접속 대상마다 다른 개인키를 써야 할 때 ~/.ssh/config 에 호스트별로 키를 지정한다.
vi ~/.ssh/config
chmod 600 ~/.ssh/config
Host git-internal
HostName git.example.com
Port <SSH_PORT>
User git
IdentityFile ~/.ssh/id_rsa_git
IdentitiesOnly yes
Host prod-*
User deploy
IdentityFile ~/.ssh/id_rsa_prod
IdentitiesOnly yes
Host *
ServerAliveInterval 60
Host 는 위에서부터 먼저 맞는 항목이 이긴다 — 구체적인 패턴을 위에, Host * 를 맨 아래에 둔다.
IdentitiesOnly yes 가 없으면 ssh-agent 에 올라 있는 키를 먼저 전부 시도한다. 서버의 MaxAuthTries (기본 6) 를 넘기면 정작 맞는 키를 내밀기 전에 끊긴다.
ssh -i ~/.ssh/id_rsa_prod -o IdentitiesOnly=yes deploy@10.0.0.10
ssh -v git-internal 2>&1 | grep -i 'offering\|identity file'
어느 키를 내밀었는지 -v 로 확인한다.