---
title: OpenSSH
description: Configure OpenSSH for the localhost server or a remote server connected to Coolify.
---
# Configure OpenSSH
Coolify uses SSH to manage the servers connected to it.
Choose **Localhost** when configuring the server where a self-hosted Coolify instance is installed. Choose **Remote server** when preparing another Linux server for Coolify Cloud or self-hosted Coolify.
---
## Choose the server
The official Coolify installation script normally installs OpenSSH and creates the **localhost** SSH connection. Choose **Semi-automatic** to configure OpenSSH before installing Coolify, or **Manual** if the localhost connection is missing or broken.
Do not close your current SSH or console session until the **localhost** server connects successfully. You will need this session to correct the configuration if SSH access stops working.
### Configure OpenSSH before installing Coolify
Use this method when you want to install and configure OpenSSH yourself, but want the Coolify installation script to create the **localhost** SSH key and dashboard connection.
### Log in to the server
Login as `root` user using SSH or use the console provided by your hosting provider.
### Install OpenSSH
Run the commands below based on your server's operating system.
```sh
apt-get update
apt-get install -y openssh-server
systemctl enable --now ssh
```
Use this for CentOS, RHEL, Rocky Linux, AlmaLinux, Fedora, Amazon Linux, Oracle Linux, or TencentOS.
```sh
dnf install -y openssh-server
systemctl enable --now sshd
```
```sh
zypper refresh
zypper install -y openssh
systemctl enable --now sshd
```
```sh
pacman -Sy --noconfirm openssh
systemctl enable --now sshd
```
```sh
apk add openssh
rc-update add sshd default
service sshd start
```
### Configure key-based SSH access
Open the OpenSSH configuration file:
```sh
nano /etc/ssh/sshd_config
```
Find these settings and change them to the values below. Add them at the bottom if they are missing.
```ini
PubkeyAuthentication yes
PermitRootLogin prohibit-password
```
`PermitRootLogin prohibit-password` allows `root` to connect with an SSH key but prevents password-based SSH login.
Before restarting OpenSSH, make sure the public key used for your current `root` login is already in `/root/.ssh/authorized_keys`. Otherwise, keep the console open so you can restore access.
### Check and restart OpenSSH
Check the configuration:
```sh
sshd -t
```
The command should return no output. If it reports an error, correct the file before continuing.
Restart OpenSSH with the command for the server's operating system:
```sh
systemctl restart ssh
```
```sh
systemctl restart sshd
```
```sh
service sshd restart
```
### Run the Coolify installation script
```sh
curl -fsSL https://cdn.coollabs.io/coolify/install.sh | bash
```
The script uses the OpenSSH service you configured, creates the **localhost** SSH key, authorizes it, and adds the **localhost** server to Coolify.
### Confirm the localhost server is ready
1. Open the Coolify dashboard.
2. Select **Servers**.
3. Open **localhost**.
4. Confirm that the **General** page says **Server is reachable and validated**.
If **localhost** is not reachable, use the **Manual** tab.
### Configure OpenSSH and the localhost connection manually
Use these steps when the automatic setup did not complete or the existing **localhost** connection is broken.
### Log in to the server
Log in as `root` through SSH or use the console provided by your hosting provider.
### Install OpenSSH
Run the commands below based on your server's operating system.
```sh
apt-get update
apt-get install -y openssh-server
systemctl enable --now ssh
```
Use this for CentOS, RHEL, Rocky Linux, AlmaLinux, Fedora, Amazon Linux, Oracle Linux, or TencentOS.
```sh
dnf install -y openssh-server
systemctl enable --now sshd
```
```sh
zypper refresh
zypper install -y openssh
systemctl enable --now sshd
```
```sh
pacman -Sy --noconfirm openssh
systemctl enable --now sshd
```
```sh
apk add openssh
rc-update add sshd default
service sshd start
```
OpenSSH is installed and configured to start when the server boots.
### Configure key-based SSH access
Open the OpenSSH configuration file:
```sh
nano /etc/ssh/sshd_config
```
Find these settings and change them to the values below. Add them at the bottom of the file if they are missing.
```ini
PubkeyAuthentication yes
PermitRootLogin prohibit-password
```
`PermitRootLogin prohibit-password` allows `root` to connect with an SSH key but prevents password-based SSH login.
Keep this server session open. Do not restart OpenSSH until the localhost public key has been added to `/root/.ssh/authorized_keys`, or you may lose SSH access.
### Generate the localhost SSH key
Create the directories used by Coolify:
```sh
mkdir -p /data/coolify/ssh/keys
mkdir -p /root/.ssh
chmod 700 /root/.ssh
```
Generate a new key without a passphrase:
```sh
ssh-keygen -t ed25519 -a 100 \
-f /data/coolify/ssh/keys/id.root@host.docker.internal \
-q -N "" -C coolify
```
If the command asks whether to overwrite an existing key, enter `y`. The remaining steps add the replacement private key to Coolify.
### Authorize the localhost SSH key
Add the generated public key to the `root` account:
```sh
cat /data/coolify/ssh/keys/id.root@host.docker.internal.pub \
>> /root/.ssh/authorized_keys
chmod 600 /root/.ssh/authorized_keys
chown 9999:root /data/coolify/ssh/keys/id.root@host.docker.internal
```
The key must not have a passphrase. Coolify cannot answer an interactive passphrase or two-factor authentication prompt when it connects.
### Check and restart OpenSSH
Check the configuration before restarting the service:
```sh
sshd -t
```
The command should return no output. If it reports an error, correct the file before continuing.
Restart OpenSSH with the command for the server's operating system:
```sh
systemctl restart ssh
```
```sh
systemctl restart sshd
```
```sh
service sshd restart
```
Keep the current session open and use a second terminal to confirm that key-based SSH access still works before closing it.
### Copy the localhost private key
Display the private key in the server terminal:
```sh
cat /data/coolify/ssh/keys/id.root@host.docker.internal
```
Copy the complete output, including the `BEGIN` and `END` lines.
### Open the Keys and Tokens page on dashboard
1. Open **Keys & Tokens** in the Coolify sidebar.
2. Select **Private Keys**.
3. Select **+ Add**.
### Add the localhost private key
1. Enter a name such as `localhost key`.
2. Paste the value copied in the previous step into **Private Key**.
3. Select **Continue**.
Do not paste the private key into **Public Key** or `/root/.ssh/authorized_keys`.
### Open the localhost server
1. Open **Servers** in the Coolify sidebar.
2. Select **localhost**.
### Select the private key
1. Select **Private Key** in the server sidebar.
2. Find the key you added in the previous step.
3. Select **Use this key**.
Coolify checks the connection before saving the new key.
### Validate the localhost server
1. Open **General** for the **localhost** server.
2. Select **Validate connection**.
3. Wait for validation to finish.
The setup is complete when the page says **Server is reachable and validated**.
### Configure OpenSSH on a remote server
Most Linux servers already have OpenSSH installed. Use these steps to install it when needed and confirm that public-key authentication is enabled.
### Log in to the server
Log in as `root` through SSH or use the server console.
### Install OpenSSH
If OpenSSH is missing, run the commands below based on your server's operating system.
```sh
apt-get update
apt-get install -y openssh-server
systemctl enable --now ssh
```
Use this for CentOS, RHEL, Rocky Linux, AlmaLinux, Fedora, Amazon Linux, Oracle Linux, or TencentOS.
```sh
dnf install -y openssh-server
systemctl enable --now sshd
```
```sh
zypper refresh
zypper install -y openssh
systemctl enable --now sshd
```
```sh
pacman -Sy --noconfirm openssh
systemctl enable --now sshd
```
```sh
apk add openssh
rc-update add sshd default
service sshd start
```
### Make sure the root SSH key is authorized
Before disabling password-based root login, make sure the public key used for the `root` account is already in `/root/.ssh/authorized_keys`.
If you have not added a key yet, complete [Create and authorize an SSH key](/core/infrastructure/servers/add-server#create-and-authorize-an-ssh-key), then return to this step.
### Update the OpenSSH configuration
Open the configuration file:
```sh
nano /etc/ssh/sshd_config
```
Find these settings and change them to the values below. Add them at the bottom if they are missing.
```ini
PubkeyAuthentication yes
PermitRootLogin prohibit-password
```
`PermitRootLogin prohibit-password` allows `root` to connect with an SSH key but prevents password-based SSH login.
Do not close the current SSH or console session until you confirm that the public key works. This session lets you correct the configuration if the new connection fails.
### Check and restart OpenSSH
Check the configuration:
```sh
sshd -t
```
The command should return no output. If it reports an error, correct the file before restarting OpenSSH.
Restart OpenSSH with the command for the server's operating system:
```sh
systemctl restart ssh
```
```sh
systemctl restart sshd
```
```sh
service sshd restart
```
### Confirm the SSH connection
Open a second terminal and connect with the authorized key:
```sh
ssh root@
```
If OpenSSH uses a port other than `22`, run:
```sh
ssh -p root@
```
Keep the original server session open until this connection succeeds.
### Connect the server to Coolify
Finish the [Connect the server](/core/infrastructure/servers/add-server#connect-the-server) steps and validate the server.
---
## Troubleshooting
The private key selected for the server does not match a public key in the SSH user's `authorized_keys` file.
For **localhost**, repeat the **Authorize the localhost SSH key** and **Select the private key** steps in the **Manual** tab.
For a remote server, repeat the SSH key steps in [Add Server](/core/infrastructure/servers/add-server#create-and-authorize-an-ssh-key).
Confirm that the server IP address and SSH port are correct. Then confirm that the [firewall](/core/infrastructure/servers/firewall) allows the SSH connection from Coolify.
OpenSSH is not running or is listening on a different port. Start the OpenSSH service, then confirm that the port in **Servers > your server > General** matches the port used by OpenSSH.