Overview
The SSH connector is used by default for all hosts unless another connector is specified:Connection Data
Configure SSH connection using inventory data:str
SSH hostname or IP address to connect to.
int
default:22
SSH port number.
str
SSH username for authentication.
str
SSH password for authentication (not recommended, use keys instead).
str
Path to SSH private key file.
str
Password for encrypted SSH private key.
bool
default:true
Whether to use SSH agent for authentication.
bool
default:true
Whether to search for SSH keys in standard locations.
bool
default:false
Whether to enable SSH agent forwarding.
str
Path to SSH config file.
str
Path to SSH known_hosts file.
str
default:"accept-new"
Host key checking mode:
accept-new, yes, or no.dict
Additional keyword arguments passed to Paramiko’s
SSHClient.connect().int
default:0
Number of connection retry attempts.
float
Minimum delay between retries (seconds).
float
Maximum delay between retries (seconds).
str
default:"sftp"
Protocol for file transfers:
sftp or scp.Inventory Examples
Single Host with SSH Forward Agent
Multiple Hosts with Shared SSH User
Multiple Hosts with Different Users
Using SSH Config File
~/.ssh/config:
Custom SSH Port and Key
Connection Retries
Using SCP Instead of SFTP
Authentication Methods
SSH Agent (Recommended)
Use SSH agent for secure key management:SSH Key File
Specify a private key file:Encrypted SSH Key
Password Authentication (Not Recommended)
Host Key Verification
Control how SSH host keys are verified:Accept New Keys (Default)
Strict Checking
Disable Checking (Not Recommended)
Agent Forwarding
Enable SSH agent forwarding to use local SSH keys on remote hosts:- Accessing Git repositories from remote hosts
- SSHing from one remote host to another
- Using local credentials on remote systems
Advanced Configuration
Paramiko Connection Options
Pass additional options to Paramiko:Custom Known Hosts File
Complete Example
Here’s a comprehensive inventory using SSH connector:File Transfer Methods
The SSH connector supports two file transfer protocols:SFTP (Default)
Recommended for most use cases:- More reliable
- Better error handling
- Works with more SSH server configurations
SCP
Useful for legacy systems:- Compatible with older SSH servers
- Simpler protocol
Troubleshooting
Connection Timeouts
Increase timeout and enable retries:Authentication Failures
Enable verbose logging:- SSH key permissions (
chmod 600 ~/.ssh/id_rsa) - SSH agent is running (
ssh-add -l) - User has correct permissions on remote host
- SSH service is running on remote host
Host Key Verification Failed
Update known_hosts:Source Reference
Location:src/pyinfra/connectors/ssh.py:119
Key Methods
connect()- Establish SSH connectiondisconnect()- Close SSH connectionrun_shell_command()- Execute commands via SSHput_file()- Upload files via SFTP/SCPget_file()- Download files via SFTP/SCP
