Docs

SSH, files and Terminal

SSH tabs and the file browser inside Ostgate, and plain ssh, scp and your IDE through Ostgate from outside it.

Updated

SSH and files

Choose Connect on a Linux instance. The first time, Ostgate creates your SSH key on this Mac, in the Secure Enclave where available, and publishes it for you: through OS Login when the instance or project enables it, otherwise through the instance's own metadata. OS Login keys expire after an hour and metadata keys after a day, and are renewed as you connect. OS Login with two-factor authentication is not supported.

The first connection to an instance that does not publish its host keys asks you to Verify the VM's SSH host key; check the fingerprint and choose Trust and Connect. From then on a different key stops the connection.

  • Browse Files opens an SFTP browser for the same instance. Drag files in to upload and out to Finder to download. You can also drop a file on a terminal to upload it to your home folder.
  • Connect As… signs in with a username and your own private key, from a file or from Secret Manager, for appliances that do not use OS Login. It publishes nothing to the instance. OpenSSH ed25519 and RSA keys and unencrypted PEM RSA keys work; for other PEM keys, re-encode first with ssh-keygen -p -f KEY_FILE.
  • For password sign-in, set SSH auth to Password in connection settings. Save password for this VM keeps it in the Keychain.
  • Show SSH Keys lists your OS Login keys and the instance's and project's metadata keys, and deletes the ones you no longer want.

Browse Files and Connect As… are not offered for Windows instances.

Use ssh from Terminal

In Settings › SSH Integration, click Install. Ostgate adds one managed block to ~/.ssh/config, after which this works from any terminal, IDE, scp or script, with Ostgate's window closed:

ssh INSTANCE.ZONE.PROJECT.gcp

The block only carries the connection through IAP, using your signed-in Ostgate accounts. ssh signs in with your own keys from ~/.ssh and checks your own known_hosts, so your public key must already be accepted by the instance: added to your OS Login profile, or to the instance's or project's SSH keys metadata. The optional OS Login username field adds a User line. Remove deletes the block and nothing else.