Lesson 21 / الدرس 21
Connecting to a server with ssh / الاتصال بخادم عبر ssh
Everything you have learned works unchanged on a machine in another country. One command opens a shell there, and the same commands you have been typing all course apply.
كل ما تعلمته يعمل دون تغيير على جهاز في بلد آخر. وأمر واحد يفتح shell هناك، وتنطبق الأوامر نفسها التي كنت تكتبها طوال الدورة.
ssh — secure shell — connects you to a shell on another machine. The connection is encrypted, which is the same protection lesson 12 of the web course described, and once you are in, the prompt is a prompt: ls, cd, tail -f and everything else behave exactly as they do at home.
ls وcd وtail -f وكل ما عداها تتصرف كما تتصرف عندك تمامًا.ssh ahmed@203.0.113.10 connect as a user, by address
ssh ahmed@example.com the same, by name — DNS resolves it
ssh -p 2222 ahmed@example.com a different port (lesson 5 of the web course)
ssh -i ~/.ssh/id_ed25519 … use a particular key
exit come back to your own machine
Keys, not passwords
You can log in with a password, and you should not. A key pair is two files: a private key that never leaves your machine and a public key you copy to the server. The server challenges you to prove you hold the private one. It is the same public-and-private arrangement as the certificates in the web course, used the other way round — here you are proving who you are.
ssh-keygen -t ed25519 -C "ahmed@laptop" make a pair, once, ever
ssh-copy-id ahmed@example.com send the PUBLIC one to the server
ssh ahmed@example.com no password from now on
~/.ssh/id_ed25519 the private key — permission 600, never shared, never committed
~/.ssh/id_ed25519.pub the public key — safe to copy anywhere
.pub on the end is the only thing telling them apart.
.pub في الآخر هو الشيء الوحيد الذي يميّزهما.Moving files: scp and rsync
scp report.pdf ahmed@example.com:~/ one file, up
scp ahmed@example.com:~/error.log . one file, down
scp -r site/ ahmed@example.com:~/public_html/ a whole directory
rsync -av site/ ahmed@example.com:~/public_html/ only what changed
rsync is better for anything you will send more than once, because it compares first and transfers only the differences. This site is deployed with exactly that command. rsync أفضل لأي شيء سترسله أكثر من مرة، لأنه يقارن أولًا وينقل الفروق فقط. وهذا الموقع يُنشر بذلك الأمر بالضبط.pwd وwhoami قبل أي شيء مدمّر، لتعرف على أي جهاز أنت — فالأمر المقصود لحاسوبك مكتوبًا في مِحَث خادم حادثة شائعة فعلًا. ولا تنفّذ rm -rf أبدًا ومسارُه فيه متغيّر. واجعل مِحَث الخادم يبدو مختلفًا عن مِحَثّك، فلا يُخلط بينهما بنظرة.
A connection that drops takes your running command with it, which is why a long job over ssh needs care. nohup command & from lesson 19 is one answer; the better one is tmux or screen, which keep a session alive on the server so you can disconnect, go home, reconnect and find everything exactly as you left it.
ssh عناية. وnohup command & من الدرس 19 جواب؛ والأفضل منه tmux أو screen، فهما يبقيان جلسة حية على الخادم فتستطيع الانقطاع والذهاب إلى البيت وإعادة الاتصال فتجد كل شيء كما تركته تمامًا.~/.ssh/config وكفّ عن إعادة كتابتها. أربعة أسطر — Host live، ثم HostName وUser وIdentityFile مزاحة تحته — ويصير ssh live هو الأمر كله. ويقرأ scp وrsync الملف نفسه، فيقصران أيضًا.Try it live / جرّب بنفسك
Check yourself / اختبر نفسك
1. Which of the two key files may be copied to a server?
The public one is meant to be distributed. The private one never leaves your machine, and anyone holding a copy can log in as you.
2.
What does the colon do in scp file ahmed@example.com:~/?
scp file ahmed@example.com:~/؟Before the colon names the machine, after it is a path there. Leaving the colon out makes it an ordinary local copy with a strange filename.
3.
Why run pwd and whoami before a destructive command?
pwd وwhoami قبل أمر مدمّر؟That is exactly the danger of ssh being seamless. A command meant for your laptop, typed into a server prompt, is a common and expensive accident.
Score / النتيجة: 0 / 3
Your task / مهمتك
If you have a server you may use, connect to it and report the session: what whoami, pwd and ls told you, and one thing you learned about the machine. If you have no server, generate a key pair on your own machine instead and report that: the two files, their permissions, and which one you would send where. Either way, explain the public and private split in your own words.
إن كان لديك خادم يجوز لك استخدامه، فاتصل به وأبلغ عن الجلسة: ماذا أخبرك whoami وpwd وls، وشيء واحد تعلمته عن الجهاز. وإن لم يكن لديك خادم، فولّد زوج مفاتيح على جهازك بدلًا من ذلك وأبلغ عنه: الملفان وصلاحياتهما وأيهما سترسل وإلى أين. وفي الحالتين، اشرح انقسام العام والخاص بكلماتك.
- A real session or a real key pair, from your own machine جلسة حقيقية أو زوج مفاتيح حقيقي من جهازك
- Permissions of the private key shown صلاحيات المفتاح الخاص معروضة
- Which file goes where, and which never moves أي ملف يذهب إلى أين، وأيهما لا يتحرك أبدًا
- No private key content anywhere in what you hand in لا محتوى مفتاح خاص في أي موضع مما تسلّمه