfy.

  • expected set: it is parsed and, when the target is reachable, compared with the key the target presents. A different key is ReasonHostKeyMismatch. An unreachable target is not an error here; the later connection still enforces the pin through StrictHostKeyChecking.
  • expected empty and firstContact false: ReasonHostKeyRequired. There is no silent trust on first use.
  • expected empty and firstContact true: the presented key is observed and pinned for this operation; the caller must record the fingerprint.

func (HostKeyPin) KnownHostsLine added in v0.52.5

func (p HostKeyPin) KnownHostsLine() string

KnownHostsLine renders the pin as one known_hosts entry (unhashed).

func (HostKeyPin) WriteKnownHosts added in v0.52.5

func (p HostKeyPin) WriteKnownHosts(path string) error

WriteKnownHosts writes the pin as a private known_hosts file for ssh(1).

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL