vps-login
v1.1.0
Published
Guided one-command setup for passwordless SSH login to a VPS. Generates a key, installs it on the remote host, writes/updates an SSH config alias, and verifies the connection. Also supports listing and removing configs it manages.
Maintainers
Readme
vps-login
Turn first-time SSH setup into one guided command.
npx vps-loginIt asks for:
- VPS IP/hostname
- SSH username
- SSH port
- VPS password (used once, never stored)
- Preferred alias
Before touching anything, it shows you a review screen — you can jump back and fix any field, or cancel outright. Once confirmed, it automatically:
- Generates an SSH key if you don't already have a usable one.
- Connects to the VPS using the password once.
- Adds the public key to
~/.ssh/authorized_keyson the VPS. - Detects whether
~/.ssh/configalready exists. - Preserves every existing
Hostentry already in that file. - Adds or updates only the alias you chose.
- Tests the new passwordless connection before finishing.
Afterwards you just run:
ssh myvpsReviewing and editing your answers
After you answer the prompts, you'll see:
Review before continuing:
Host: 203.0.113.5
Username: root
Port: 22
Password: ********
Alias: myvps
? Look right? › Yes, continue / Edit a field / CancelChoosing Edit a field lets you pick any one value, fix it, and you're
brought right back to the summary — so a typo doesn't mean starting over
or, worse, connecting to the wrong box. This step is skipped automatically
in --yes (non-interactive) mode.
Managing what you've set up
vps-login list # or: vps-login lsShows every Host entry in ~/.ssh/config, tagging which ones were
created by this tool ([vps-login]) versus ones you added by hand
([manual]) — so removal never touches something it didn't create.
vps-login remove myvps # or: vps-login rm myvps- Asks for confirmation (shows the target host/user first).
- Connects with the still-installed key to strip that key's exact line
from the VPS's
~/.ssh/authorized_keys(best-effort — a warning is printed instead of failing if the server's unreachable). - Removes the
Hostblock from~/.ssh/config, leaving every other entry untouched. - If the local private key isn't referenced by any other alias, asks whether to delete it too. If another alias still uses it, it's kept automatically.
Flags: --keep-remote-key, --keep-local-key, -y/--yes (skip prompts).
Non-interactive / scripted usage
Every setup prompt has a matching flag, so the tool also works unattended (CI, provisioning scripts, dotfiles bootstrap, etc.):
npx vps-login setup \
--host 203.0.113.5 \
--username root \
--port 22 \
--password 'hunter2' \
--alias myvps \
--yessetup is the default command, so vps-login --host ... --yes works the
same as vps-login setup --host ... --yes. Any flag you omit falls back
to an interactive prompt, unless --yes is set, in which case missing
required values cause the command to fail loudly instead of hanging on a
prompt.
Add --dry-run to preview exactly what setup would do — the key it would
create/reuse, the Host block it would write — without changing anything.
All setup flags
| Flag | Description | Default |
|---|---|---|
| -H, --host <host> | VPS IP or hostname | — |
| -u, --username <user> | SSH username | root |
| -p, --port <port> | SSH port | 22 |
| -P, --password <password> | VPS password (one-time use) | — |
| -a, --alias <alias> | SSH config alias | derived from host |
| -k, --key-path <path> | Explicit key path to create/reuse | ~/.ssh/id_ed25519 |
| -t, --key-type <type> | ed25519 | rsa | ecdsa | ed25519 |
| --force-new-key | Always generate a fresh key | off |
| --skip-test | Skip the final connection check | off |
| --dry-run | Preview only, no changes | off |
| -y, --yes | Fail instead of prompting; skips the review step | off |
Design notes
- Idempotent. Re-running against the same host de-duplicates
authorized_keysand updates (rather than duplicates) the matchingHostblock in~/.ssh/config. - Non-destructive. Existing
Hostentries and comments in~/.ssh/configare preserved exactly; the file is backed up once to~/.ssh/config.bakbefore the first write. - Scoped removal. Every
Hostblock this tool writes carries a# managed-by: vps-loginmarker, solist/removecan tell the difference between what it manages and entries you added yourself. - Key reuse. If you already have a default key
(
id_ed25519/id_rsa/id_ecdsa), it's reused by default instead of generating a new one. Use--key-pathto keep a dedicated key per VPS, or--force-new-keyto always generate fresh. - No password storage. The password is only ever held in memory for the single bootstrap connection and is never written to disk or logged.
- Cross-distro. The remote-side key install/removal is a small POSIX
shell one-liner (no dependency on
ssh-copy-idbeing present on the VPS).
Requirements
- Node.js 16+
- The OpenSSH client tools (
ssh-keygen) available on your localPATH
Local install
npm install
node bin/vps-login.js