# SSH, SCP, rsync आणि environment variables

Source: https://ravindrabagale.com/mr/cyber/part-02/ch06-linux-advanced-commands/6-10-remote-access-ssh-scp-rsync-and-environment.html
Language: mr (Marathi with English technical terms)

SSH login व्यतिरिक्त remote command चालवण्यासाठीही वापरता येतो. SCP file/folder copy करतो आणि rsync sync करताना बदललेला data कार्यक्षमपणे transfer करू शकतो. खालील IP documentation example आहे; स्वतःच्या lab details वापरा.

ssh -i ~/keys/mykey.pem ec2-user@203.0.113.10              # log in
ssh -i ~/keys/mykey.pem ubuntu@203.0.113.10 'uptime'        # run one command remotely
scp -i ~/keys/mykey.pem index.html ec2-user@203.0.113.10:/home/ec2-user/        # upload file
scp -i ~/keys/mykey.pem -r ./site ubuntu@203.0.113.10:~/                        # upload folder
scp -i ~/keys/mykey.pem ec2-user@203.0.113.10:/var/log/nginx/error.log .        # download
rsync -avz -e "ssh -i ~/keys/mykey.pem" ./site/ ubuntu@203.0.113.10:~/site/     # smart sync

scp -r directory copy करतो. Remote source आणि local destination दिल्यास download होतो. Rsync example मध्ये ./site/ च्या trailing slash मुळे directory मधलं content sync होतं; slash नसल्यास destination structure बदलू शकतो.

SSH config मध्ये alias

~/.ssh/config मध्ये:

Host web1
    HostName 203.0.113.10
    User ec2-user
    IdentityFile ~/keys/mykey.pem

मग ssh web1 किंवा scp file.txt web1:~/ एवढं लिहिता येतं.

Environment variables

echo $HOME $USER $PATH $SHELL
env | sort                     # all environment variables
export APP_ENV=production      # set for this session and child processes
echo $APP_ENV
unset APP_ENV
echo 'export PATH=$PATH:$HOME/bin' >> ~/.bashrc   # make permanent for your user
source ~/.bashrc               # reload without logging out

HOME, USER, PATH, SHELL हे environment संदर्भ आहेत. export APP_ENV=production current session आणि त्यातून सुरू होणाऱ्या child processes साठी variable देतो. unset काढतो. .bashrc मधली export line interactive Bash setup साठी टिकते; प्रत्येक shell/service तीच file वाचेलच असं नाही. source त्या file मधल्या commands चालवतो, म्हणून trusted file वरच वापरा.

Secrets code मध्ये टाकू नका

Database passwords आणि API keys Git मध्ये hard-code करू नका. Environment किंवा permissions 600 असलेली .env file वापरताना ती web root बाहेर ठेवा आणि logs/process diagnostics मध्ये leak होणार नाही याची काळजी घ्या. Environment variables हे encryption किंवा पूर्ण secret store नाहीत. AWS मध्ये योग्य IAM roles आणि managed secret storage उपयोगी पडतात.

Practice

तुमच्या instance साठी web1 alias तयार करा. SCP ने lab folder upload करा, परवानगी असलेली log file download करा आणि एका SSH command ने remote uptime पाहा. env output मध्ये secrets असू शकतात, म्हणून ते share करू नका.

रवींद्र बागले यांची tip

SCP मध्ये remote address नंतर colon महत्त्वाचा: user@IP:~/. Colon नसेल तर तो local filename समजला जाऊ शकतो. Copy झाल्यावर file कुठे गेली ते तपासा.
