# Terminal and SSH

> Source: https://www.allsweb.com/sixpanel/docs/terminal-and-ssh
> Markdown for agents: https://www.allsweb.com/sixpanel/docs/terminal-and-ssh.md
> Publisher: AllsWeb (www.allsweb.com)

Part of: SixPanel documentation

**What this page is for:** run commands on your server from the panel itself — as
root, or as one project's own account — and decide who may sign in over SSH: a
project's or website's own account with a key, and SSH for the whole server on or off.

Open **Server** and the **Terminal** tab for a shell as root, the terminals open right
now, and SSH for the whole server. A 6amMart project's terminal is under **Advanced →
Terminal**; a website's is its **Terminal** page. Both carry that project's **SSH
access** below the terminal.

**You need**

- The owner's login. A temporary login and the read-only demo cannot open a terminal
  or see or change SSH access, and neither can Tia, the panel's assistant.
- To confirm it is you — the 6-digit code from your authenticator app, or your panel
  password when two-factor login is off — to open a root terminal, to add an SSH key,
  to turn on SSH access that already has keys, and to turn SSH back on for the server.
  You are asked once; for the next 5 minutes the panel does not ask again. **Security
  → Confirming it is you** sets how long (every time, 2, 5 or 15 minutes) — see
  **[Security](https://www.allsweb.com/sixpanel/docs/security)**.

**The rule that does not move:** what you type is never recorded. The **Activity**
page shows that a terminal opened — who, as which account, from which address — and
when and why it closed. Nothing in between.

---

## Open a terminal

Press **Open terminal**. A dark terminal opens on the page, sized to it; drag the
window and it follows. Everything works as in any terminal: colours, full-screen
programs such as `top`, `nano` or `vim`, and Tab completion. Select text to copy it;
paste with **Ctrl+V** (**⌘V** on a Mac). **Ctrl+C** stops the running command, as it
always does.

The line under the title says which account the shell runs as and in which folder:

- **Server → Terminal** — root, in `/root`. Root can change anything on the server,
  which is why the panel asks you to confirm it is you first.
- **A 6amMart project** — the project's own account (`six-<name>`), in its app folder
  (`/var/www/<name>/admin`). Files you create belong to the project, exactly as after
  a deploy, so `php artisan`, `composer` and `git` behave as the panel's own deploys do.
- **A website** — the website's own account (`site-<name>`), in its folder, with the
  website's own PHP and Node.js versions first on the path.

The project and website accounts keep their shell history and tool caches in their
own home under `/var/cache/sixpanel`, never in the app folder — so a terminal never
leaves files behind that would stop the next deploy.

## When it closes

A terminal closes:

- after **15 minutes without typing** — a minute before, the page warns you, and any
  key keeps it open. Output does not count: a log scrolling in a forgotten tab is not
  somebody at the keyboard;
- when you **leave the page** or close the tab;
- when you **sign out**, or your sign-in ends;
- when the **panel restarts** — an update restarts it — and the terminal says so;
- when its **website is moved to another server** — the move closes the terminals
  open on it as it pauses the website, and says so;
- when you type `exit`.

Closing works like a dropped SSH connection: the running command gets the hang-up
signal and stops. To keep something running after you close the terminal, start it
the way you would over SSH — `nohup <command> &`, or inside `tmux` or `screen`.
The page says why each terminal closed, and **Open again** starts a new one.

## Open terminals

At most **three** terminals can be open on the server at once. **Server → Terminal**
lists them — where each one is, the account, the address it was opened from, when,
and how long it has been idle. **Close** ends that terminal's shell at once — the way
to free a place when a terminal was left open in another browser.

## SSH access for a project or website

**Off** until you turn it on. On, it lets that project's own account sign in over SSH
**with a key, never a password** — for deploying from your computer with `rsync` or
`scp`, or an editor that saves over SFTP. Turning it on for one project gives nothing
to any other project, to root, or to your server's own login user.

**Off means off.** While access is off, the account cannot sign in over SSH at all —
not with a password, and not with a key file placed inside the project's own folder.
The only keys that ever count are the ones listed on this card, which SixPanel keeps
outside the app folder where the app cannot change them.

### Add a key

Paste the line from your public key file into **Add a public key** and press **Add
key** — for example the contents of `~/.ssh/id_ed25519.pub`. It starts with
`ssh-ed25519`, `ssh-rsa` or `ecdsa-sha2-…`. No key yet? Make one on your own computer:

```bash
ssh-keygen -t ed25519
cat ~/.ssh/id_ed25519.pub
```

Ed25519 keys are the best choice. RSA keys must be 2048 bits or more, and DSA keys are
refused (OpenSSH no longer accepts them). If you paste a **private** key by mistake,
the panel refuses it and says so — never paste a private key anywhere. You can paste
several keys at once, one per line; up to 20 per account.

Each key is listed with its type, its fingerprint and the note at the end of the line
(often your name and computer). **Remove** takes a key off at once.

### Sign in

With access on and at least one key, the card shows the exact line to use, with
**Copy**:

```bash
ssh six-myshop@203.0.113.10 -p 22
```

It uses the server's own address, not the panel's domain: a domain behind Cloudflare
carries web traffic only, never SSH.

You land in the app folder, as the project's account. Port, agent and X11 forwarding
are off for these accounts, so a tool that tunnels through SSH — VS Code's Remote-SSH,
for one — cannot connect this way; SFTP, `scp` and `rsync` work.

### Turn SSH access off

**Turn SSH access off** stops every key at once, takes the account's login shell away
again and closes the account to SSH altogether. The keys stay on the list, so turning
access back on brings them back.

### While a website is being moved

A website that is being moved to another server
(**[Move projects to another server](https://www.allsweb.com/sixpanel/docs/move-between-servers)**) takes no SSH
sign-in and no terminal from the moment the move pauses it. Its card says **Closed
for the move**, its keys stop working, and a session that was open is ended — the
move's log names what it ended. A copy is only worth comparing if nothing can write
to it.

The keys stay on the list. Access opens again by itself, exactly as it was, when a
move ends without moving the website. On the copy a move leaves behind it stays
closed for as long as that copy is parked, and opens again when you press **Start
it here again** on its **Overview**. Turning access off and removing a key work at
any time.

**SSH access is not sent to the other server.** Who may sign in there is your
decision there, behind your password: turn it on again on the website's **Terminal**
page on that server, and add the keys you want. The same holds for a 6amMart
project that is moved.

## An agent on the server, inside one project

*In the panel this is the card **Let an agent work on the server itself**, on the
project's **AI agent** page.*

You can hand **one** project to an AI agent that works in a shell — Claude Code, Codex
or any other — without handing it the server. The agent works as the project's own
account: it reaches that project's code, database, deploys and logs, and nothing else
on the server. A staging site is a project of its own, with its own account and its own
**AI agent** page.

There are two ways to give an agent one project, both on that page:

- **From your own computer** — the first card, **Connect your AI agent to …**. Nothing
  runs on the server; see
  **[Connect your own agent](https://www.allsweb.com/sixpanel/docs/ai-assistant#connect-your-own-agent)**.
- **On the server itself** — this section. The agent runs in a shell on the server and
  edits the files in place.

Open the project's **AI agent** page and press **Turn it on** on the card **Let an
agent work on the server itself**. The panel asks you to confirm it is you, then
prepares three things for that account:

- **A shell that is ready.** The project's own PHP and Node.js come first, `npm i -g`
  works without root (what it installs goes into the account's own home), and the shell
  opens in the code.
- **A guide the agent reads by itself.** The panel writes it into the account's home as
  `~/.claude/CLAUDE.md`, `~/.codex/AGENTS.md` and `~/AGENTS.md`, and rewrites it when
  the project changes. It says what the project is, its folders and addresses, its PHP
  and Node.js versions, its database and where its credentials are, whether this is
  **production** or a **staging site** (and of what, on which branch), the rules, and
  the commands below. **Read the guide the agent is given** on the card shows the text.
  Claude Code is also told to refuse the commands that wipe a database
  (`migrate:fresh`, `db:wipe` and the like).
- **The `sixpanel` command, for this project only.** See the list below.

The card then shows three steps:

1. **Sign in as the account** — in the project's **Terminal**, or over SSH with the line
   the card shows once **SSH access** is on and has your key (the card links to the
   Terminal page, where SSH access is).
2. **Start your agent there** — for Claude Code:

   ```bash
   claude
   ```

   Not installed in that account yet? `npm install -g @anthropic-ai/claude-code` first.
3. **It reads its guide by itself**, and has the `sixpanel` command for this project.
   There is nothing to add or connect: no `claude mcp add` line is needed on the server.

The `sixpanel` command also answers a session of **[AI Coding](https://www.allsweb.com/sixpanel/docs/ai-coding)** that
the panel itself is running for that project — with this switch on or off: you started
that session in the panel.

### What the account may run

```
sixpanel status                  what this project is, whether it is live, recent errors
sixpanel logs [what] [-n N]      recent log lines (sixpanel logs help names them)
sixpanel deploy                  put the repository's code live: pull, build, migrations
sixpanel restart [what]          restart a service of this project
sixpanel jobs                    the panel's recent jobs for this project
sixpanel job <id>                one job: its steps, its error, its last lines
sixpanel changes                 a staging site on a branch: what changed on the server
sixpanel commit -m "<message>"   a staging site on a branch: commit it and push it
sixpanel sync                    a staging site on a branch: bring production's commits in
sixpanel mcp                     the same tools as an MCP server, for the agent itself
```

Every one of them acts on **this project only** — the account cannot name another —
and every change one of them makes is on the **Activity** page, marked with the
account's name (a command that only reads — `status`, `logs`, `jobs`, `changes` — leaves
no line). The account
holds no password for your repository: `deploy`, `commit` and `sync` have the panel do
that part. Any other `sixpanel` command answers that it is for the server's
administrator.

**A change that cannot be taken back still waits for you.** Promoting a staging site to
production, deleting, restoring a backup: the agent's command waits, the panel shows
you an approval card under **AI**, and nothing happens until you approve it.

**The `sixpanel` command is part of SixPanel Pro**, like
**[Connect your own agent](https://www.allsweb.com/sixpanel/docs/ai-assistant#connect-your-own-agent)** — it is the same
thing for one project. The shell, the guide and SSH access are part of every plan.

### What it cannot do

- Reach another project, the server's settings, or root. There is no `sudo`.
- Be used by the project's own website. The website runs as the same account, so the
  panel looks at where a call comes from: it answers a person or an agent in an SSH
  session or in the panel's Terminal, and refuses the web app, its workers and its
  scheduled tasks. A fault in the website is not a way into the panel.
- Go on after you close the way in. Turning SSH access off stops the command for
  sessions that are still open; a project that is being moved answers nothing until
  the move ends.

### In a 6amMart project

The agent's own files — `CLAUDE.md`, `AGENTS.md`, `.claude/`, `.codex/`, `.cursor/`,
`.mcp.json` — are kept out of git inside the project's code, so a deploy does not stop
over them and does not delete them. Any other file the agent changes and does not
commit still stops the next deploy, as it would for you: that is what
`sixpanel commit` on a staging site is for.

The guide tells the agent the rules of a 6amMart project: never `artisan config:cache`
or `optimize` by hand (the panel decides that per shop), `sixpanel restart php` after a
PHP file changes, and no destructive database command on production.

### Turn it off

**Turn it off** on the card stops the `sixpanel` command for that account at once and
takes the guide and the shell set-up out of its home. Files the agent made in the code
stay. In a 6amMart project the account's home folder counts as a build cache again once
the switch is off, so the build-cache clean-up on the **Disk** page (and a deploy, when
the caches are over their limit) may empty it — the agent's sign-in and the tools
installed with `npm i -g` go with it.
SSH access is its own switch and is not changed.

Like SSH access, this is never sent to another server by a move: on the server a
project was moved to, you prepare its account again there.

## Turn SSH off for the whole server

**Server → Terminal** shows whether SSH is on and on which port. **Turn SSH off**
stops the SSH server: nobody — you included — can sign in over SSH until it is turned
back on. SSH sessions open at that moment are not cut off.

With SSH off, the panel's own **Terminal** and your hosting provider's **console** (the
"Console" or "Recovery" button in their dashboard) are the way in. That is why the
panel only lets you turn SSH off once it answers on **its own domain with a
certificate** (**Security → Access → Panel address**): a panel reached only through a bare IP
address could be one address change away from no way in at all.

**Turn SSH on** starts it again exactly as it was before (on Ubuntu the socket that
starts SSH on the first connection, on Debian the SSH service).

## What a temporary login can do

Nothing here. A temporary login cannot open a terminal, cannot see the list of open
terminals, and cannot see or change SSH access or SSH itself — the panel refuses each
of those and says why.

## How to check it worked

- **Terminal** — after **Open terminal**, run `whoami` and `pwd`: they print the
  account and the folder the line under the title names.
- **SSH access** — from your own computer, the line the card shows signs you in
  without asking for a password. Then `whoami` prints the project's account.
- **SSH off** — `ssh` to the server from your computer is refused (connection refused
  or timed out), and the **Terminal** tab still opens a shell.
- **Activity** shows a line for each terminal opened and closed, and for each SSH
  change.
- **An agent on the server** — signed in as the account, `sixpanel status` prints the project,
  and `cat ~/AGENTS.md` prints the guide. The same command typed by any other user
  says it must run as root.

## If it went wrong

- **"A terminal cannot open on this server yet: python3 is not installed".** The
  terminal runs its shell through `python3`. Install it from your provider's console
  or over SSH: `sudo apt-get install -y python3-minimal`. The next panel update
  installs it by itself too.
- **The terminal says the connection was lost straight after opening.** Something
  between your browser and the panel is blocking WebSockets — a company proxy or a
  firewall in front of the server. Cloudflare passes them through. Try from another
  network.
- **"3 terminals are already open".** Close one under **Open terminals** on
  **Server → Terminal**, or wait for an idle one to close.
- **The card says "Closed for the move", or "… is being moved to another server
  right now".** The website is being moved, or this is the copy that was moved
  away. See **While a website is being moved** above: wait for the move, or press
  **Start it here again** on the website's **Overview** to use this copy.
- **The card "Let an agent work on the server itself" says the panel is not answering
  the `sixpanel` command in this account.** The switch is on, but the small helper the panel runs to answer that
  command is not running. The panel starts it with itself and starts it again by itself
  within half a minute when it stops; if the line stays, restart the panel — `sudo
  sixpanel panel restart` over SSH — and open the card again. The helper needs `python3`,
  as the terminal does (see the first line of this list). Right after an update to 1.5.3
  the line can show until the panel has restarted: the restart is what finishes it.
- **`sixpanel` says "sixpanel is not switched on for …".** Press **Turn it on** on the
  card **Let an agent work on the server itself**, on the project's **AI agent** page.
- **`sixpanel` says it answers "only from an SSH session or the panel's Terminal".**
  The command was started by something other than a sign-in — a scheduled task, the
  website itself, or `su` from another user. Run it in an SSH session as the account,
  or in the panel's Terminal.
- **`sixpanel` says SSH access is off.** A session that was open when SSH access was
  turned off is no longer answered. Turn SSH access on again, or use the Terminal.
- **The card says something was "Not written yet".** The line under the title says
  why — most often a link stands where a folder should be in the account's home
  (`~/.claude`, for one). The panel never writes through a link there. Remove it and
  switch the card off and on again.
- **The key is refused when you sign in.** Check the server's SSH is on, the card
  says access is **On**, and the key on your computer is the one listed (compare
  `ssh-keygen -lf ~/.ssh/id_ed25519.pub` with the fingerprint on the card). If your
  own SSH settings name the account in a `Match` block of their own, or no longer
  read `/etc/ssh/sshd_config.d/`, the panel refuses to turn access on and says which.
- **"The SSH server refused the new settings".** The panel checks every change with
  `sshd -t` before it counts, and put the previous settings back. The message quotes
  what SSH did not accept — usually a hand edit elsewhere in `/etc/ssh/` — fix that
  first.
- **Locked out with SSH off.** Open the panel and use **Server → Terminal**, or your
  provider's console, and turn SSH on again (`sudo systemctl enable --now ssh` on
  Debian, `sudo systemctl enable --now ssh.socket` on Ubuntu).
