The config file and jump hosts
Save connection settings with aliases and reach private machines through a bastion.
Stop typing long commands
Create or edit ~/.ssh/config (mode 600) to give servers short names and settings:
Host web
HostName server.example.com
User ana
Port 2222
IdentityFile ~/.ssh/id_ed25519
Host *
ServerAliveInterval 60Now ssh web expands to ssh -p 2222 -i ~/.ssh/id_ed25519 ana@server.example.com. The Host * block applies to every host: here it sends a keep-alive every 60 seconds so idle sessions are not dropped by firewalls.
NoteSSH uses the first value it finds for each option, reading top to bottom. Put specific Host blocks before general ones such as Host *.
Jump hosts (bastions)
Production machines often have no public SSH access. You reach them through one hardened bastion (jump host) that is exposed. With -J (ProxyJump), SSH connects to the bastion and tunnels onward in one step:
ssh -J ana@bastion.example.com ana@10.0.0.20The same in the config file:
Host internal
HostName 10.0.0.20
User ana
ProxyJump ana@bastion.example.comYour private key stays on your machine. It is not copied to the bastion, which is why ProxyJump is safer than the older agent-forwarding habit.
Test yourself
Answer all the questions, then check them. Finish with every answer right to mark the lesson as done.