Lesson 21 / الدرس 21

Connecting to a server with ssh / الاتصال بخادم عبر ssh

Everything you have learned works unchanged on a machine in another country. One command opens a shell there, and the same commands you have been typing all course apply.

كل ما تعلمته يعمل دون تغيير على جهاز في بلد آخر. وأمر واحد يفتح shell هناك، وتنطبق الأوامر نفسها التي كنت تكتبها طوال الدورة.

ssh — secure shell — connects you to a shell on another machine. The connection is encrypted, which is the same protection lesson 12 of the web course described, and once you are in, the prompt is a prompt: ls, cd, tail -f and everything else behave exactly as they do at home.

ssh ahmed@203.0.113.10            connect as a user, by address
ssh ahmed@example.com             the same, by name — DNS resolves it
ssh -p 2222 ahmed@example.com     a different port (lesson 5 of the web course)
ssh -i ~/.ssh/id_ed25519 …        use a particular key
exit                              come back to your own machine
Note how much of this you already know: a user, a host that DNS resolves, and a port that defaults to 22. It is the same anatomy the web course took apart, in a different protocol.

Keys, not passwords

You can log in with a password, and you should not. A key pair is two files: a private key that never leaves your machine and a public key you copy to the server. The server challenges you to prove you hold the private one. It is the same public-and-private arrangement as the certificates in the web course, used the other way round — here you are proving who you are.

ssh-keygen -t ed25519 -C "ahmed@laptop"      make a pair, once, ever
ssh-copy-id ahmed@example.com                 send the PUBLIC one to the server
ssh ahmed@example.com                         no password from now on

~/.ssh/id_ed25519       the private key — permission 600, never shared, never committed
~/.ssh/id_ed25519.pub   the public key — safe to copy anywhere
Three commands and you never type that password again. Run the demonstration for which file is which — getting these two the wrong way round is the mistake that matters, and the .pub on the end is the only thing telling them apart.

Moving files: scp and rsync

scp report.pdf ahmed@example.com:~/            one file, up
scp ahmed@example.com:~/error.log .           one file, down
scp -r site/ ahmed@example.com:~/public_html/ a whole directory

rsync -av site/ ahmed@example.com:~/public_html/    only what changed
The colon is what makes a path remote — everything before it names the machine, everything after it is a path on that machine. rsync is better for anything you will send more than once, because it compares first and transfers only the differences. This site is deployed with exactly that command.

A connection that drops takes your running command with it, which is why a long job over ssh needs care. nohup command & from lesson 19 is one answer; the better one is tmux or screen, which keep a session alive on the server so you can disconnect, go home, reconnect and find everything exactly as you left it.

Try it live / جرّب بنفسك

Preview / المعاينة

Check yourself / اختبر نفسك

1. Which of the two key files may be copied to a server?

2. What does the colon do in scp file ahmed@example.com:~/?

3. Why run pwd and whoami before a destructive command?

Your task / مهمتك

If you have a server you may use, connect to it and report the session: what whoami, pwd and ls told you, and one thing you learned about the machine. If you have no server, generate a key pair on your own machine instead and report that: the two files, their permissions, and which one you would send where. Either way, explain the public and private split in your own words.

إن كان لديك خادم يجوز لك استخدامه، فاتصل به وأبلغ عن الجلسة: ماذا أخبرك whoami وpwd وls، وشيء واحد تعلمته عن الجهاز. وإن لم يكن لديك خادم، فولّد زوج مفاتيح على جهازك بدلًا من ذلك وأبلغ عنه: الملفان وصلاحياتهما وأيهما سترسل وإلى أين. وفي الحالتين، اشرح انقسام العام والخاص بكلماتك.

  • A real session or a real key pair, from your own machine جلسة حقيقية أو زوج مفاتيح حقيقي من جهازك
  • Permissions of the private key shown صلاحيات المفتاح الخاص معروضة
  • Which file goes where, and which never moves أي ملف يذهب إلى أين، وأيهما لا يتحرك أبدًا
  • No private key content anywhere in what you hand in لا محتوى مفتاح خاص في أي موضع مما تسلّمه
How do you want to submit? / كيف تريد التسليم؟