Skip to main content

Claude/ChatGPT Prompt to Set Up Passwordless SSH Cleanly

Set up key-only SSH across multiple servers: ed25519 keys, agent, ~/.ssh/config aliases, password-auth disabled, fail2ban safety net.

Fill in the placeholders

Edit the values, then copy your finished prompt.

Your Prompt
prompt.txt
You are a senior Linux engineer. Return exact commands and config snippets, not prose, and keep me from locking myself out.

Context:
- Number of servers: 10
- Local OS: macOS
- Host aliases wanted: web1, web2, db1
- Key comment/identity: deploy@mylaptop

Deliverables:
1. Generate an ed25519 key with my identity comment and load it into the agent/keychain for my local OS.
2. Distribute the public key to all servers with ssh-copy-id, and verify key login works before changing anything server-side.
3. A ~/.ssh/config block using my aliases, each with HostName, User, IdentityFile, and IdentitiesOnly.
4. Server-side sshd_config changes to disable password auth and the reload command, with the order that prevents lockout.
5. fail2ban as a safety net, plus a one-line recovery path if a server rejects my key.

Output: numbered commands and config snippets in fenced blocks, in the safe order to run them.

What this prompt does

This prompt makes the model a senior Linux engineer and asks for exact commands and config snippets to set up key-only SSH across multiple servers — explicitly keeping you from locking yourself out. You set [server_count], [local_os], [aliases], and [key_identity], and it returns ed25519 key generation, key distribution with ssh-copy-id and verification, a ~/.ssh/config block using your aliases, server-side sshd_config changes to disable password auth, and fail2ban as a safety net.

The structure works because the fastest way to ruin an afternoon is disabling password auth before confirming your key works, so the prompt enforces verify-before-lockdown ordering. [key_identity] becomes the key comment so you can tell keys apart later, [aliases] populate the SSH config with HostName, User, IdentityFile, and IdentitiesOnly entries, [local_os] decides how the key loads into the agent or keychain, and [server_count] scopes the distribution step. Because the output is ordered commands and config snippets in the safe sequence to run them — generate, distribute, verify, then lock down — you can work through it top to bottom without having to reason about which step might strand you. The IdentitiesOnly flag in the config also stops the agent from offering every key and tripping over server limits.

When to use it

  • You're moving a fleet of servers from password to key-only SSH.
  • You want the verify step to come before the lockdown step, every time.
  • You need a clean ~/.ssh/config with friendly host aliases.
  • You're generating an ed25519 key and loading it into your OS keychain or agent.
  • You want password auth disabled with the reload order that prevents lockout.
  • You want fail2ban and a one-line recovery path as safety nets.

Example output

Expect numbered commands and config snippets in fenced blocks, ordered so the safe steps come first: ed25519 key generation with your identity comment, loading it into the agent or keychain for your OS, ssh-copy-id distribution with a login verification before any server change, a ~/.ssh/config block using your aliases, the sshd_config edits plus the reload command in lockout-safe order, and fail2ban setup with a recovery path.

Pro tips

  • Set [key_identity] to something meaningful like deploy@laptop so you can identify the key later in authorized_keys.
  • List your real [aliases] so the SSH config maps directly to how you refer to each host.
  • Match [local_os] to your actual machine; loading a key into the macOS keychain differs from a Linux agent.
  • Follow the order exactly — verify key login works before you touch sshd_config, as the prompt enforces.
  • Keep one SSH session open while you flip password auth off, so you have a way back in if something's wrong.
  • Confirm fail2ban isn't about to ban your own IP before you rely on it as the safety net.
  • Use IdentitiesOnly yes in each config block so the agent presents only the right key, avoiding too-many-auth-failures rejections on busy fleets.
  • Note the one-line recovery path before you start; knowing how to get back in turns a scary lockdown into a routine change.

Frequently Asked Questions

How does this stop me from locking myself out?
It enforces a verify-before-lockdown order: you distribute the key and confirm key login works before disabling password auth. It also sets up fail2ban with a one-line recovery path and advises keeping a second session open while you change sshd_config.
Why ed25519 instead of RSA keys?
The prompt generates ed25519 keys, which are modern, compact, and fast with strong security. They are the current recommended default for SSH, and the key carries your `[key_identity]` as a comment so you can identify it in authorized_keys later.
Does it work for both macOS and Linux locally?
Yes. Set `[local_os]` to your machine and the key-loading step adapts — using the macOS keychain or a Linux ssh-agent as appropriate — since loading and persisting keys differs between the two operating systems.
Can it set up several servers at once?
Yes. Set `[server_count]` and list your `[aliases]`, and it distributes the public key to all servers and builds a `~/.ssh/config` block with an entry per alias, each with HostName, User, IdentityFile, and IdentitiesOnly.
Engr Mejba Ahmed

Need this built for real?

Engr Mejba Ahmed

AI Developer · Software Engineer

I'm Mejba — I design and ship production AI systems, automations, and full-stack apps. If you want this turned into a working solution for your team, let's talk.

More in Linux & Shell Scripting Prompts

Engr Mejba Ahmed

Engr Mejba Ahmed

AI assistant · trained on my work

👋

Hey there!

Quick Actions

WhatsApp Direct line to me

Chat on WhatsApp

+880 1723 741224 · Replies within the hour on working days

Popular Questions

Engr Mejba Ahmed is connected
Engr Mejba Ahmed is typing...
Engr Mejba Ahmed avatar

✉ Want me to follow up? Drop your email

Engr Mejba Ahmed avatar

📞 Connect Directly

Choose how you'd like to reach me

WhatsApp

+880 1723 741224

Email

mejba.13@gmail.com

✓ Details sent! I'll get back to you shortly.

Powered by OpenAI

335+

Blog Posts

25

AI Courses

63

Projects

Services & Expertise

Pricing & Process

Learning & Resources

Connect & Support