CertShell

SSH from your browser.
No keys to manage.

Log in with your identity provider. CertShell signs a 15-minute SSH certificate for each session, valid for one host and one login.

Get started View on GitHub
# enroll a host (one-time snippet from the admin UI)
root@web1:~# curl -fsS https://ssh.example.com/enroll/… | sh
✓ CA trusted, sshd reloaded, host key pinned

# later, from the browser, as alice (group: ops)
✓ cert serial 4182 · principal web1:root · valid 15m · no forwarding
root@web1:~#

How it works

  1. 1

    Log in

    Through Pocket ID or any OIDC provider. Your IdP groups decide which hosts and logins you get.

  2. 2

    Cert minted

    CertShell signs a fresh key with a 15-minute cert for exactly one host and one login.

  3. 3

    Shell opens

    A full terminal in your browser. The session is audit-logged and the cert expires on its own.

Features

Short-lived certificates

Every terminal gets its own cert. One host, one login, no forwarding, gone in 15 minutes.

One-line enrollment

Run a one-time snippet as root. Existing authorized_keys keep working, so you can't lock yourself out.

Access map in the UI

Map IdP group → host → login from the admin page. No edits on the host after enrollment.

Host key pinning

The host key is recorded at enrollment. A different machine at the same address is refused.

Audit trail

Logins, certs and sessions go to the app and stdout. sshd logs each cert's ID and serial too.

Hardened container

Non-root, read-only root filesystem, all capabilities dropped. Strict headers and rate limits.

Quick start

cp -r examples/caddy certshell && cd certshell
cp .env.example .env     # set SSH_DOMAIN, ID_DOMAIN, OIDC_* ...
docker compose up -d

Generate your own config with the setup generator. Full walkthrough in the docs.