Sign inSign up

jadaptive/sshteam

Verified Publisher

By Jadaptive Limited

•Updated 2 months ago

SSH key management server and SSH certificate authority. Replace permanent SSH keys.

Image
Networking
Security
Developer tools
0

646

jadaptive/sshteam repository overview

⁠SSH Teams

Replace permanent SSH keys with short-lived SSH certificates.

SSH Teams is an SSH key management server and SSH certificate authority that replaces the distribution and management of permanent SSH keys with short-lived SSH certificates issued on demand.

Define who can access what, and let authorised users obtain temporary SSH credentials when they need them.

No permanent SSH keys to distribute. No user limits. No server limits. No registration. No trial.

⁠Quick Start

Start SSH Teams with a single Docker command:

docker run -d \
  --name sshteam \
  -p 8080:8080 \
  -p 8443:8443 \
  -v sshteam_conf:/app/conf.d \
  -v sshteam_data:/app/nitrate/data \
  -e SSHTEAM_PERSISTENCE_BACKEND=nitrate \
  -e HTTP_PORT=8080 \
  -e HTTPS_PORT=8443 \
  jadaptive/sshteam:latest

Docker automatically creates the sshteam_conf and sshteam_data volumes when the container is first started.

Once running, open:

https://localhost:8443

HTTP is also available on port 8080.

Your browser may display a certificate warning when accessing a new local installation over HTTPS.

⁠Stop distributing permanent SSH keys

Traditional SSH access usually means copying public keys onto servers and then trying to keep track of:

  • Who has access
  • Which servers they can access
  • Where their SSH keys have been installed
  • Whether those keys should still be there
  • How to remove access when somebody leaves or changes role

SSH Teams takes a different approach.

Your SSH servers trust the SSH Teams certificate authority. Users authenticate with SSH Teams and receive a short-lived SSH certificate authorising the access they need.

When the certificate expires, the access expires with it.

No key removal exercise. No forgotten authorized_keys entries. No permanent SSH credentials scattered across your infrastructure.

⁠What can SSH Teams do?

SSH Teams lets you:

  • Issue short-lived SSH certificates on demand
  • Replace permanent user SSH keys with temporary credentials
  • Control SSH access using central policy
  • Manage who can access your SSH infrastructure
  • Support modern Ed25519 and RSA SSH keys
  • Simplify onboarding and removal of SSH users
  • Integrate certificate-based SSH access into automation and agent workflows
  • Run your SSH certificate authority within your own infrastructure

⁠How does it work?

At a high level:

  1. Your SSH servers are configured to trust the SSH Teams certificate authority.
  2. A user requests SSH access.
  3. SSH Teams evaluates the applicable access policy.
  4. If authorised, SSH Teams signs the user's SSH key and issues a short-lived certificate.
  5. The user connects to the server using their key and certificate.
  6. When the certificate expires, the access automatically expires with it.

The server only needs to trust the certificate authority. It doesn't need an individual permanent public key installed for every user.

⁠Why use SSH certificates?

⁠Short-lived access

SSH certificates are deliberately temporary.

Instead of granting access using credentials that may remain valid for months or years, SSH Teams issues certificates with a limited lifetime.

When a certificate expires, it can no longer be used to authenticate.

⁠Central access policy

Define which users are allowed to access which SSH resources.

SSH Teams evaluates access before issuing a certificate, allowing SSH permissions to be managed centrally rather than independently on every server.

⁠Simple server trust

Instead of maintaining individual user keys in authorized_keys, configure your SSH servers to trust the SSH Teams certificate authority.

Once that trust is established, authorised users can receive certificates without requiring their individual public keys to be installed on every server.

⁠No artificial limits

SSH Teams has no user or server limits designed to force you into another edition as your environment grows.

There is no registration requirement and no trial period.

Use it. Scale it.

⁠Who is SSH Teams for?

SSH Teams is designed for:

  • DevOps and infrastructure teams
  • System administrators
  • Development teams accessing Linux infrastructure
  • Organisations managing access across multiple SSH servers
  • Teams replacing permanent SSH key distribution
  • Environments requiring temporary or policy-controlled SSH access
  • Automation and agent workflows requiring temporary SSH credentials

⁠Docker Configuration

⁠Stop and start

Stop the container:

docker stop sshteam

Start it again:

docker start sshteam

To remove the container:

docker rm -f sshteam

The configuration and application data remain stored in the Docker volumes.

⁠Environment variables

The Quick Start example uses:

VariableValueDescription
SSHTEAM_PERSISTENCE_BACKENDnitratePersistence backend used by SSH Teams
HTTP_PORT8080HTTP server port
HTTPS_PORT8443HTTPS server port

⁠Persistent data

SSH Teams stores persistent configuration and application data in:

Container PathDocker VolumeDescription
/app/conf.dsshteam_confConfiguration
/app/nitrate/datasshteam_dataPersistent application data

Docker named volumes are used in the Quick Start so no host directories need to be created before starting the container.

To inspect the volumes:

docker volume ls

Removing these volumes will permanently delete the SSH Teams configuration and stored application data.


⁠Documentation & Community

Full documentation:

https://docs.jadaptive.com⁠

Jadaptive:

https://jadaptive.com⁠

Questions, feedback and community support:

https://www.reddit.com/r/jadaptive/⁠

⁠More from Jadaptive

SSH Teams is part of Jadaptive's infrastructure and security software collection, including:

  • Password Express
  • Nodal VPN
  • Aegis Gateway
  • DropPort
  • Maverick SSH MCP

Explore the Jadaptive Docker Hub namespace to discover more.

Use it. Scale it. No artificial limits.

Tag summary

Content type

Image

Digest

sha256:c772e7ce1…

Size

472.7 MB

Last updated

2 months ago

docker pull jadaptive/sshteam