SSH access management

Give access. Keep the keys.

Generate and store SSH keys in an encrypted vault, install them on hosts in one click and let your team connect through roles — without ever seeing a private key.

Hardware security key plugged into a laptop showing a terminal

Before & after

What changes on day one

Without PlainShip

  • Private keys copied between laptops
  • Passwords shared in chat
  • Former team members who still have access
  • No record of who opened a shell

With PlainShip

  • Keys generated and sealed in the vault
  • Secrets referenced as {{ NAME }}
  • Remove a user and their access is gone
  • Every terminal session logged with duration

How it works

Four steps, no agents

  1. Generate a key

    Ed25519, RSA or ECDSA — created and encrypted inside the vault.

  2. Install it on hosts

    Push the public key to many servers at once, like ssh-copy-id.

  3. Grant access by role

    Operators connect and run; viewers can only watch.

  4. Audit every session

    Sign-ins, shells and changes recorded in the activity log.

inventory.yml
# hosts reference vault keys — never key files on disk
hosts:
  web1:
    address: 203.0.113.10
    user: deploy
    key_id: deploy-ed25519
  db1:
    address: 10.20.2.10
    user: dba
    password_env: DB1_PASSWORD   # vault secret