SSH productivity tips
blogs.perl.org
blogs.perl.org
A terminal multiplexer is an absolute must if your connection is likely to be interrupted. Closing the laptop, moving to a different room and picking up right where you left off is great.
TCPKeepAlive
Specifies whether the system should send TCP keepalive messages to the other side. If they are sent, death of the connection or crash of one of the machines will be properly noticed. However, this means that connections will die if the route is down temporarily, and some people find it annoying.
I thought it was a nice overview of some things I use a lot (control master, and nicknames in .config) and included some things I didn't know, like the control persistence and some of the nickname wildcarding. It shouldn't be dismissed just because it isn't about screen/tmux.
Even if I don't need to be logged in to the server at all, I still do it so it keeps the master connection open, and then speed up the rsyncs.
But doing git push all is out of the question for me, because I'm rsyncing while developing, so I'd need to constantly commit and push tiny nonsensical commits to the server, and then do a massive rebase afterwards. In effect, it's more work and gains me nothing.
The idea of repeatedly writing code and rsyncing it up to a production server while adding new features/whatever seems incredibly error prone to me. And that's not even to touch on whether or not there's automated testing (in the form of unit/integration/whatever tests in the code).
My reasons: I don't have to pollute my laptop with various (sometimes mutually exclusive) servers - virtualenv &co are great, but can only go so far, and VMs are much harder on the battery; trivial for other people (colleagues, clients) to see WIP, even if my laptop is suspended.
Using TRAMP for emacs to tab-complete remote filenames is really nice, and much faster if you have a control connection already established.
I've not come across the ControlPersist option before - it's something I'm going to have a poke with to see if it can replace my scripts that fire off a bunch of common host control connections in the background, and use autossh to resume them when I get a net connection or wake the laptop from sleep.
The biggest downside to ControlMaster in general is when you accidentally close (well, kill) the master session, and everything else dies along with it. The usual behaviour is to close that channel on EOF, but wait until all other muxed connections are closed before actually exiting. If you forget it's the master and Ctrl-C it, bye bye sessions.
My backgrounding stuff is currently a horrible mess of Perl scripts, and a bit flakey when it comes to hostname/option parsing, but I might give it a tidy and stick it up on github at some point.
[ui]
ssh = ssh -o ControlMaster=no -o ControlPersist=noTmux is great even if you're not using it as a process manager; it dramatically increased my productivity at the terminal (which is most of my day)
No, you'll want to actually use rxvt-unicode [1] on X11 on your Mac. The X implementation is annoying at times on OS X, but using a great terminal is worth it if you spend all your time in one. iTerm2 is nice, and Lion's new Terminal.app isn't bad, but programs like vim and tmux are designed with real xterm-compatible terminals in mind [2].
[1]: http://dist.schmorp.de/rxvt-unicode/
[2]: For instance, you can enter copy-mode in tmux 1.5 with a mouse scroll if you are using xterm or rxvt-unicode
defscrollback 30000 term xterm-color termcapinfo xterm ti@:te@ # scroll wheel action!
escape ^Tt # Instead of Control-a, make the escape/command character be Control-b
"Ctrl-a d" and "screen -r"
I'd love to hear how you use screen, for example. Do you use multiple sessions or windows? Split screen?
Ctrl-a c (to create a new terminal)
Ctrl-a 1 (to go to the first terminal)
Ctrl-a 2 (second, etc)
If you're an emacs user, you might also want to change the command key away from something as essential as the default bind for beginning-of-line. I myself use Ctrl-T. In .screenrc, that would be: escape ^Tt
The screen manpage is also very good.There are some other features, but with these you're using much of the power of screen. Takes a few days to get used to, but it's one of those "how did I ever live without this" tools.
My biggest use of screen is for running a persistent Irssi session on my server, and connecting to that from whatever terminal or mobile device I happen to be sitting in front of. In that case, I have just a couple active windows, but only one that I use 95% of the time.
I have a similar persistent screen session on my work machine for running Irssi's SILC client to chat with co-workers.
I also use screen for my primary workflow, because a lot of my development takes place on servers. I'll start a screen session on each server, and create a new window for each type of task I'm performing. Eg, I have a window each for `htop`, mongodb console, vim, git, and for running the program I'm working on, plus a few others for one-off tasks like installing a new package or editing a system configuration file.
Some tips I have include:
- Set up a nice .screenrc file, and make yourself a customized "caption" line, which will give you a status bar of sorts that will list all your open windows. Mine is `caption always "%{= dd}%{+b ky}%{+ .b} $LOGNAME@%H %{-} %{.y}%-w%50>%{+ Kg} %n %t %{-}%+w%<%{-}"`
- Similary, either get in the habit of naming your windows, or set up your shell to properly report commands to screen so it can automatically name them based on the command you've run. My zshell config does this for both screen and gnome-terminal: https://github.com/jreese/oh-my-zsh/blob/jreese/custom/scree...
- Ctrl-a, Ctrl-a is a great combination for "alt-tabbing" between windows
- I set my least-used window to #0, as it's the "hardest" number to hit after ctrl-a, and I put my most used windows between #1 and #5 for easy one-handed switching.
- Ctrl-a Escape is the easiest way to get into copy mode to view your scrollback buffer. Ctrl-a [ is equivalent, but IMO using escape instead allows me to start moving my right hand to the cursor/paging keys while I'm still using my left hand to enter copy mode.
screen -x
Attaches a currently running session without detaching it from where ever it's currently attached to. (Note: this can cause some issues if the currently attached session has a larger/smaller terminal).I've also mapped Ctrl-a to ` instead. This makes flipping between the most recent 'windows' as easy as `q.
# Use backtick as the escape character. Use F11 and F12 to switch between ` and
# C-o as the escape sequence. This is useful when pasting text to the terminal
# that may contain backticks in the text.
#
# SOURCE http://superuser.com/questions/74492/whats-the-best-prefix-escape-sequence-for-screen-or-tmux
escape \140\140
bindkey -d -k F1 escape ^O^O # bound to F11
bindkey -d -k F2 escape \140\140 # bound to F12
F11 swaps the escape sequence to C-o (useful for pasting things that might have a ` into the terminal)
F12 swaps the escape back to `Also:
[escape] n -- cycle to the next window in the list
[escape] p -- cycle to the prev window in the list
[escape] " -- see the window list
Turn off the startup message: startup_message off
* Note: 'escape' doesn't refer to the Escape key, but to the key sequence that 'escapes' all screen key bindings (default: C-a). info screenI start my screen sessions thus: screen -e'^\\\'. This makes C-\ the Magic Screen Key Combo. C-\ has other meanings in some contexts, but in practice I've never used it. On the other hand, I use C-a lots, in Emacs and in shells.
Also, if you plan to have more than one screen session, you can name them with -S <argument>. So: screen -e'^\\\' -S blahblah.
You can reattach later: screen -Dr bla. If there's no ambiguity, you don't need to type out the full name.
Even without a bastion host, connection sharing allows for faster scp from your home box to the target host you're running screen on.
In fact, they've little to do which each other. Screens allow you to keep your session running and reattach to it. Control (shared connection) allow you to keep the connection running instead of opening multiple ones.
This is much much faster for example if you're using SCP, or have scripts opening different tunnels, and so on.
<return>~.
ssh -C me@myhost.com
you can also specify a compression algorithm
(man ssh) -C Requests compression of all data (including stdin, stdout, stderr, and data for forwarded X11 and TCP connections). The compression algorithm is the same used by gzip(1), and the “level” can be controlled by the CompressionLevel option for protocol version 1. Compression is desirable on modem lines and other slow connections, but will only slow down things on fast networks. The default value can be set on a host-by-host basis in the configuration files; see the Compression option.
It would be nice if they described what this actually did - I'm hesitant to run options off, especially ones related to authentication.
[1] http://en.wikipedia.org/wiki/Generic_Security_Services_Appli...
UseDNS no # disable rdns lookups in sshd logs. See man sshd_config
There's a possible security benefit to having it enabled, in that it'll try to resolve your rdns, and then confirm your forward dns matches it, but I'm not sure how much of a benefit that is, in practice.There's Dokan SSHFS, (Dokan is a similar endeavor than Fuse FS, only for Windows). For a commercial product, there's apparently ExpanDrive.
In the past, I'm sure that waking the laptop from sleep, or unlocking the screensaver also unlocked the login keychain, and with it updated ssh-agent with my priv key, but recently I've been having to manually unlock it, which is getting to be quite a pain.
(ssh-agent remains running the whole time, ssh-add -l shows the identity when the login chain is unlocked, but is empty otherwise)
Pre-Lion, it was then good until the next reboot. In Lion, it occasionally asks me to re-enter it. As you noticed, this seems to correlate with coming back from sleep or screen lock. It doesn't seem to happen every time, though, so I'm not sure what is going on.
According to ps, it is using the -l option to ssh-agent. The man page and the usage message of ssh-agent do not admit the existence of such an option. Perhaps that has something to do with it.
http://www.opensource.apple.com/source/OpenSSH/OpenSSH-95.1....
ssh -t server1 ssh server2
Will bounce you right to the second server. I'll generally alias this as the second servers name.nc solves that.
Likwise if you use this for scp, it works with nc, but it wont with a double ssh.
mc can access remote filesystems and do complex file and directory management with ease.
Of course, there's always rsync as well.
Fast, easy to use, and nothing special has to be configured at the server besides installing sshd.