A read-only, keyboard-first TUI for browsing OpenSSH configuration, inspecting effective host options, and starting SSH sessions.
The demo is generated reproducibly with demo/record.py.
- Foldable, alphabetically sorted tree with nested groups and host details
- Native
Includesupport for split configurations such as~/.ssh/config.d/ - Metadata comments for groups, descriptions, hidden hosts, and default expansion
- Effective inherited options resolved during the in-process configuration scan
- Compact fuzzy search across aliases, hostnames, usernames, descriptions, and group paths
- On-demand TCP reachability indicators for hosts
- Embedded SSH terminal that keeps the host tree visible
- Keyboard and mouse navigation
- Read-only operation: SSH configuration files are never modified
- OpenSSH client (
ssh) inPATH - Rust stable when building from source
Prebuilt x86_64 binaries for Linux and Windows are attached to tagged GitHub
releases. Extract the Linux archive and place ssh-tui-rs in a directory
included in PATH. On Windows, download the executable, rename it to
ssh-tui-rs.exe, and place it in a directory included in PATH.
To build and install from source with Cargo:
cargo install --locked --path .Cargo installs binaries to ~/.cargo/bin on Linux and
%USERPROFILE%\.cargo\bin on Windows by default. Make sure that directory is
included in PATH.
By default, ssh-tui-rs reads the current user's OpenSSH configuration:
~/.ssh/config on Linux or %USERPROFILE%\.ssh\config on Windows.
ssh-tui-rsCommand-line options:
Keyboard-first SSH config browser
Usage: ssh-tui-rs [OPTIONS]
Options:
-c, --config <PATH> Read OpenSSH configuration from PATH
--no-network-check Disable host reachability checks
--embedded-ssh Run SSH sessions inside the details pane
-h, --help Print help
-V, --version Print version
| Key | Action |
|---|---|
j, k, Up, Down |
Move through the tree |
Space |
Fold/unfold the selected group |
h, l, Left, Right |
Fold/unfold groups |
Enter |
Connect to a host or toggle a group |
Alt+Enter |
Open the selected host in a new inline terminal tab |
/ |
Enter search mode |
r |
Reload SSH config from disk |
F5 |
Switch focus between the tree and the active embedded session |
Alt+Left, Alt+h |
Switch to the previous tab (when multiple tabs are open) |
Alt+Right, Alt+l |
Switch to the next tab (when multiple tabs are open) |
x |
Close the active embedded session tab |
q |
Quit |
| Key | Action |
|---|---|
Up, Down |
Move through search results |
Enter |
Reveal result in tree |
Alt+Enter |
Reveal result in tree and open it in the inline terminal |
Esc |
Leave search mode |
Mouse scrolling and selection are supported. Click the search box to start typing, click groups to toggle them, and double-click hosts to connect.
Use Alt+Enter for an inline session, or --embedded-ssh to make inline
sessions the default. Each activation opens a new tab in the details pane while
keeping the tree visible. Switch between tabs with Alt+Left/Alt+Right (or
Alt+h/Alt+l). Drag over text to select and copy it on mouse release.
Reachability checks run when groups are unfolded. Ungrouped hosts and hosts in
groups marked with @expanded are checked at startup. The probe is a direct
TCP connection to the effective HostName and Port; proxy-only hosts may
therefore appear unreachable.
Linux and Windows release artifacts are built when a v* or release-* tag
is pushed. Their filenames include the tag, such as
ssh-tui-rs-v0.4.0-linux-x86_64-glibc.tar.gz. The linux-x86_64-glibc
artifact uses the standard GNU C library; the linux-x86_64-musl artifact is
statically linked and does not depend on the host's glibc version. Both Linux
archives contain an executable named ssh-tui-rs. Windows releases are
provided as an x86_64 .exe.
- Conditional options from
Matchblocks are not included in the TUI's displayed effective values or reachability targets. OpenSSH still applies them when connecting. OpenSSH provides no bulk configuration query, so exact resolution would require a separatessh -Gevaluation for every host and could executeMatch execcommands many times.
Use OpenSSH's native Include directive in the main configuration:
# ~/.ssh/config
Include ~/.ssh/config.d/*.conf
Host arch
HostName localhost
User m3nixEach included file starts without an active group. This makes one file per
environment an easy way to organize the tree. Hosts without @group, such as
arch above, remain at the root.
# ~/.ssh/config.d/work.conf
# @group Work
# @description Company systems
# @expanded
Host work-*
User bob
IdentityFile ~/.ssh/work_ed25519
# @description SSH jump host
Host work-bastion
HostName bastion.example.com
# @group Work/Production
# @description Customer-facing systems
Host work-web
HostName web.internal
ProxyJump work-bastion
# @description Primary database
Host work-db
HostName db.internal
ProxyJump work-bastion# ~/.ssh/config.d/homelab.conf
# @group Personal/Lab
# @description Home lab systems
Host lab-controller
HostName 192.168.1.50
User m3nix
# @hidden
Host lab-helper
HostName helper.internalSupported metadata:
| Comment | Effect |
|---|---|
# @group Work/Production |
Assign following hosts to a nested group |
# @description text |
Describe the active group or next host |
# @expanded |
Open the active group on startup |
# @hidden |
Hide the next Host block from the TUI |
The first @description after @group describes that group. Later
descriptions apply to the following host. A group remains active until another
@group appears in the same physical file. Wildcard Host blocks are hidden
from the tree but their options are inherited by matching concrete hosts.
This project was inspired by sshclick, created by karlot. Thank you for the original idea.
The code in this project was written by AI and may contain mistakes. Review and test it before relying on it in sensitive or production environments.
This project is free and open-source software licensed under the MIT License.
