sshs3 Product Documentation
Welcome to the official technical manual, operations runbook, and architectural reference portal for sshs3 — an enterprise-grade, security-focused SSH, SFTP, S3, and Kubernetes client engineered for system administrators, DevOps/SRE engineers, and developers.
Security & Operations Philosophy
sshs3 is architected strictly around the principle of Zero Private Key Extraction: private cryptographic keys remain inside your hardware tokens (YubiKey, PKCS#11, Smartcard) or are driven directly by your operating system's native OpenSSH client process. No private key bytes ever touch the JavaScript heap, and remote vault synchronization is secured via zero-knowledge client-side AES-256-GCM encryption.
Modules & Solutions
Select a module below to inspect full technical specifications, user workflows, protocol limitations, and diagnostics runbooks.
Installation, Updates & Air-Gap
Native packaging for Linux (DEB, RPM, AppImage) and Windows, cryptographic verification, and air-gap lockdown.
Connection Profiles & Key Deployment
Hierarchical profiles, authentication methods (password, key, FIDO2, smartcard), TOFU host verification, and ssh-copy-id GUI.
Terminal, Split Panes & Ergonomics
Real OpenSSH process via node-pty, Konsole-style recursive splits, managed SSH_AUTH_SOCK for local shells, search, and snippets.
Live Telemetry & Diagnostics Bar
Agentless zero-overhead system telemetry sampled over ControlMaster /proc and Kubernetes metrics.k8s.io API.
Dual-Pane File Manager & SFTP
OpenSSH SFTP v3 engine, in-memory cross-storage streams, byte-offset resume, directory diff & sync, and external file editor.
S3 Cloud & Object Storage
Multi-cloud compatibility (AWS, Cloudflare R2, MinIO, Ceph), AWS SSO OIDC device auth, presigned URLs, and object versioning.
Kubernetes & OpenShift Workloads
Live kubeconfig watcher, WebSocket container exec, agentless pod file explorer, and kubectl debug with Netshoot/RHEL.
Security, Hardware Keys & Smartcards
Zero Private Key Extraction, FIDO2 resident keys, visual touch banner, PKCS#11 smartcards, and ephemeral PIN caching (AppAgent).
Networking, Bastions & SSH Tunnels
ProxyJump bastions, standalone SSH tunnels dashboard (Local, Remote, Dynamic SOCKS5), and rootless X11 GUI forwarding via VcXsrv.
Environment & Profile Synchronization
Dotfiles pool session staging, zero-knowledge AES-256-GCM remote sync, smartcard vault unlock, and managed ~/.ssh/config block.
Git Integration & Developer Tooling
Cryptographic SSH commit signing, one-click key registration for GitHub/GitLab, and remote public key lookup (username.keys).
Configuration, Settings & Shortcuts
Full field reference across all 7 configuration panels, 2D Spatial Keyboard Navigation, and rebindable keyboard shortcuts.
Architecture, Security Model & Internals
Three-process Electron sandboxing, active Electron Fuses, threat model matrix, and autogenerated IPC contract reference.