Open source · MIT licensed · Linux & Windows

One client for SSH, SFTP, S3 and Kubernetes.

A modern, security-focused desktop app that pairs a real OpenSSH terminal with a dual-pane file manager, S3 object storage, and Kubernetes exec & debugging — with hardware key and smartcard support built in.

AppImage · .deb · .rpm · Windows installer & portable

sshs3 start screen with the new cloud-terminal logo
features

Everything you touch on a server, in one window.

Built for sysadmins, DevOps and developers who work across many hosts and clusters, hop through bastions, and authenticate with hardware tokens.

Real OpenSSH terminal

Spawns your system's own ssh — so ~/.ssh/config, agents and aliases just work. Tabs and recursive split panes.

Dual-pane file manager

Local disk, SFTP, S3 and pod filesystems side by side. Drag & drop, folder sync, search, chmod and a transfer queue.

Kubernetes & OpenShift

Cluster tree from your kubeconfig, container exec, live logs, port-forwarding and kubectl debug ephemeral containers.

S3 & object storage

AWS, MinIO, NetApp StorageGRID and any S3-compatible endpoint. AWS SSO login, policies, CORS and versioning.

FIDO2 & smartcards

YubiKey, resident FIDO2 keys, PKCS#11, SITHS and Net iD — with an in-app PIN dialog and touch prompts.

Tunnels & jump hosts

ProxyJump, agent forwarding, local / remote / SOCKS tunnels, HTTP & SOCKS proxies, and X11 forwarding with a bundled X server on Windows.

terminal

Split anything, restore everything.

Konsole-style recursive splits, each pane with its own connection picker and isolated session.

  • Local shells next to SSH — including PowerShell, cmd and WSL on Windows
  • Session persistence — tabs, layouts and working directories come back after restart
  • Managed ssh-agent wired into local shells automatically
Three split panes: a remote SSH session, a local shell and a second SSH session
kubernetes

Get inside any pod — even distroless.

Browse container filesystems like a normal folder and attach debug containers without restarting anything.

  • Pod file explorer — upload, download and edit files, no agent needed in the container
  • kubectl debug presets — Netshoot, RHEL support tools, BusyBox, Ubuntu, or your own image
  • Live logs with search, plus port-forwarding and a pod inspector
  • OpenShift login — paste your oc login command
Attach Debug Container dialog with Netshoot preset
files

Local disk, SFTP, S3 and pods — one interface.

Drag between panes, diff and sync folders across any two backends, and edit files in place.

  • Folder sync with diff, compare and reusable profiles — even remote ↔ remote
  • Content search across local, SFTP and S3 with regex
  • Editor with live Markdown preview
  • Transfer queue with pause, resume and conflict resolution
Dual-pane file manager with an S3 bucket and local disk, showing the context menu
object storage

A proper S3 browser.

Manage buckets the way you manage folders — with the admin features you actually need.

  • AWS SSO device-flow login for short-lived credentials
  • Bucket policy editor, CORS, tagging and object versioning
  • Self-signed CA support and your OS trust store
An S3 bucket next to a Kubernetes pod filesystem, with bucket policy, CORS and versioning in the context menu
editor

Edit remote files without leaving the app.

Open any file from local disk, SFTP, S3 or a pod — and preview Markdown as you write.

  • Live Markdown preview with GitHub-flavored tables and code blocks
  • Tail -f a growing log file in the same viewer
  • External editor hand-off when you'd rather use your own
Built-in editor showing a rendered Markdown preview
tunnels

Tunnels, saved and one click away.

Keep every port forward per connection and start or stop them from a single dialog.

  • Local, remote and SOCKS forwards per profile
  • Jump hosts and agent forwarding for multi-hop access
  • Pod port-forwarding from the Kubernetes tab of the Connection Manager
SSH Tunnels dialog listing saved forwards per connection
sync

Your setup follows you.

Move between machines without rebuilding your connections or your shell environment. Both features are opt-in and off by default.

Profile sync

Back up and sync connection profiles, dotfile pools and settings to your own S3 bucket or SFTP server — there is no sshs3 cloud.

  • Encrypted client-side with AES-256-GCM before upload
  • Unlock with a master password or a smartcard / hardware token
  • Auto-sync pushes changes and pulls remote updates in the background
  • Per-record merge, so two machines edited independently don't overwrite each other
  • Keeps a managed block in ~/.ssh/config in step, so plain ssh <alias> works everywhere

Dotfiles sync

Keep .bashrc, .vimrc and friends the same on every server you log in to.

  • Define a pool of files and assign it to specific SSH profiles
  • On connect, a short background SFTP check compares the pool against the server
  • Review the diff in a non-blocking banner, or let it update silently per profile policy
  • Uses existing sessions, so hardware-key logins need no extra touches
security

Your keys stay yours.

Hardware-first authentication, encrypted-at-rest secrets, and sync that never touches a server we run.

  • Smartcards & FIDO2 — SITHS, Net iD, OpenSC, YubiKey PIV, p11-kit and resident ed25519-sk keys
  • PIN caching modes — always prompt, once per terminal, or unlock at startup
  • OS keyring — passwords and keys encrypted via libsecret, DPAPI or Keychain
  • Zero-knowledge sync — profiles encrypted with AES-256-GCM client-side, stored in your S3 bucket or SFTP server
  • Host key verification with an interactive trust dialog
# unlock your card once, connect everywhere
❯ ssh prod-bastion
⚿  Enter PIN for SITHS card
☝  Touch your security key to authenticate

alun@prod-bastion in /srv/app
❯ kubectl get pods -n payments
NAME              READY   STATUS
api-7c9d4f6b8c    1/1     Running
download

Free and open source.

Grab the latest build for your platform. Every release is published on GitHub.

sshs3 is under active early-stage development — expect rough edges. Found one? Open an issue.