> No more password prompts
Is that - you ask - because he's using ssh-agent? No, it's because he doesn't tell you you should be using a password-protected key. Some kung fu. > No more password prompts
Is that - you ask - because he's using ssh-agent? No, it's because he doesn't tell you you should be using a password-protected key. Some kung fu.For continuous deployment you can't easily work around using ssh, but at least the access can be limited to specific commands only.
Let's suppose I have an account tests@host which runs the tests (scripts) that need to login to an array of machines.
In order for keychain to be helpful here, you need two prerequisites.
1) You need to be able to interactively login to tests@host once after bootup; after that you don't need to touch the machine again.
2) Then, the test scripts need to say
. $HOME/.keychain/$HOSTNAME-sh
once before executing any ssh command (the line above
simply imports the ssh-agent session variables into
the current environment).edit: I removed the Nagios references as other posters rightly point out that there are more endemic ways to collect information with Nagios.
In this case you would limit this ssh-key to only be able to execute the nagios monitoring scripts. Nothing else.
You do this in ~/.ssh/config on the remote machine.
For anyone interested here's an SO question with an example: http://stackoverflow.com/questions/402615/how-to-restrict-ss...