Terminal and SSH

Device keys

Every computer you sign in on gets its own SSH key, and all your Kisten accept all of them.

You never copy SSH keys around. Every computer you sign in on with kiste login creates its own SSH key, stored only on that computer, and adds its public half to your account. Every Kiste of your account accepts every one of these device keys, including Kisten created before you signed in on that computer.

kiste devices              # the computers signed in to your account
kiste devices remove ID    # remove one computer's key

How keys reach your Kisten

kiste.run installs your account's current device keys into a Kiste when it is created or resumed, and again before every SSH connection. A key you removed stops working at the next of these. The keys live in a managed block of /root/.ssh/authorized_keys; lines you add yourself outside that block are left alone.

Signing out

kiste logout revokes the computer's sign-in and removes its device key from your account. kiste logout --local only forgets the sign-in on this computer, for when kiste.run can't be reached; remove the key later with kiste devices remove.

Limits

An account can have 50 device keys (L09). Browser sessions never add keys; only a CLI sign-in does.

A lost computer

Remove its key with kiste devices remove ID from any other signed-in computer, and end its sign-in in the console or with sign out everywhere.

On this page