SSH: Why and How
A lock and a key, not a password. Build the real file model before you ever touch GitHub.
Before your recipe project can push to a real host like GitHub, that host needs a way to know it is genuinely you — without you typing a password every single time. SSH solves this with a real key PAIR: a public key (safe to hand out, even to post publicly) and a private key (never shared, ever). The host keeps a copy of your public key; anything encrypted with it can only be decrypted with the matching private key you alone hold.\n\nOne honest note before starting: this training VM is a fully offline sandbox with no network access and no SSH tooling installed at all — confirmed directly, ssh-keygen genuinely does not exist here. That is by design, not a limitation to work around: the real key-generation command (ssh-keygen -t ed25519) and the GitHub upload step happen on your own machine, outside any sandbox. What this lesson builds instead is the real, hands-on file and permission model — genuinely the same structure ssh-keygen itself produces — so the concept is concrete before you ever run the real command elsewhere.
The Real Directory and Its Permissions
mkdir -p ~/.ssh && chmod 700 ~/.ssh
700 means only you (the owner) can read, write, or enter this directory — genuinely no one else on the same machine can even list what is inside it.
A Real Key Pair, Two Very Different Files
# On your own machine, this is the real command:
# ssh-keygen -t ed25519 -C "you@example.com"
# Here, we build the same real file structure by hand to inspect it directly:
cat ~/.ssh/id_ed25519.pub # the PUBLIC key — safe to share
The public key is meant to travel — you paste it into GitHub's settings, hand it to a server admin, post it anywhere. On its own, it can verify a signature but never forge one.
Permissions That Actually Matter
chmod 600 ~/.ssh/id_ed25519 # private key: owner read/write only
chmod 644 ~/.ssh/id_ed25519.pub # public key: fine for others to read
ls -l ~/.ssh
Real SSH clients genuinely refuse to use a private key file that is readable by anyone but its owner — loose permissions on a private key are treated as a real security failure, not a formality.
Public key vs private key
Two mathematically related files that work as a real pair: content locked with the public key can only be unlocked with the matching private key. Sharing the public key openly is genuinely safe by design; the private key must never leave the machine it was generated on.
chmod 600 on a private key
Restricts a file to read/write access for its owner only — confirmed directly in this lab via ls -l showing "-rw-------". Real SSH clients enforce this: a private key with looser permissions is treated as compromised and refused.
📁 Build the Real .ssh Directory
Create ~/.ssh with the exact permissions a real key setup requires.
mkdir -p ~/.ssh && chmod 700 ~/.sshls -ld ~/.sshstudent@lab:~$ mkdir -p ~/.ssh && chmod 700 ~/.ssh student@lab:~$ ls -ld ~/.ssh drwx------ 2 root root 4096 Aug 24 19:34 /home/student/.ssh
🔑 Build the Key Pair Files
Create the two files a real key pair produces — clearly illustrative content, since this sandbox has no key-generation tooling, but the real file structure.
printf 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILLUSTRATIVEEXAMPLEKEYNOTREAL ada@example.com\n' > ~/.ssh/id_ed25519.pubprintf 'ILLUSTRATIVE PLACEHOLDER PRIVATE KEY - NOT A REAL KEY\n' > ~/.ssh/id_ed25519student@lab:~$ printf 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILLUSTRATIVEEXAMPLEKEYNOTREAL ada@example.com\n' > ~/.ssh/id_ed25519.pub student@lab:~$ printf 'ILLUSTRATIVE PLACEHOLDER PRIVATE KEY - NOT A REAL KEY\n' > ~/.ssh/id_ed25519
🔒 Apply the Real Permissions
Lock down the private key and confirm the public key stays readable.
chmod 600 ~/.ssh/id_ed25519chmod 644 ~/.ssh/id_ed25519.publs -l ~/.sshstudent@lab:~$ chmod 600 ~/.ssh/id_ed25519 student@lab:~$ chmod 644 ~/.ssh/id_ed25519.pub student@lab:~$ ls -l ~/.ssh total 8 -rw------- 1 root root 54 Aug 24 19:34 id_ed25519 -rw-r--r-- 1 root root 82 Aug 24 19:34 id_ed25519.pub
📤 Confirm What's Actually Safe to Share
Read the public key's content — this, and only this file, is what gets pasted into GitHub.
cat ~/.ssh/id_ed25519.pubstudent@lab:~$ cat ~/.ssh/id_ed25519.pub ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILLUSTRATIVEEXAMPLEKEYNOTREAL ada@example.com
Lab 1.5.1 complete. The real key-pair file model, built and understood by hand:\n\n\n .ssh directory, correct perms : ✅ drwx------\n Key pair files created : ✅ id_ed25519 + .pub\n Permissions applied correctly : ✅ 600 / 644\n Public key content confirmed : ✅ safe to share\n
Enable JavaScript to run the live terminal and track your progress.