SSH

Install

brew install ssh
choco install ssh

Configure

  • ssh-keygen -t rsa
  • Follow instructions

Multiple Personas

When providing a host alias, try to retain the original url and provide only suffix.
This can help things like Azure DevOps VsCode extensions to continue to function.

~/.ssh/config


Host ssh.dev.azure.com.WORK
    HostName ssh.dev.azure.com
    IdentityFile ~/.ssh/id_rsa_WORK
    IdentitiesOnly yes

Add host alias entries as required

When cloning

Use the Host entry instead of the HostName, the specified key will then be used.

Why

Imagine two instances on Azure DevOps

git@ssh.dev.azure.com:v3/PERSONAL/<project>/<repo> git@ssh.dev.azure.com:v3/WORK/<project>/<repo>

You want to be able to use different SSH keys per instance. Aliasing at least one of them will allow you to choose a specific key

git@ssh.dev.azure.com.WORK:v3/WORK/<project>/<repo>

Backup

TODO Document backup commands for storing keys in KeyVault (or link to KeyVault page)

Restoring

I backup my keys to an Azure KeyVault. To pull down what I need for a restore quickly and easily, I am going to need either the Az CLI or PowerShell.

Get the key


$vaultName = 'vault'
$keyName   = 'ssh-key-private'
$keyPath   = '~/.ssh/id_rsa'

install-module az.Accounts -Scope CurrentUser
install-module az.KeyVault -Scope CurrentUser

Login-AzAccount

(Get-AzKeyVaultSecret -VaultName $vaultName -Name $keyName).SecretValueText | Out-File $keyPath

Set the permissions

chmod 0600 ~/.ssh/id_rsa 

Generate a public key

ssh-keygen -y -f ~/.ssh/id_rsa > ~/.ssh/id_rsa.pub

Azure Cli

TODO Document backup commands for storing keys in KeyVault (or link to KeyVault page)