Open source · MIT licensed · Linux & Windows

One client for SSH, SFTP, S3 and Kubernetes.

A modern, security-focused desktop app that pairs a real OpenSSH terminal with a dual-pane file manager, S3 object storage, and Kubernetes exec & debugging — with hardware key and smartcard support built in.

AppImage · .deb · .rpm · Windows installer & portable

sshs3 start screen with the new cloud-terminal logo
features

Everything you touch on a server, in one window.

Built for sysadmins, DevOps and developers who work across many hosts and clusters, hop through bastions, and authenticate with hardware tokens.

Real OpenSSH terminal

Spawns your system's own ssh — so ~/.ssh/config, agents and aliases just work. Tabs, recursive split panes, clickable links, snippets and search.

Terminal docs →

Dual-pane file manager

Local disk, SFTP, S3 buckets and pod filesystems side by side. Drag & drop file transfers directly between SSH servers and S3, folder sync and queue.

File manager docs →

Kubernetes & OpenShift

Cluster tree from your kubeconfig, container exec, live logs, port-forwarding and kubectl debug ephemeral containers.

Kubernetes docs →

S3 & object storage

AWS, MinIO, Ceph, Cloudflare R2 and any S3-compatible endpoint. Transfer to/from SSH, AWS SSO login, policies, CORS and versioning.

S3 storage docs →

Live telemetry & diagnostics

Real-time CPU, RAM, disk I/O, iowait and network throughput directly above active terminals. Zero extra logins, zero agent overhead.

Telemetry docs →

FIDO2 & smartcards

YubiKey, resident FIDO2 keys, PKCS#11, SITHS and Net iD — with an in-app PIN dialog and touch prompts.

Security docs →

Tunnels & jump hosts

ProxyJump, agent forwarding, local / remote / SOCKS tunnels, HTTP & SOCKS proxies, and X11 forwarding with a bundled X server.

Tunnels docs →

Git in the file manager

Branch, change and ahead/behind indicators for local and SFTP folders. One-click pull, clone here, and open in GitHub or GitLab.

Git integration docs →

Git & GitHub keys

Find your developer SSH keys, register them on GitHub or GitLab, and turn on SSH commit signing with allowed_signers.

Connection docs →
terminal

Split anything, restore everything.

Konsole-style recursive splits, each pane with its own connection picker and isolated session.

  • Local shells next to SSH — including PowerShell, cmd and WSL on Windows
  • Session persistence — tabs, layouts and working directories come back after restart
  • Managed ssh-agent wired into local shells automatically
Three split panes: a remote SSH session, a local shell and a second SSH session
performance

Live server telemetry, right above your shell.

Monitor system health in real time without third-party agents, extra logins, or terminal clutter.

  • ControlMaster multiplexing — samples /proc over existing connections with zero extra password or hardware key prompts
  • Deep diagnostics — click the bar for 15-minute history graphs, memory cache breakdown, and per-filesystem usage
  • Bottleneck detection — instant visibility into iowait disk bottlenecks and cloud hypervisor steal
  • Kubernetes pod metrics — container memory usage tracked against limits to catch OOMKills early
Live Performance Bar strip in an active terminal session
15-minute diagnostic history view with CPU donut, memory breakdown and filesystem gauges
kubernetes

Get inside any pod — even distroless.

Browse container filesystems like a normal folder and attach debug containers without restarting anything.

  • Pod file explorer — upload, download and edit files, no agent needed in the container
  • kubectl debug presets — Netshoot, RHEL support tools, BusyBox, Ubuntu, or your own image
  • Live logs with search, plus port-forwarding and a pod inspector
  • OpenShift login — paste your oc login command
Attach Debug Container dialog with Netshoot preset
files

Local disk, SFTP, S3 and pods — one interface.

Drag between panes, diff and sync folders across any two backends, and edit files in place.

  • Folder sync with diff, compare and reusable profiles — even remote ↔ remote
  • Content search across local, SFTP and S3 with regex
  • Editor with live Markdown preview
  • Transfer queue with pause, resume and conflict resolution
Dual-pane file manager with an S3 bucket and local disk, showing the context menu
object storage

A proper S3 browser.

Manage buckets the way you manage folders — with the admin features you actually need.

  • AWS SSO device-flow login for short-lived credentials
  • Bucket policy editor, CORS, tagging and object versioning
  • Self-signed CA support and your OS trust store
An S3 bucket next to a Kubernetes pod filesystem, with bucket policy, CORS and versioning in the context menu
editor

Edit remote files without leaving the app.

Open any file from local disk, SFTP, S3 or a pod — and preview Markdown as you write.

  • Live Markdown preview with GitHub-flavored tables and code blocks
  • Tail -f a growing log file in the same viewer
  • External editor hand-off when you'd rather use your own
Built-in editor showing a rendered Markdown preview
tunnels

Tunnels, saved and one click away.

Keep every port forward per connection and start or stop them from a single dialog.

  • Local, remote and SOCKS forwards per profile
  • Jump hosts and agent forwarding for multi-hop access
  • Pod port-forwarding from the Kubernetes tab of the Connection Manager
SSH Tunnels dialog listing saved forwards per connection
sync

Your setup follows you.

Move between machines without rebuilding your connections or your shell environment. Both features are opt-in and off by default.

Profile sync

Back up and sync connection profiles, dotfile pools and settings to your own S3 bucket or SFTP server — there is no sshs3 cloud.

  • Encrypted client-side with AES-256-GCM before upload
  • Unlock with a master password or a smartcard / hardware token
  • Auto-sync pushes changes and pulls remote updates in the background
  • Per-record merge, so two machines edited independently don't overwrite each other
  • Keeps a managed block in ~/.ssh/config in step, so plain ssh <alias> works everywhere

Dotfiles sync

Keep .bashrc, .vimrc and friends the same on every server you log in to.

  • Define a pool of files and assign it to specific SSH profiles
  • On connect, a short background SFTP check compares the pool against the server
  • Review the diff in a non-blocking banner, or let it update silently per profile policy
  • Uses existing sessions, so hardware-key logins need no extra touches
security

Your keys stay yours.

Hardware-first authentication, encrypted-at-rest secrets, and sync that never touches a server we run.

  • Smartcards & FIDO2 — SITHS, Net iD, OpenSC, YubiKey PIV, p11-kit and resident ed25519-sk keys
  • PIN caching modes — always prompt, once per terminal connection, or once for the whole app session
  • OS keyring — passwords and keys encrypted via libsecret, DPAPI or Keychain
  • Zero-knowledge sync — profiles encrypted with AES-256-GCM client-side, stored in your S3 bucket or SFTP server
  • Host key verification with an interactive trust dialog
# unlock your card once, connect everywhere
❯ ssh prod-bastion
⚿  Enter PIN for SITHS card
☝  Touch your security key to authenticate

admin@prod-bastion in /srv/app
❯ kubectl get pods -n payments
NAME              READY   STATUS
api-7c9d4f6b8c    1/1     Running
faq

Frequently asked questions

Common questions about SSH, S3 object storage, security keys, and cross-platform workflows.

Can I transfer files directly between SSH / SFTP and S3?

Yes. sshs3 features a dual-pane file manager where you can open an SSH/SFTP connection on one side and an S3 bucket (or MinIO, Ceph, Cloudflare R2) on the other. You can drag and drop, queue transfers, or synchronize folders directly between your remote servers and object storage without intermediary local downloads. Read more in the file manager guide and S3 storage guide.

Which S3 object storage providers are supported?

sshs3 connects to any standard S3-compatible API. This includes Amazon AWS S3 (with AWS SSO device-flow login for short-lived credentials), MinIO, Ceph, Cloudflare R2, Wasabi, Backblaze B2, and NetApp StorageGRID. You can edit bucket policies, manage CORS, tags, and object versioning directly in the UI.

How does sshs3 handle OpenSSH configuration and security?

sshs3 executes your system's native OpenSSH client rather than a third-party reimplementation. This means your existing ~/.ssh/config host aliases, ProxyJump bastions, and ssh-agent just work. Furthermore, it includes first-class support for hardware security keys (FIDO2 / YubiKey) and PKCS#11 smartcards with in-app PIN entry. See the security documentation.

Is sshs3 completely free and open source?

Yes, sshs3 is released under the permissive MIT license. The source code and builds are hosted on GitHub with native packages for Linux (AppImage, .deb, .rpm) and Windows (installer & portable).

download

Free and open source.

Grab the latest build for your platform. Every release is published on GitHub.

sshs3 is under active early-stage development — expect rough edges. Found one? Open an issue.

App theme