-
-
Notifications
You must be signed in to change notification settings - Fork 2
cmd access
Manage SSH key access on an already-deployed server.
nself access <subcommand> [flags]
Grant, revoke, and list SSH key access on a running nself host, without a raw
ssh session and hand-edited authorized_keys.
nself security hardens a host (firewall, fail2ban, sshd config) but has no
concept of individual keys or people. hcloud ssh-key create only injects a
key when a server is created, so it does nothing for a host that is already
running. nself access fills that gap: it manages authorized_keys entries
directly, over SSH, on a host that is already live.
nself access <subcommand> [flags]
Add a person's public key to a host's authorized_keys, or update it if they
already have one. Re-granting the identical key is a no-op. Granting a
different key, or different --sudo/--docker/--expires metadata, for the
same --user replaces that person's single managed line rather than adding a
second one.
Before writing anything, the current authorized_keys is backed up to a
timestamped sibling file, and the key's SHA256 fingerprint is echoed back so
you can verify it against what the person sent you.
nself access grant --host root@203.0.113.5 --user alice --key @alice.pubFlags: --host (required, [user@]host), --identity (local private key
used to connect, defaults to ~/.ssh/id_ed25519), --user (required, a
label for whose key this is), --key (required, public key material or
@path/to/file), --sudo and --docker (record the intended privilege
level as metadata only, this command does not itself change OS group
membership), --expires (optional YYYY-MM-DD), --dry-run (print the
resulting diff, change nothing).
Remove a person's public key from a host's authorized_keys.
Refuses to remove the last remaining key on the host, since that would lock
out all SSH access, unless --force is given. This is the one command in
nself access that can end a session mid-flight if pointed at the wrong
host, so --dry-run is worth running first against anything that matters.
nself access revoke --host root@203.0.113.5 --user aliceFlags: --host (required), --identity, --user (required), --force
(allow removing the last remaining key), --dry-run.
Show every person nself access has granted a key to on a host, their
fingerprint, recorded --sudo/--docker/--expires metadata, and whether
that expiry has passed. Also reports how many keys in the file were not
granted by this command (the original key the host shipped with, for
example) so those are visibly accounted for rather than silently ignored.
nself access list --host root@203.0.113.5Flags: --host (required), --identity, --json (machine-readable output).
| Flag | Default | Description |
|---|---|---|
--help, -h
|
— | Show help |
| Name | Description |
|---|---|
grant |
Grant a person SSH key access to a host |
list |
List who has SSH key access to a host |
revoke |
Revoke a person's SSH key access to a host |
# Grant alice access using a key file
nself access grant --host root@203.0.113.5 --user alice --key @alice.pub# Grant bob access with an inline key and sudo metadata
nself access grant --host root@203.0.113.5 --user bob --key "ssh-ed25519 AAAA... bob@laptop" --sudo# Grant carol access with an expiry date
nself access grant --host root@203.0.113.5 --user carol --key @carol.pub --expires 2026-12-31# Preview a grant without changing anything
nself access grant --host root@203.0.113.5 --user dave --key @dave.pub --dry-run# See who currently has access, then revoke someone who left
nself access list --host root@203.0.113.5
nself access revoke --host root@203.0.113.5 --user alice- cmd-security, firewall, fail2ban, and sshd hardening for the same host
-
cmd-deploy, the SSH transport
nself accessmirrors for connecting to staging and production - Commands, full command index
ɳSelf CLI v1.0.9. MIT licensed. Docs CC BY 4.0.
GitHub · Issues · Discussions · nself.org · nself.org/docs
Getting Started
Commands
- Commands, Overview
- Lifecycle: cmd-init · cmd-build · cmd-start · cmd-stop · cmd-restart · cmd-dev
- Monitoring: cmd-status · cmd-logs · cmd-health · cmd-urls · cmd-doctor · cmd-monitor · cmd-alerts · cmd-sentry · cmd-watchdog
- Data: cmd-db · cmd-backup · cmd-dr · cmd-queue · cmd-webhooks
- Config: cmd-config · cmd-service · cmd-env · cmd-promote
- Networking: cmd-ssl · cmd-trust · cmd-dns-setup
- Security: cmd-access · cmd-security · cmd-secrets
- Tenancy: cmd-tenant · cmd-billing
- Plugins: cmd-plugin · cmd-license · cmd-dogfood (extracted, CLI-R11) · cmd-k8s (extracted, CLI-R11) · cmd-encryption (extracted, CLI-R11) · cmd-waf (extracted, CLI-R11) · cmd-federation (extracted, CLI-R11) · cmd-mail (extracted, CLI-R11) · cmd-dlq (extracted, CLI-R11)
- AI: cmd-ai · cmd-claw · cmd-model
- Templates: cmd-template
- Utilities: cmd-exec · cmd-clean · cmd-reset · cmd-update · cmd-upgrade · cmd-version · cmd-admin · cmd-migrate · cmd-migrate-firebase · cmd-migrate-supabase · cmd-completion
Features
- Features, Overview
- Feature-Auth
- Feature-Storage
- Feature-Search
- Feature-Functions
- Feature-Email
- Feature-Monitoring
- Feature-Plugins
- Feature-nClaw, AI Assistant
- Feature-nChat, Messaging
- Feature-nTV, Media Player
- Feature-nFamily, Family Social
- Feature-nCloud, Managed Hosting
- Feature-Memory-Rooms, Knowledge Organization
- Feature-Agent-Dashboard, Agent Metrics
- Feature-Image-Generation, AI Image Generation
Configuration
- Configuration, Overview
- Config-Env-Vars
- Config-Postgres
- Config-Hasura
- Config-Auth
- Config-Nginx
- Config-Optional-Services
- Config-Custom-Services
- Config-System
Plugins (87 + 10 monitoring)
Free (25)
- plugin-backup
- plugin-content-acquisition
- plugin-content-progress
- plugin-cron
- plugin-donorbox
- plugin-feature-flags
- plugin-github
- plugin-github-runner
- plugin-invitations
- plugin-jobs
- plugin-link-preview
- plugin-mdns
- plugin-mlflow
- plugin-monitoring
- plugin-notifications
- plugin-notify
- plugin-paypal
- plugin-search
- plugin-shopify
- plugin-stripe
- plugin-subtitle-manager
- plugin-tokens
- plugin-torrent-manager
- plugin-vpn
- plugin-webhooks
Pro (62)
- plugin-access-controls
- plugin-activity-feed
- plugin-admin-api
- plugin-nself-ai-gateway
- plugin-nself-ai-mcp
- plugin-nself-ai-mcp
- plugin-analytics
- plugin-auth
- plugin-backup-pro
- plugin-bots
- plugin-browser
- plugin-calendar
- plugin-cdn
- plugin-chat
- plugin-claw
- plugin-claw-budget
- plugin-claw-news
- plugin-claw-web
- plugin-cloudflare
- plugin-cms
- plugin-compliance
- plugin-cron-pro
- plugin-ddns
- plugin-devices
- plugin-documents
- plugin-donorbox-pro
- plugin-entitlements
- plugin-epg
- plugin-file-processing
- plugin-game-metadata
- plugin-geocoding
- plugin-geolocation
- plugin-google
- plugin-home
- plugin-idme
- plugin-knowledge-base
- plugin-linkedin
- plugin-livekit
- plugin-media-processing
- plugin-meetings
- plugin-moderation
- plugin-mux
- plugin-notify-pro
- plugin-object-storage
- plugin-observability
- plugin-paypal-pro
- plugin-photos
- plugin-podcast
- plugin-post
- plugin-realtime
- plugin-recording
- plugin-retro-gaming
- plugin-rom-discovery
- plugin-shopify-pro
- plugin-social
- plugin-sports
- plugin-stream-gateway
- plugin-streaming
- plugin-stripe-pro
- plugin-support
- plugin-tmdb
- plugin-voice
- plugin-web3
- plugin-workflows
Planned (26)
plugin-auditplugin-blogplugin-checkoutplugin-commerceplugin-drmplugin-exportplugin-flowplugin-importplugin-ldapplugin-mailgunplugin-mediaplugin-oauth-providersplugin-pagesplugin-postmarkplugin-rate-limitplugin-reportsplugin-samlplugin-schedulerplugin-sendgridplugin-ssoplugin-subscriptionplugin-thumbplugin-transcoderplugin-twilioplugin-wafplugin-watermark
Guides
- Guide-Production-Deployment
- Guide-SSL-Setup
- Guide-Multi-Tenancy
- Guide-Security-Hardening
- Guide-Monitoring-Setup
- Guide-Backup-Restore
- Guide-Custom-Services
- Guide-Migration-from-v1
Architecture
Reference
- API-Reference
- error-codes, Error Codes
Licensing
Security
Brand
Operations
- operations/release-cascade, Release Cascade
- operations/self-healing, Self-Healing Schema
- operations/redis-tuning, Redis Pool Tuning
- operations/meilisearch-warmup, MeiliSearch Warm-Up
- operations/jwt-rotation, JWT Key Rotation
- operations/windows-wsl2-setup, Windows / WSL2 Setup
- operations/gemini-oauth-reauth, Gemini OAuth Reauth
Contributing
Admin
- USER-ACTION-QUEUE, Pending Admin Actions
All commands (52)
- A: cmd-access · cmd-account · cmd-admin
- B: cmd-backup · cmd-build · cmd-bundle
- C: cmd-ci · cmd-clean · cmd-completion · cmd-config
- D: cmd-db · cmd-deploy · cmd-dev · cmd-doctor
- E: cmd-env · cmd-exec
- F: cmd-functions
- G: cmd-generate
- H: cmd-health · cmd-help-topics
- I: cmd-init · cmd-install
- L: cmd-license · cmd-login · cmd-logout · cmd-logs
- M: cmd-man · cmd-mcp · cmd-migrate
- O: cmd-oauth · cmd-ops
- P: cmd-plugin · cmd-promote
- R: cmd-remove · cmd-reset · cmd-restart · cmd-runner
- S: cmd-secrets · cmd-security · cmd-self-heal · cmd-server · cmd-service · cmd-start · cmd-status · cmd-stop
- T: cmd-telemetry · cmd-template · cmd-trust
- U: cmd-update · cmd-urls
- V: cmd-verify-sbom · cmd-version