sshkeeper v0.7.0 — encrypted sync between devices
v0.7.0 keeps your devices in step: profiles, port forwards, command
templates, groups and tags, vault secrets, and the private keys your profiles
use travel end-to-end encrypted through a folder or a git repository.
Added
- Sync between devices.
m→ Settings → Synchronization chooses the
storage — a shared folder (Syncthing, Nextcloud, Dropbox, a network drive)
or a git repository — and the form shows only the fields that storage
needs. The first device creates the sync space; others join with a
six-digit code. - Six-digit pairing. "Add device" shows a code valid for ten minutes.
The new device enters it together with the master password of the device
showing it. The code alone is worthless and is deleted after use; in git it
lives on a temporary branch that never enters the history. - Recovery key. Shown when the sync space is created, for the case when
every device is lost. It also works in place of a pairing code. - Automatic sync. With auto sync on, the TUI syncs at start and three
seconds after each change. The dashboard header shows⇅with the time
since the last sync, and changes from other devices refresh the list. sshkeeper synccommands:setup,init,add-device,join,
status,recovery-key,leave, and plainsync.
How secrets stay secret
- Everything travels in one file sealed with XChaCha20-Poly1305 under a
random 256-bit key. The storage sees a format tag and a key fingerprint —
no names, hosts, or even how many secrets exist. - The sync key lives only in each device's vault; a stolen sync file has no
password to guess. - Sync refuses to run while the vault is locked, so missing secrets are never
mistaken for deletions. - Existing key files are never overwritten, and a device's own different key
at the same path never travels to other devices. - Changes merge per item by the latest edit; deletions travel too. Device-local
facts — last connection, last test, running tunnels, language, sort order —
stay on each device.
Changed
- Manage → Settings is now a menu with Language and Synchronization.
Fixed
- Esc in the identity-file, tags, startup-command, or route picker of the
server form left the whole form instead of closing the picker. With a filter
typed in a picker, the first Esc now clears the filter. - Groups, Tags, Command templates, Sessions, and Running tunnels opened from
the Manage menu return to it on Esc. - The vault no longer prints "Deriving key..." when saving, which could draw
over the TUI.
To install on Debian/Ubuntu x86-64, download the release asset and run
sudo apt install ./sshkeeper_0.7.0-1_amd64.deb (use the arm64 package on
ARM64). Git sync needs the system git; folder sync needs nothing extra.