SSH key management server and SSH certificate authority. Replace permanent SSH keys.
646
Replace permanent SSH keys with short-lived SSH certificates.
SSH Teams is an SSH key management server and SSH certificate authority that replaces the distribution and management of permanent SSH keys with short-lived SSH certificates issued on demand.
Define who can access what, and let authorised users obtain temporary SSH credentials when they need them.
No permanent SSH keys to distribute. No user limits. No server limits. No registration. No trial.
Start SSH Teams with a single Docker command:
docker run -d \
--name sshteam \
-p 8080:8080 \
-p 8443:8443 \
-v sshteam_conf:/app/conf.d \
-v sshteam_data:/app/nitrate/data \
-e SSHTEAM_PERSISTENCE_BACKEND=nitrate \
-e HTTP_PORT=8080 \
-e HTTPS_PORT=8443 \
jadaptive/sshteam:latest
Docker automatically creates the sshteam_conf and sshteam_data volumes when the container is first started.
Once running, open:
https://localhost:8443
HTTP is also available on port 8080.
Your browser may display a certificate warning when accessing a new local installation over HTTPS.
Traditional SSH access usually means copying public keys onto servers and then trying to keep track of:
SSH Teams takes a different approach.
Your SSH servers trust the SSH Teams certificate authority. Users authenticate with SSH Teams and receive a short-lived SSH certificate authorising the access they need.
When the certificate expires, the access expires with it.
No key removal exercise. No forgotten authorized_keys entries. No permanent SSH credentials scattered across your infrastructure.
SSH Teams lets you:
At a high level:
The server only needs to trust the certificate authority. It doesn't need an individual permanent public key installed for every user.
SSH certificates are deliberately temporary.
Instead of granting access using credentials that may remain valid for months or years, SSH Teams issues certificates with a limited lifetime.
When a certificate expires, it can no longer be used to authenticate.
Define which users are allowed to access which SSH resources.
SSH Teams evaluates access before issuing a certificate, allowing SSH permissions to be managed centrally rather than independently on every server.
Instead of maintaining individual user keys in authorized_keys, configure your SSH servers to trust the SSH Teams certificate authority.
Once that trust is established, authorised users can receive certificates without requiring their individual public keys to be installed on every server.
SSH Teams has no user or server limits designed to force you into another edition as your environment grows.
There is no registration requirement and no trial period.
Use it. Scale it.
SSH Teams is designed for:
Stop the container:
docker stop sshteam
Start it again:
docker start sshteam
To remove the container:
docker rm -f sshteam
The configuration and application data remain stored in the Docker volumes.
The Quick Start example uses:
| Variable | Value | Description |
|---|---|---|
SSHTEAM_PERSISTENCE_BACKEND | nitrate | Persistence backend used by SSH Teams |
HTTP_PORT | 8080 | HTTP server port |
HTTPS_PORT | 8443 | HTTPS server port |
SSH Teams stores persistent configuration and application data in:
| Container Path | Docker Volume | Description |
|---|---|---|
/app/conf.d | sshteam_conf | Configuration |
/app/nitrate/data | sshteam_data | Persistent application data |
Docker named volumes are used in the Quick Start so no host directories need to be created before starting the container.
To inspect the volumes:
docker volume ls
Removing these volumes will permanently delete the SSH Teams configuration and stored application data.
Full documentation:
Jadaptive:
Questions, feedback and community support:
https://www.reddit.com/r/jadaptive/
SSH Teams is part of Jadaptive's infrastructure and security software collection, including:
Explore the Jadaptive Docker Hub namespace to discover more.
Use it. Scale it. No artificial limits.
Content type
Image
Digest
sha256:c772e7ce1…
Size
472.7 MB
Last updated
2 months ago
docker pull jadaptive/sshteam