Install
brew install ssh
choco install ssh
Configure
ssh-keygen -t rsa- Follow instructions
Multiple Personas
When providing a host alias, try to retain the original url and provide only suffix.
This can help things like Azure DevOps VsCode extensions to continue to function.
~/.ssh/config
Host ssh.dev.azure.com.WORK
HostName ssh.dev.azure.com
IdentityFile ~/.ssh/id_rsa_WORK
IdentitiesOnly yes
Add host alias entries as required
When cloning
Use the Host entry instead of the HostName,
the specified key will then be used.
Why
Imagine two instances on Azure DevOps
git@ssh.dev.azure.com:v3/PERSONAL/<project>/<repo>
git@ssh.dev.azure.com:v3/WORK/<project>/<repo>
You want to be able to use different SSH keys per instance. Aliasing at least one of them will allow you to choose a specific key
git@ssh.dev.azure.com.WORK:v3/WORK/<project>/<repo>
Backup
TODO Document backup commands for storing keys in KeyVault (or link to KeyVault page)
Restoring
I backup my keys to an Azure KeyVault. To pull down what I need for a restore quickly and easily, I am going to need either the Az CLI or PowerShell.
Get the key
$vaultName = 'vault'
$keyName = 'ssh-key-private'
$keyPath = '~/.ssh/id_rsa'
install-module az.Accounts -Scope CurrentUser
install-module az.KeyVault -Scope CurrentUser
Login-AzAccount
(Get-AzKeyVaultSecret -VaultName $vaultName -Name $keyName).SecretValueText | Out-File $keyPath
Set the permissions
chmod 0600 ~/.ssh/id_rsa
Generate a public key
ssh-keygen -y -f ~/.ssh/id_rsa > ~/.ssh/id_rsa.pub
Azure Cli
TODO Document backup commands for storing keys in KeyVault (or link to KeyVault page)