Skip to main content
The SSH connector is pyinfra’s default connector for connecting to remote hosts using SSH. It uses Paramiko for SSH communication and supports various authentication methods.

Overview

The SSH connector is used by default for all hosts unless another connector is specified:

Connection Data

Configure SSH connection using inventory data:
str
SSH hostname or IP address to connect to.
int
default:22
SSH port number.
str
SSH username for authentication.
str
SSH password for authentication (not recommended, use keys instead).
str
Path to SSH private key file.
str
Password for encrypted SSH private key.
bool
default:true
Whether to use SSH agent for authentication.
bool
default:true
Whether to search for SSH keys in standard locations.
bool
default:false
Whether to enable SSH agent forwarding.
str
Path to SSH config file.
str
Path to SSH known_hosts file.
str
default:"accept-new"
Host key checking mode: accept-new, yes, or no.
dict
Additional keyword arguments passed to Paramiko’s SSHClient.connect().
int
default:0
Number of connection retry attempts.
float
Minimum delay between retries (seconds).
float
Maximum delay between retries (seconds).
str
default:"sftp"
Protocol for file transfers: sftp or scp.

Inventory Examples

Single Host with SSH Forward Agent

Multiple Hosts with Shared SSH User

Multiple Hosts with Different Users

Using SSH Config File

With ~/.ssh/config:

Custom SSH Port and Key

Connection Retries

Using SCP Instead of SFTP

Authentication Methods

Use SSH agent for secure key management:

SSH Key File

Specify a private key file:

Encrypted SSH Key

Password authentication is not recommended for production use. Use SSH keys with SSH agent instead.

Host Key Verification

Control how SSH host keys are verified:

Accept New Keys (Default)

Accepts new hosts but verifies known hosts.

Strict Checking

Rejects unknown hosts.
Disabling host key checking makes you vulnerable to man-in-the-middle attacks. Only use in trusted environments.

Agent Forwarding

Enable SSH agent forwarding to use local SSH keys on remote hosts:
Useful for:
  • Accessing Git repositories from remote hosts
  • SSHing from one remote host to another
  • Using local credentials on remote systems

Advanced Configuration

Paramiko Connection Options

Pass additional options to Paramiko:

Custom Known Hosts File

Complete Example

Here’s a comprehensive inventory using SSH connector:

File Transfer Methods

The SSH connector supports two file transfer protocols:

SFTP (Default)

Recommended for most use cases:
  • More reliable
  • Better error handling
  • Works with more SSH server configurations

SCP

Useful for legacy systems:
  • Compatible with older SSH servers
  • Simpler protocol

Troubleshooting

Connection Timeouts

Increase timeout and enable retries:

Authentication Failures

Enable verbose logging:
Check:
  1. SSH key permissions (chmod 600 ~/.ssh/id_rsa)
  2. SSH agent is running (ssh-add -l)
  3. User has correct permissions on remote host
  4. SSH service is running on remote host

Host Key Verification Failed

Update known_hosts:

Source Reference

Location: src/pyinfra/connectors/ssh.py:119

Key Methods

  • connect() - Establish SSH connection
  • disconnect() - Close SSH connection
  • run_shell_command() - Execute commands via SSH
  • put_file() - Upload files via SFTP/SCP
  • get_file() - Download files via SFTP/SCP