> ## Documentation Index
> Fetch the complete documentation index at: https://docs.stackshift.cloud/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect with Edge SSH

> Enable a per-VPS SSH port on the StackShift edge and connect with your existing guest login and private key.

## Goal

Reach a VPS over a standard SSH client when direct IPv6 is unavailable or inconvenient.

## Prerequisites

* A running Compute VPS in an account with the Publishing tab enabled.
* An SSH service listening on the selected guest port and a private key already authorized in the VPS.

## Workflow

<Steps>
  <Step>
    Open Compute → your VPS → Publishing → Edge SSH.
  </Step>

  <Step>
    Enter the guest SSH port (normally 22). Optionally add allowed client IP ranges in CIDR notation.
  </Step>

  <Step>
    Click Enable edge SSH. Copy the hostname, assigned port, and username displayed by StackShift.
  </Step>

  <Step>
    Wait for Status: configured, then connect with your normal SSH client and private key.
  </Step>
</Steps>

## Fill in Edge SSH

* Guest SSH port: enter the port where sshd listens inside the VPS. Leave the default 22 unless you changed the guest SSH configuration.
* Allowed client IP ranges: leave empty to connect from any network. To restrict access to one public IPv4 address, enter that address with /32; for one IPv6 address, use /128. Separate multiple CIDRs with commas or spaces.
* Click Enable edge SSH. StackShift then displays the external hostname, assigned port, and guest username. The external port is different from the Guest SSH port.

## Connect from your computer

Replace the three quoted values below with the port and username shown in Publishing and the path to your existing private key. Do not type angle brackets around a port or username in a shell command.

```bash theme={null}
EDGE_PORT="PORT_SHOWN_IN_PUBLISHING"
VPS_USER="USER_SHOWN_IN_PUBLISHING"
SSH_KEY="$HOME/.ssh/YOUR_PRIVATE_KEY"
ssh -i "$SSH_KEY" -p "$EDGE_PORT" "$VPS_USER@ssh.compute.stackshift.cloud"
```

## Use the endpoint in a remote server manager

In Coolify, Dokploy, or another tool that adds a remote server over SSH, set the host to ssh.compute.stackshift.cloud, the SSH port to your assigned external port, and the user to the one shown in Publishing. Give that tool a private key whose public key is authorized in the guest. The VPS remains a normal full-root server.

## Status and disabling

* Pending: StackShift is applying the endpoint. Wait for Configured before connecting.
* Configured: the edge route has been applied. Your normal guest SSH login and key checks still apply.
* Offline: the VPS is not eligible to receive the route while stopped or suspended. Start or restore the VPS, then wait for the route to return.
* Disable edge SSH removes the edge listener. It does not delete the VPS, turn off guest sshd, remove your keys, or change direct SSH access.
* To change the guest SSH port or allowed client ranges in the dashboard, disable Edge SSH and enable it again with the new values. The assigned external port remains reserved for this VPS.

## Expected result

<Check>
  Your SSH client reaches the same guest SSH server and authenticates with the same key you use for direct access.
</Check>

## Common failures

<Warning>
  * Timeout before an SSH banner: confirm the displayed edge port is configured, your client network can reach the edge, any client CIDR restriction includes your current public IP, and the guest SSH daemon is listening on the configured guest port.
  * Permission denied (publickey): the network path reached the guest SSH service. Check the selected username, private key, and guest authorized\_keys rather than changing the edge route.
  * A changed host-key warning deserves investigation. The edge forwards the guest SSH session, so compare the fingerprint with a trusted guest fingerprint before accepting it.
</Warning>

## Related guides

<CardGroup cols={2}>
  <Card title="Compute edge network" href="/compute/edge-network-overview">
    Reach a full-root VPS through opt-in HTTPS publishing or Edge SSH without assigning the guest a dedicated public IPv4.
  </Card>

  <Card title="Use a VPS with Coolify or Dokploy" href="/compute/coolify-and-dokploy">
    Use Edge SSH to manage the VPS remotely and Web publishing to expose an app already running behind Coolify or Dokploy.
  </Card>

  <Card title="Troubleshoot Compute publishing" href="/compute/troubleshooting">
    Use the Publishing status and connection symptom to check the right guest port, SSH key, DNS record, or client IP restriction.
  </Card>
</CardGroup>
