Remote commands through profiles — not a free shell.
SSH connections store host, port, user and secret-referenced keys. Workflows run allowlisted command profiles. Free-form ssh.execute-command is disabled; use ssh.execute-profile.
What SSH is allowed to do
Catalog-gated `ssh` connector. Admin/manager (and super-admin) manage connections. Host-key trust is an explicit UI step after fingerprint check.
SSH connections
Create host, port and user in admin. Keys and passwords go to secret-service. Test connectivity before a workflow uses the connection.
Command profiles
ssh.execute-profile runs a catalog profile with validated arguments — not an arbitrary remote command from the model.
Tunnels
ssh.tunnel opens an allowlisted tunnel destination. Sessions are tracked and purged; it is not an open-ended jump host.
Host keys
Trust the host key in admin after you verify the fingerprint. A mismatch is not something to override from a chat payload.
Behind VPN when needed
If the host is only reachable over VPN, bring the gateway up first — then SSH. Timeout often means the path, not the key.
Ready to move beyond the chatbot?
Build AI that understands your business, follows your processes, finishes the work — and keeps token spend under your control.