Computing and the Command Line

GitHub over SSH

GitHub hosts remotes and adds pull requests, issues, and a web view. Connect with an SSH key: generate an Ed25519 key pair with a passphrase, let ssh-agent remember it, add the public key to your GitHub account, and test with ssh -T. Create a repository on GitHub, add it as origin with its SSH URL, and push. HTTPS with a personal access token as the alternative, and keeping private things private.

  • 5 min
  • 8 steps
  • 2 questions
  • Lesson 35 of 80

In this lesson

  1. What GitHub adds
  2. Two ways to connect
  3. Making a key
  4. Adding it to GitHub
  5. Your first GitHub repository
  6. Keeping private things private
  7. Your turn
  8. So

What GitHub adds

GitHub hosts git repositories. Your repository on GitHub is an ordinary remote, plus a web view of your code and history, pull requests for proposing and reviewing changes (next lesson), issues for tracking work, and an off-site backup. GitLab, Codeberg, and others do the same job; the git commands don’t change.

Make a free account at github.com. Use the same email you set as user.email (module 1), so your commits are linked to your account.

Two ways to connect

GitHub accepts two kinds of remote URL 1:

  • HTTPS, like https://github.com/you/garden.git. Git asks for your username and a personal access token, which GitHub uses in place of your password 1.
  • SSH, like git@github.com:you/garden.git, which uses an SSH key instead of any password.

SSH is set up once per computer and then just works. It’s also the same SSH you’ll use to log in to other Linux machines (Linux course). Here’s how.

Making a key

An SSH key is a pair of files. The private key stays on your computer and is never shared; the public key can go anywhere. A server holding your public key can check that you hold the matching private key without the private key ever being sent 2.

Generate an Ed25519 key, GitHub’s recommended type, labeled with your email 2:

me@linuxbox:~$ ssh-keygen -t ed25519 -C "you@example.com"
Generating public/private ed25519 key pair.
Enter file in which to save the key (/home/me/.ssh/id_ed25519):
Enter passphrase (empty for no passphrase):
Enter same passphrase again:

Press Enter to accept the default file. Then type a passphrase: it encrypts the private key on disk, so a stolen laptop or backup doesn’t give someone your GitHub account 2. You end up with two files, ~/.ssh/id_ed25519 (private) and ~/.ssh/id_ed25519.pub (public).

To avoid typing the passphrase on every push, load the key into ssh-agent, which remembers it for your session 2:

me@linuxbox:~$ eval "$(ssh-agent -s)"
me@linuxbox:~$ ssh-add ~/.ssh/id_ed25519

Make one key per computer, so you can revoke one without touching the others.

Left, your computer, with two key files: the private key ~/.ssh/id_ed25519, never shared and protected with a passphrase, and the public key ~/.ssh/id_ed25519.pub, safe to share and pasted into GitHub; ssh-agent remembers the passphrase for the session. An arrow labeled copy goes from the public key to GitHub's Settings, SSH and GPG keys page, which shows ssh-ed25519 AAAAC3Nz... you@laptop. On each connection GitHub checks that you hold the matching private key, which never leaves home. Below, setup once per computer: ssh-keygen -t ed25519 -C "you@example.com"; cat ~/.ssh/id_ed25519.pub to copy into GitHub; ssh -T git@github.com, answered with Hi USERNAME! You've successfully authenticated, but GitHub does not provide shell access.
One key pair per computer: the private half stays put. Credit: StudyCorner diagram · CC BY 4.0 · Source

Quick check

Which key file do you paste into GitHub?

Adding it to GitHub

Print the public key and copy it 3:

me@linuxbox:~$ cat ~/.ssh/id_ed25519.pub
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... you@example.com

On GitHub: your profile picture, Settings, SSH and GPG keys, New SSH key. Give it a title naming the computer, like “WSL laptop,” paste the key, and save 3.

Test the connection 4:

me@linuxbox:~$ ssh -T git@github.com
The authenticity of host 'github.com (...)' can't be established.
ED25519 key fingerprint is SHA256:+DiY3wvvV6TuJJhbpZisF/zLDA0zPMSvHdkr4UvCOqU.
Are you sure you want to continue connecting (yes/no)? yes
Hi you! You've successfully authenticated, but GitHub does not provide shell access.

The first time, SSH asks whether to trust GitHub’s server. Check that the fingerprint matches the one GitHub publishes before typing yes 4. SSH remembers it from then on.

Your first GitHub repository

On GitHub, click New repository, name it garden, choose Private, and leave it empty (no README) since you already have one locally. GitHub then shows the commands; choose the SSH URL 5:

me@linuxbox:~/garden$ git remote add origin git@github.com:you/garden.git
me@linuxbox:~/garden$ git push -u origin main

Refresh the page: your files and history are there. From now on, git push and git pull work as in the last lesson. If you’d already added an HTTPS remote, switch it with git remote set-url origin git@github.com:you/garden.git.

Quick check

Which remote URL uses your SSH key?

Keeping private things private

  • Private repositories are visible only to you and people you invite; public ones to everyone. Start private.
  • Never commit secrets: passwords, tokens, private keys. Remember module 2: once committed, a secret is in history even after you delete the file, so change it instead.
  • Never paste your private key anywhere. If it’s ever exposed, delete the public key from GitHub’s settings and make a new pair.

Your turn

Exercises

  1. Make a GitHub account (or sign in), then generate an Ed25519 key with a passphrase.
  2. Add the public key to GitHub and test with ssh -T git@github.com.
  3. Create a private, empty garden repository on GitHub, add it as origin with the SSH URL, and push.
  4. Make a change on GitHub’s web editor (edit README.md there), then git pull it.
  5. Clone the repository into a second folder, as a “second computer,” and practice push and pull between the two through GitHub.
Answers
  1. Hi <your-username>! You've successfully authenticated, but GitHub does not provide shell access. If you see Permission denied (publickey), the key isn’t loaded (ssh-add -l lists loaded keys) or the public key wasn’t saved on GitHub.
  2. git pull fast-forwards your main to include the web edit, which shows up in git log as its own commit.
  3. git clone git@github.com:you/garden.git ~/garden2; commit and push in one, git pull in the other.

So

GitHub hosts your remote and adds pull requests and a web view. Connect over SSH: ssh-keygen -t ed25519 with a passphrase, ssh-add it to the agent, paste the public key into GitHub, and test with ssh -T git@github.com. Then add the SSH URL as origin and git push -u origin main. Keep repositories private by default and secrets out of them.

Lesson complete

Nice work.

1day streak
0/1today's goal
–correct

Up next · 5 min

Pull Requests

Next lesson
Sources for this lesson
  1. 1
    About remote repositories. GitHub Docs. verifiedYou can push to HTTPS URLs (https://github.com/user/repo.git) or SSH URLs (git@github.com:user/repo.git); the default remote is usually named origin. Over HTTPS, when git asks for your password, enter a personal access token.
  2. 2
    Generating a new SSH key and adding it to the ssh-agent. GitHub Docs. verifiedGenerate a key with ssh-keygen -t ed25519 -C "your_email@example.com" (RSA 4096 for legacy systems), accept the default file, and set a secure passphrase; with a passphrase, add the key to ssh-agent (eval "$(ssh-agent -s)", ssh-add) so the agent remembers it.
  3. 3
    Adding a new SSH key to your GitHub account. GitHub Docs. verifiedCopy the public key (the .pub file), then in GitHub Settings, SSH and GPG keys, choose New SSH key, give it a descriptive title, paste it, and save.
  4. 4
    Testing your SSH connection. GitHub Docs. verifiedRun ssh -T git@github.com; on first connection, verify the host key fingerprint (Ed25519: SHA256:+DiY3wvvV6TuJJhbpZisF/zLDA0zPMSvHdkr4UvCOqU) against GitHub's published fingerprints before typing yes; success reads Hi USERNAME! You've successfully authenticated, but GitHub does not provide shell access.
  5. 5
    Scott Chacon, Ben Straub. Pro Git, 2nd edition. Apress; free online at git-scm.com. 2014. verifiedFree CC BY-NC-SA 3.0 book, maintained online. Ch. 1: version control; Git's 2005 origin when the Linux kernel lost free use of BitKeeper; snapshots, not differences (unchanged files stored once); nearly every operation local; integrity through 40-character SHA-1 checksums; the three states (modified, staged, committed) and three areas (working tree, staging area or index, .git directory); first-time setup with system/global/local config levels, user.name and user.email baked into commits, core.editor, git config --list --show-origin. Ch. 2: git init, status (and -s), add, diff and diff --staged, commit (-m, -a), .gitignore, log options, amending, undoing, remotes, tags, aliases. Ch. 3: branches as movable pointers, HEAD, merging and conflicts, remote branches, rebasing and its rule. Ch. 7: reset demystified, stashing, revision selection. Ch. 8: core.autocrlf true on Windows, input on Linux and macOS. Ch. 10: objects (blob, tree, commit) and references.