From e94f23d82e2cbfaef4b0b011b0fc7db4a418e70d Mon Sep 17 00:00:00 2001 From: Timmy Date: Thu, 9 Apr 2026 13:11:56 +0800 Subject: [PATCH] Consolidate SSH config: merge duplicate hosts, fix paths and formatting - Merge same-user hosts into grouped Host entries (timmy, ma) - Fix ssh_key_management.sh path from ~/Sync to iCloud - Standardize = syntax to space-separated (jason_hsieh) - Unify indentation to 4 spaces (config) - Remove duplicate 192.168.88.173 entry and redundant HostNames Co-Authored-By: Claude Opus 4.6 (1M context) --- config | 45 +++++++------- config.d/jason_hsieh | 8 +-- config.d/ma | 134 +++++++++++++----------------------------- config.d/timmy | 71 +++++----------------- ssh_key_management.sh | 6 +- 5 files changed, 83 insertions(+), 181 deletions(-) diff --git a/config b/config index 2d8b1e5..84415ed 100644 --- a/config +++ b/config @@ -3,37 +3,34 @@ Include config.d/* # Fig ssh integration. Keep at the bottom of this file. Match all - Include ~/.fig/ssh + Include ~/.fig/ssh Host github.com - IdentityFile ~/.ssh/id_rsa - AddKeysToAgent yes + IdentityFile ~/.ssh/id_rsa + AddKeysToAgent yes # --- Global Settings --- Host * -# StrictHostKeyChecking no # 不進行 Strict HostKey 檢查 -# UserKnownHostsFile /dev/null # 不使用 KnownHosts 檔案 - # —— 連線穩定與正常結束 —— - TCPKeepAlive yes # 啟用 TCP KeepAlive 功能 - ServerAliveInterval 60 # 每 60 秒向伺服器端發送一次請求 - ServerAliveCountMax 5 # 若伺服器端 5 次無回應則中斷連接 - ExitOnForwardFailure yes # 若連線轉發失敗立即退出,避免殘留 session + # —— 連線穩定與正常結束 —— + TCPKeepAlive yes # 啟用 TCP KeepAlive 功能 + ServerAliveInterval 60 # 每 60 秒向伺服器端發送一次請求 + ServerAliveCountMax 5 # 若伺服器端 5 次無回應則中斷連接 + ExitOnForwardFailure yes # 若連線轉發失敗立即退出,避免殘留 session - # —— Multiplexing(加速多連線,減少殘留程序)—— - ControlMaster auto # 自動使用 ControlMaster 功能 - ControlPath ~/.ssh/sockets/%r@%h-%p # 設定 ControlPath - ControlPersist 5m # 主連線關掉後,socket 最多保留 5 分鐘 + # —— Multiplexing(加速多連線,減少殘留程序)—— + ControlMaster auto # 自動使用 ControlMaster 功能 + ControlPath ~/.ssh/sockets/%r@%h-%p # 設定 ControlPath + ControlPersist 5m # 主連線關掉後,socket 最多保留 5 分鐘 - # —— 安全性建議(擇一)—— - # 預設:保留嚴格檢查(建議) - #StrictHostKeyChecking ask - # 或想少互動但仍相對安全: - #StrictHostKeyChecking accept-new + # —— 安全性建議(擇一)—— + # 預設:保留嚴格檢查(建議) + #StrictHostKeyChecking ask + # 或想少互動但仍相對安全: + #StrictHostKeyChecking accept-new - # —— 代理/金鑰(依你目前環境)—— - IdentityAgent /Users/timmy/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh - - CheckHostIP no # 不檢查 IP 位址是否變更 - VisualHostKey no # 不顯示伺服器端的 HostKey + # —— 代理/金鑰(依你目前環境)—— + IdentityAgent /Users/timmy/Library/Containers/com.maxgoedjen.Secretive.SecretAgent/Data/socket.ssh + CheckHostIP no # 不檢查 IP 位址是否變更 + VisualHostKey no # 不顯示伺服器端的 HostKey diff --git a/config.d/jason_hsieh b/config.d/jason_hsieh index f8271a1..c8fdc4b 100644 --- a/config.d/jason_hsieh +++ b/config.d/jason_hsieh @@ -49,10 +49,10 @@ Host 140.136.202.209 Host 34.80.116.132 HostName 34.80.116.132 IdentityFile /Users/timmy/.ssh/google_compute_engine - UserKnownHostsFile=/Users/timmy/.ssh/google_compute_known_hosts - # HostKeyAlias=compute.97799509408430482 - IdentitiesOnly=yes - CheckHostIP=no + UserKnownHostsFile /Users/timmy/.ssh/google_compute_known_hosts + # HostKeyAlias compute.97799509408430482 + IdentitiesOnly yes + CheckHostIP no # Fu Jen Dev Server (輔大) Host fju_dev diff --git a/config.d/ma b/config.d/ma index a8a6a6a..9f292f0 100644 --- a/config.d/ma +++ b/config.d/ma @@ -1,69 +1,37 @@ Host 192.168.77.10 - User root + User root # MA 防火牆 Host ma_fw HostName 192.168.88.1 User ubuntu - -Host 192.168.88.2 - User root - -Host 192.168.88.99 - User ubuntu - Host 192.168.88.4 192.168.88.4.nip.io - User pi + User pi -Host 192.168.88.10 - User timmy +# MA 內網主機 (root) +Host 192.168.88.2 + User root -Host 192.168.88.11 - User timmy - -Host 192.168.88.12 - User timmy - -Host 192.168.88.13 - User timmy # 預設使用者:連線時自動使用 timmy 帳號登入 - -Host 192.168.88.15 - User ubuntu - -Host 192.168.88.16 - User timmy +# MA 內網主機 (timmy) +Host 192.168.88.10 192.168.88.11 192.168.88.12 192.168.88.13 192.168.88.16 192.168.88.33 + User timmy Host 192.168.88.18 - User timmy - LocalForward 50041 127.0.0.1:80 + User timmy + LocalForward 50041 127.0.0.1:80 -Host 192.168.88.19 - User ubuntu - -Host 192.168.88.30 - User ubuntu - -Host 192.168.88.31 - User ubuntu - -Host 192.168.88.173 - User ubuntu - -Host 192.168.88.32 - User ubuntu - Port 22 - -Host 192.168.88.33 - User timmy +# MA 內網主機 (ubuntu) +Host 192.168.88.15 192.168.88.19 192.168.88.30 192.168.88.31 192.168.88.32 192.168.88.99 192.168.88.181 192.168.88.193 192.168.88.194 + User ubuntu # Mail Server MA (內網連線) Host mail_ma_local 192.168.88.35 HostName 192.168.88.35 User timmy - LocalForward 16361 127.0.0.1:80 # Mail 管理介面 - HostKeyAlgorithms +ssh-rsa # 支援舊版加密 - PubkeyAcceptedKeyTypes +ssh-rsa # 支援舊版金鑰 + LocalForward 16361 127.0.0.1:80 + HostKeyAlgorithms +ssh-rsa + PubkeyAcceptedKeyTypes +ssh-rsa # --- Timmy Personal Dev --- @@ -99,63 +67,41 @@ Host ma_mediawiki HostName 192.168.88.173 User ubuntu -Host 192.168.88.181 - User ubuntu +# --- MA 虛擬化主機 --- -Host 192.168.88.193 - User ubuntu - HostName 192.168.88.193 - -Host 192.168.88.194 - User ubuntu - HostName 192.168.88.194 - -# This is VMware ESXi 6.0.0 Update 2 with the main firewall for MA on the 11th floor of Oriental Science Park (internal IP 192.168.88.1) and the firewall for implementing IPv6 (internal IP 192.168.88.150). +# VMware ESXi 6.0.0 (11F 防火牆 + IPv6 防火牆) Host 192.168.88.241 - User root - HostKeyAlgorithms +ssh-rsa + User root + HostKeyAlgorithms +ssh-rsa -# This is the MA VMware ESXi 6.7.0 Update 1 server with a mail server, along with the firewall for the 5th floor of Oriental Science Park and a dedicated firewall for the mail server. +# VMware ESXi 6.7.0 (郵件伺服器 + 5F 防火牆) Host 192.168.88.248 - User root + User root -# This is the MA PVE server. -Host 192.168.88.247 - User root +# PVE 伺服器 +Host 192.168.88.247 192.168.88.249 192.168.88.73 + User root -# This is the MA PVE server. -Host 192.168.88.249 - User root - -# This is the MA PVE server. -Host 192.168.88.73 - User root - - -# This is the firewall for MA on the 5th floor of Oriental Science Park. +# 5F 防火牆 (東方科學園區) Host 192.168.3.88 - User apple - ProxyJump 211.23.141.208 - Ciphers aes256-cbc,aes256-ctr + User apple + ProxyJump 211.23.141.208 + Ciphers aes256-cbc,aes256-ctr -# This is the firewall for MA on the 11th floor of Oriental Science Park. +# 11F 防火牆 (東方科學園區) Host 211.23.141.208 - User ubuntu + User ubuntu -# This is the firewall for MA on the 11th floor of Oriental Science Park. -# Host 211.23.141.207 -# User timmy - -# This is the Ubuntu Server for the Serbia office. +# Serbia 辦公室 Host 89.216.107.241 serbia-office - HostName 89.216.107.241 - User timmy - Port 8022 - Ciphers aes256-cbc,aes256-ctr - ProxyJump 211.23.141.208 + HostName 89.216.107.241 + User timmy + Port 8022 + Ciphers aes256-cbc,aes256-ctr + ProxyJump 211.23.141.208 # 遠振 Host 103.123.242.152 yz-prod - User root - HostName 103.123.242.152 - HostKeyAlgorithms ssh-rsa + User root + HostName 103.123.242.152 + HostKeyAlgorithms ssh-rsa diff --git a/config.d/timmy b/config.d/timmy index ab7cacb..3f31098 100644 --- a/config.d/timmy +++ b/config.d/timmy @@ -1,63 +1,22 @@ Host timmy_home_server - User timmy - HostName 125.229.110.50 - Ciphers aes256-cbc,aes256-ctr # Encryption algorithms for better security + User timmy + HostName 125.229.110.50 + Ciphers aes256-cbc,aes256-ctr Host 141.11.93.252 - User root - HostName 141.11.93.252 - Ciphers aes256-cbc,aes256-ctr # Encryption algorithms for better security + User root + HostName 141.11.93.252 + Ciphers aes256-cbc,aes256-ctr +# 內網主機 (root) +Host 192.168.42.10 192.168.42.38 192.168.42.39 192.168.42.40 192.168.42.101 192.168.42.102 192.168.42.106 192.168.42.112 192.168.42.118 192.168.42.123 192.168.42.124 192.168.42.126 192.168.42.211 + User root -Host 192.168.42.123 - User root - -Host 192.168.42.10 - User root - -Host 192.168.42.38 - User root - -Host 192.168.42.39 - User root - -Host 192.168.42.40 - User root - - -Host 192.168.42.101 - User root - -Host 192.168.42.102 - User root - -Host 192.168.42.112 - User root - -Host 192.168.42.106 - User root - -Host 192.168.42.120 - User ubuntu - -Host 192.168.42.121 - User ubuntu - -Host 192.168.42.122 - User ubuntu - -Host 192.168.42.211 - User root - -Host 192.168.42.118 - User root - -Host 192.168.42.124 - User root - -Host 192.168.42.126 - User root +# 內網主機 (ubuntu) +Host 192.168.42.120 192.168.42.121 192.168.42.122 + User ubuntu +# Termux (Android) Host 100.64.0.9 - Port 8022 - User u0_a291 + Port 8022 + User u0_a291 diff --git a/ssh_key_management.sh b/ssh_key_management.sh index 9d5a8c7..14b487e 100755 --- a/ssh_key_management.sh +++ b/ssh_key_management.sh @@ -14,9 +14,9 @@ export LANGUAGE=en_US:en eval $(ssh-agent) # 將指定路徑的 SSH 私鑰加入到 SSH-Agent 中 -# ssh-add ~/Sync/.ssh/ -ssh-add ~/Sync/.ssh/aws_server_13_113_205_237.pem -ssh-add ~/Sync/.ssh/aws_server_18_177_222_167.pem +BASE_DIR="$HOME/Library/Mobile Documents/com~apple~CloudDocs/.ssh" +ssh-add "$BASE_DIR/aws_server_13_113_205_237.pem" +ssh-add "$BASE_DIR/aws_server_18_177_222_167.pem" # 列出已經加入到 SSH-Agent 中的金鑰清單 ssh-add -l