Skip to main content
The Mirage server can listen for SSH next to HTTP. The SSH username names the workspace. Every line runs in Mirage’s shell, and every file operation goes through the workspace’s mounts.
Only public keys log in: no passwords. Nothing is forwarded: no ports, no agent, no X11.

Turn it on

1

Install the SSH library

2

Pick a port

SSH stays off until a port is set.
3

Authorize your key

The file is read on every login, so adding or removing a key needs no restart.
4

Restart and connect

The server makes its host key on first start and keeps it, so your known_hosts entry stays valid.

Settings

An environment variable wins over ~/.mirage/config.toml, which wins over the default.

Bind a key to a profile

The mirage-profile option runs every login of that key under a profile. A key without it gets the workspace’s default.
~/.mirage/ssh/authorized_keys
The server reads the option, not the client, so a key cannot pick looser rules. Give each agent’s sandbox its own key, bound to that agent’s profile.

Sessions

Each channel (one ssh, sftp or scp run) gets a fresh session, closed when it ends, so a cd or export never leaks between them. The session’s profile and the mount modes apply as in any shell: a read-only mount refuses sftp put. Ctrl-C cancels the running line and sets $? to 130, a dropped connection cancels it too, and ssh host cmd exits with the line’s status.