Add cli docs for infisical ssh connect command

This commit is contained in:
Tuan Dang
2025-04-17 22:40:43 -07:00
parent 0265665e83
commit 796f5510ca
+45 -15
View File
@@ -7,10 +7,38 @@ description: "Generate SSH credentials with the CLI"
[Infisical SSH](/documentation/platform/ssh) lets you issue SSH credentials to clients to provide short-lived, secure SSH access to infrastructure. [Infisical SSH](/documentation/platform/ssh) lets you issue SSH credentials to clients to provide short-lived, secure SSH access to infrastructure.
This command enables you to obtain SSH credentials used to access a remote host; we recommend using the `issue-credentials` sub-command to generate dynamic SSH credentials for each SSH session. This command enables you to obtain SSH credentials used to access a remote host. We recommend using the `connect` sub-command which handles the full workflow of issuing credentials and establishing an SSH connection in one step.
### Sub-commands ### Sub-commands
<Accordion title="infisical ssh connect">
This command is used to connect to an SSH host using issued credentials. It will automatically issue credentials and either add them to your SSH agent or write them to disk before establishing an SSH connection.
```bash
$ infisical ssh connect
```
### Flags
<Accordion title="--hostname">
The hostname of the SSH host to connect to. If not provided, you will be prompted to select from available hosts.
</Accordion>
<Accordion title="--loginUser">
The login user for the SSH connection. If not provided, you will be prompted to select from available login users.
</Accordion>
<Accordion title="--writeHostCaToFile">
Whether to write the Host CA public key to ~/.ssh/known_hosts if it doesn't already exist.
Default value: `true`
</Accordion>
<Accordion title="--outFilePath">
The path to write the SSH credentials to such as ~/.ssh, ./some_folder, ./some_folder/id_rsa-cert.pub. If not provided, the credentials will be added to the SSH agent and used to establish an interactive SSH connection.
</Accordion>
<Accordion title="--token">
An authenticated token to use to authenticate with Infisical.
</Accordion>
</Accordion>
<Accordion title="infisical ssh issue-credentials"> <Accordion title="infisical ssh issue-credentials">
This command is used to issue SSH credentials (SSH certificate, public key, and private key) against a certificate template. This command is used to issue SSH credentials (SSH certificate, public key, and private key) against a certificate template.
@@ -29,43 +57,44 @@ This command enables you to obtain SSH credentials used to access a remote host;
</Accordion> </Accordion>
<Accordion title="--addToAgent"> <Accordion title="--addToAgent">
Whether to add issued SSH credentials to the SSH agent. Whether to add issued SSH credentials to the SSH agent.
Default value: `false` Default value: `false`
Note that either the `--outFilePath` or `--addToAgent` flag must be set for the sub-command to execute successfully. Note that either the `--outFilePath` or `--addToAgent` flag must be set for the sub-command to execute successfully.
</Accordion> </Accordion>
<Accordion title="--outFilePath"> <Accordion title="--outFilePath">
The path to write the SSH credentials to such as `~/.ssh`, `./some_folder`, `./some_folder/id_rsa-cert.pub`. If not provided, the credentials will be saved to the current working directory where the command is run. The path to write the SSH credentials to such as `~/.ssh`, `./some_folder`, `./some_folder/id_rsa-cert.pub`. If not provided, the credentials will be saved to the current working directory where the command is run.
Note that either the `--outFilePath` or `--addToAgent` flag must be set for the sub-command to execute successfully. Note that either the `--outFilePath` or `--addToAgent` flag must be set for the sub-command to execute successfully.
</Accordion> </Accordion>
<Accordion title="--keyAlgorithm"> <Accordion title="--keyAlgorithm">
The key algorithm to issue SSH credentials for. The key algorithm to issue SSH credentials for.
Default value: `RSA_2048` Default value: `RSA_2048`
Available options: `RSA_2048`, `RSA_4096`, `EC_prime256v1`, `EC_secp384r1`. Available options: `RSA_2048`, `RSA_4096`, `EC_prime256v1`, `EC_secp384r1`.
</Accordion> </Accordion>
<Accordion title="--certType"> <Accordion title="--certType">
The certificate type to issue SSH credentials for. The certificate type to issue SSH credentials for.
Default value: `user` Default value: `user`
Available options: `user` or `host` Available options: `user` or `host`
</Accordion> </Accordion>
<Accordion title="--ttl"> <Accordion title="--ttl">
The time-to-live (TTL) for the issued SSH certificate (e.g. `2 days`, `1d`, `2h`, `1y`). The time-to-live (TTL) for the issued SSH certificate (e.g. `2 days`, `1d`, `2h`, `1y`).
Defaults to the Default TTL value set in the certificate template. Defaults to the Default TTL value set in the certificate template.
</Accordion> </Accordion>
<Accordion title="--keyId"> <Accordion title="--keyId">
A custom Key ID to issue SSH credentials for. A custom Key ID to issue SSH credentials for.
Defaults to the autogenerated Key ID by Infisical. Defaults to the autogenerated Key ID by Infisical.
</Accordion> </Accordion>
<Accordion title="--token"> <Accordion title="--token">
An authenticated token to use to issue SSH credentials. An authenticated token to use to issue SSH credentials.
</Accordion> </Accordion>
</Accordion> </Accordion>
<Accordion title="infisical ssh sign-key"> <Accordion title="infisical ssh sign-key">
@@ -95,22 +124,23 @@ This command enables you to obtain SSH credentials used to access a remote host;
</Accordion> </Accordion>
<Accordion title="--certType"> <Accordion title="--certType">
The certificate type to issue SSH credentials for. The certificate type to issue SSH credentials for.
Default value: `user` Default value: `user`
Available options: `user` or `host` Available options: `user` or `host`
</Accordion> </Accordion>
<Accordion title="--ttl"> <Accordion title="--ttl">
The time-to-live (TTL) for the issued SSH certificate (e.g. `2 days`, `1d`, `2h`, `1y`). The time-to-live (TTL) for the issued SSH certificate (e.g. `2 days`, `1d`, `2h`, `1y`).
Defaults to the Default TTL value set in the certificate template. Defaults to the Default TTL value set in the certificate template.
</Accordion> </Accordion>
<Accordion title="--keyId"> <Accordion title="--keyId">
A custom Key ID to issue SSH credentials for. A custom Key ID to issue SSH credentials for.
Defaults to the autogenerated Key ID by Infisical. Defaults to the autogenerated Key ID by Infisical.
</Accordion> </Accordion>
<Accordion title="--token"> <Accordion title="--token">
An authenticated token to use to issue SSH credentials. An authenticated token to use to issue SSH credentials.
</Accordion> </Accordion>
</Accordion>
</Accordion>