Omahub
← All plugins
K

Fleet SSH

by kszx11

Open a guarded tmux session that broadcasts input to a named group of SSH hosts.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
f374903
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
f374903
Reviewed
1 month ago

The plugin is a bar widget that manages tmux sessions with SSH connections to user-configured hosts. It performs SSH preflight checks and launches terminals, but all actions are user-initiated and limited to the configured aliases. No malicious behavior, credential handling, or arbitrary code execution was found.

How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/kszx11/omarchy-fleet-ssh-plugin --enable
Productivity #quickshell #security

Fleet SSH for Omarchy

Fleet SSH opens one SSH connection per host in a dedicated tmux session. It is for sending the same reviewed input to several servers while keeping each server's output visible.

Fleet SSH broadcasting df -h / to two servers

Safety model

  • Fleet SSH does not create, read, copy, upload, or store SSH private keys, passwords, passphrases, agent sockets, or host keys.
  • Host aliases are resolved by your existing OpenSSH configuration. The launcher forces ForwardAgent no and never weakens host-key verification.
  • It preflights every target with non-interactive OpenSSH authentication before creating a session. If one target is unavailable, it creates no session.
  • Commands typed into a Fleet session go to every server in its group. A failed SSH connection exits its pane instead of dropping into a local shell.

Fleet SSH cannot make divergent interactive programs safe. Do not broadcast passwords, MFA codes, editor input, or commands whose effects you have not reviewed for every target.

Requirements

  • Omarchy 4.0 or later with Quickshell plugin support
  • ssh, tmux, and xdg-terminal-exec
  • SSH aliases configured in ~/.ssh/config
  • Key or agent authentication that succeeds without a password prompt during the connection preflight

Example OpenSSH alias:

Host web-01
  HostName 203.0.113.10
  User deploy
  IdentityFile ~/.ssh/id_ed25519_ops
  IdentitiesOnly yes
  ForwardAgent no

SSH key setup

Fleet SSH requires every host in a group to accept key or agent authentication without an interactive password prompt. Your private key always stays on your local computer; only its public-key counterpart is installed on each server.

Create a dedicated key if you do not already have one:

ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519_fleet -C "fleet-ssh"

Install the public key on each server, once per server. Substitute your remote account and host address:

ssh-copy-id -i ~/.ssh/id_ed25519_fleet.pub user@server.example.com

Load the key into your running SSH agent for the current login session:

ssh-add ~/.ssh/id_ed25519_fleet

Then configure each host as an alias in ~/.ssh/config and test it before adding it to a Fleet group:

ssh web-01

If ssh-add reports that it cannot connect to an authentication agent, start one first with eval "$(ssh-agent -s)", then run ssh-add again. Do not put a password, passphrase, private key, or MFA code in a Fleet SSH session.

Install

omarchy plugin add https://github.com/kszx11/omarchy-fleet-ssh-plugin.git --enable

Create a private group configuration. This command refuses to overwrite an existing file:

~/.config/omarchy/plugins/io.github.kszx11.fleet-ssh/bin/fleet-ssh init

Edit ~/.config/fleet-ssh/groups.conf, replacing the commented examples with your SSH aliases. Then check the group before starting it:

~/.config/omarchy/plugins/io.github.kszx11.fleet-ssh/bin/fleet-ssh check default
~/.config/omarchy/plugins/io.github.kszx11.fleet-ssh/bin/fleet-ssh start default

Left-click the Fleet SSH bar icon to hide the currently open Fleet. When that Fleet is not open, left-click shows a picker listing every group in groups.conf; selecting one opens or resumes that Fleet. Right-click ends the Fleet most recently selected in the picker.

Click the Fleet SSH bar icon to open or resume its group. Click it again to hide the visible terminal while keeping its SSH connections alive. A later click resumes the same session without reconnecting. To end every connection, right-click the Fleet SSH icon, then select End Fleet in the Omarchy confirmation popup.

From inside a Fleet terminal, press the tmux prefix (Omarchy uses Ctrl+Space), then press X, and confirm with y to end the Fleet and disconnect every server.

Inside a Fleet SSH session, every command you type goes to every server in the selected group. The tmux status bar shows FLEET ACTIVE · N SERVERS. Never type passwords, MFA codes, or other secrets into a Fleet session.

Development

./tests/run
omarchy plugin validate .

Removal

omarchy plugin remove io.github.kszx11.fleet-ssh

Removal does not touch ~/.ssh, your keys, tmux sessions, or ~/.config/fleet-ssh/groups.conf.

License

MIT. See LICENSE.