Agent skill

Ssh Connection Management

by GoogleCloudPlatform in GoogleCloudPlatform/gcsfuse

Guides on establishing persistent master SSH multiplexing sockets at ~/.ssh/sockets/<TARGETNAME.sock using ssh -f -N -M -S, testing connection liveness, gracefully terminating via -O exit, removing…

Apache-2.0Auto-check: warnings

Install Ssh Connection Management

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add GoogleCloudPlatform/gcsfuse --skill ssh-connection-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install GoogleCloudPlatform/gcsfuse ssh-connection-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/GoogleCloudPlatform/gcsfuse.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ssh-connection-management .claude/skills/ssh-connection-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ssh-connection-management
GitHub stars
2.3k
Token cost
~1.6k tokens
SKILL.md length
592 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides on establishing persistent master SSH multiplexing sockets at ~/.ssh/sockets/<TARGETNAME.sock using ssh -f -N -M -S, testing connection liveness, gracefully terminating via -O exit, removing…

  • Works in 5 steps: Create Socket Cache Directory → Clean Up Lingering Sessions and Stale… → Establish Master SSH Connection → …
  • SKILL.md covers Prerequisites & Trigger…, Input/Output Contract, Step-by-Step Procedure and Failure Modes & Edge Cases, plus 1 more section
  • Calls ssh and gcloud

What it does

Ssh Connection Management is an agent skill from GoogleCloudPlatform/gcsfuse. Guides on establishing persistent master SSH multiplexing sockets at ~/.ssh/sockets/<TARGETNAME.sock using ssh -f -N -M -S, testing connection liveness, gracefully terminating via -O exit, removing stale control sockets, and recreating sockets when remote user permissions or groups change.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Google Cloud. The repository describes itself as: A user-space file system for interacting with Google Cloud Storage. The licence is Apache-2.0.

Example prompts

  • “Use the ssh-connection-management skill to guide on establishing persistent master SSH multiplexing sockets at ~/.ssh/sockets/<TARGETNAME.sock using…”
  • “/ssh-connection-management”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Create Socket Cache Directory
  2. Clean Up Lingering Sessions and Stale Sockets
  3. Establish Master SSH Connection
  4. Verify Connection Liveness
  5. Refreshing / Recreating Sockets

What it can do on your machine

Read from SKILL.md and the folder at commit fac0483. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • ssh
    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use ssh and gcloud, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ssh Connection Management loads about 1.6k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 592 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:3
    tent master SSH multiplexing sockets at ~/.ssh/sockets/<TARGET_NAME>.sock using ssh -f -N -M -S, testing connection live
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:13
    Keys**: Local SSH key pair present at `~/.ssh/google_compute_engine` (or standard `~/.ssh/id_rsa`).
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:32
    - **Socket Cache Directory**: `~/.ssh/sockets/`.
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:35
    File**: Unix domain socket located at `~/.ssh/sockets/<TARGET_NAME>.sock`.
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:44
    mkdir -p ~/.ssh/sockets
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:51
    ssh -O exit -S ~/.ssh/sockets/<TARGET_NAME>.sock <SSH_USER>@nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com 2>
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:58
    ssh -f -N -M -S ~/.ssh/sockets/<TARGET_NAME>.sock -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -i ~/.ssh/
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:65
    - `-S ~/.ssh/sockets/<TARGET_NAME>.sock`: Path to the control socket.
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:72
    ssh -S ~/.ssh/sockets/<TARGET_NAME>.sock -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -i ~/.ssh/google_co
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:80
    ssh -O exit -S ~/.ssh/sockets/<TARGET_NAME>.sock <SSH_USER>@nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from GoogleCloudPlatform/gcsfuse at commit fac0483, republished under its Apache-2.0 licence (© GoogleCloudPlatform). 592 words, ~1,631 tokens.

Download SKILL.mdSave it as .claude/skills/ssh-connection-management/SKILL.md (or your agent's skills folder).
name
ssh-connection-management
description
Guides on establishing persistent master SSH multiplexing sockets at ~/.ssh/sockets/<TARGET_NAME>.sock using ssh -f -N -M -S, testing connection liveness, gracefully terminating via -O exit, removing stale control sockets, and recreating sockets when remote user permissions or groups change.

SSH Connection Management

This skill guides you through establishing, managing, and troubleshooting persistent SSH socket multiplexing connections to target GCE VMs or remote VMs. Socket multiplexing speeds up command execution and maintains session resilience across automated workflow steps such as remote testing, benchmarking, or environment management.

Prerequisites & Trigger Conditions

Prerequisites
  1. GCP Compute SSH Keys: Local SSH key pair present at ~/.ssh/google_compute_engine (or standard ~/.ssh/id_rsa).
  2. GCP Authentication: Local gcloud authenticated with compute viewer/admin permissions.
  3. Network Reachability: Internal IP or hostname reachability to target VM (e.g. nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com or <REMOTE_HOST>).
  4. OpenSSH Client: Local OpenSSH client supporting ControlMaster options (-M, -S).
Trigger Conditions
  • Executed prior to running remote commands, setup scripts, conformance test suites, benchmarking, or environment management on target GCE or remote VMs.
  • Triggered when SSH connections fail due to stale socket files ("Control socket connect failed").
  • Triggered when user permissions or group memberships on target VM are modified requiring session group ID refresh.

Input/Output Contract

Inputs
  • Target Connection Details:
    • Target Name (<TARGET_NAME>, e.g., gce-c4-ssd or target VM identifier).
    • VM Name (<VM_NAME>).
    • Zone (<ZONE>).
    • GCP Project ID (<PROJECT_ID>).
    • SSH User (<SSH_USER>).
  • Socket Cache Directory: ~/.ssh/sockets/.
Outputs
  • Active Master Socket File: Unix domain socket located at ~/.ssh/sockets/<TARGET_NAME>.sock.
  • Background SSH Process: Persistent background ssh -f -N -M process holding the master channel open.

Step-by-Step Procedure

Step 1: Create Socket Cache Directory

Ensure local socket directory exists:

bash
mkdir -p ~/.ssh/sockets
Step 2: Clean Up Lingering Sessions and Stale Sockets

Before starting a master connection, gracefully terminate any active master SSH daemon associated with the target to avoid leaving orphaned background processes in memory, and remove any broken or stale socket file:

bash
ssh -O exit -S ~/.ssh/sockets/<TARGET_NAME>.sock <SSH_USER>@nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com 2>/dev/null || rm -f ~/.ssh/sockets/<TARGET_NAME>.sock
Step 3: Establish Master SSH Connection

Launch the persistent master SSH connection in the background (forks immediately via -f):

bash
ssh -f -N -M -S ~/.ssh/sockets/<TARGET_NAME>.sock -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -i ~/.ssh/google_compute_engine <SSH_USER>@nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com

Key options explained:

  • -f: Requests ssh to go to background just before command execution (forks into background).
  • -N: Do not execute a remote command (background connection mode).
  • -M: Place the SSH client into master mode for connection sharing.
  • -S ~/.ssh/sockets/<TARGET_NAME>.sock: Path to the control socket.
  • -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null: Prevent interactive host key prompts.
Step 4: Verify Connection Liveness

Test remote command execution over the master socket:

bash
ssh -S ~/.ssh/sockets/<TARGET_NAME>.sock -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -i ~/.ssh/google_compute_engine <SSH_USER>@nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com "echo 'Connection Alive'"
Show full SKILL.md (278 more words)Show less
Step 5: Refreshing / Recreating Sockets

If user permissions or group memberships change on the remote VM (e.g., after usermod -aG <group>):

  1. Gracefully terminate the active master SSH session and clean up the socket file:
    bash
    ssh -O exit -S ~/.ssh/sockets/<TARGET_NAME>.sock <SSH_USER>@nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com 2>/dev/null || rm -f ~/.ssh/sockets/<TARGET_NAME>.sock
  2. Re-establish the master connection by repeating Step 3.

Failure Modes & Edge Cases

Failure ScenarioRoot CauseRemediation / Recovery Action
Control socket connect failed: Connection refusedMaster SSH process died unexpectedly, leaving a dead socket fileGracefully exit or remove stale socket file (`ssh -O exit -S ~/.ssh/sockets/<TARGET_NAME>.sock <SSH_USER>@<HOST> 2>/dev/null
Permission Denied (publickey)SSH key ~/.ssh/google_compute_engine missing or expired GCP IAM SSH login credentialsRun gcloud compute config-default-ssh-keys or gcloud compute ssh <VM_NAME> --zone=<ZONE> to refresh SSH keys.
Permission / Group Refresh DelayUser added to a new group or permissions modified, but commands fail with permission errorsActive SSH master session retains original user and group IDs. Gracefully exit master session (`ssh -O exit -S ~/.ssh/sockets/<TARGET_NAME>.sock <SSH_USER>@<HOST> 2>/dev/null
Connection Drop / Network DisconnectRemote VM rebooted or network path resetGracefully exit master socket if responsive (`ssh -O exit -S ~/.ssh/sockets/<TARGET_NAME>.sock <SSH_USER>@<HOST> 2>/dev/null

Verification Checks

  1. Local Socket File Check: Confirm socket file exists and is an active socket file:
    bash
    test -S ~/.ssh/sockets/<TARGET_NAME>.sock && echo "SOCKET_EXISTS"
  2. Remote Echo Check: Confirm commands execute over multiplexed socket:
    bash
    ssh -S ~/.ssh/sockets/<TARGET_NAME>.sock -o StrictHostKeyChecking=no -o UserKnownHostsFile=/dev/null -i ~/.ssh/google_compute_engine <SSH_USER>@nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com "echo 'Connection Alive'"
  3. Graceful Teardown Check: Confirm graceful termination of the master socket:
    bash
    ssh -S ~/.ssh/sockets/<TARGET_NAME>.sock -O exit <SSH_USER>@nic0.<VM_NAME>.<ZONE>.c.<PROJECT_ID>.internal.gcpnode.com

© GoogleCloudPlatform, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/ssh-connection-management of GoogleCloudPlatform/gcsfuse.

Open the folder on GitHubat commit fac0483

Compare with similar skills

Ssh Connection Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ssh Connection Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ssh Connection Management this skillGoogleCloudPlatform/gcsfuse2.3k—~1.6kAutomated safety check: WarnApache-2.0
Gmail Inbox Watchergoogleworkspace/cli31k1 repos~476Automated safety check: PassApache-2.0
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Thesvgglincker/thesvg2.8k—~1.5kAutomated safety check: PassMIT

Similar skills

  • Gmail Inbox Watcher

    googleworkspace/cli

    Streams new Gmail messages as NDJSON from the gws command line tool using Google Pub/Sub, with label filters, batch settings and optional per-message files.

    31k GitHub starsUsed in 1 repo~476 tokens
    Productivity & AutomationAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Check Kiln's model list for deprecated or sunset models across all providers.

    5.2k GitHub stars~2.5k tokensUpdated today
    AI & LLM EngineeringAuto-check: notes

More from GoogleCloudPlatform/gcsfuse

  • Gcsfuse Integration Testing

    GoogleCloudPlatform/gcsfuse

    Step-by-step runbook for creating, extending, and verifying integration tests in the GCSFuse repository.

    2.3k GitHub stars~5.6k tokensUpdated today
    Auto-check passed

Works with

Questions about Ssh Connection Management

What does Ssh Connection Management do?

Guides on establishing persistent master SSH multiplexing sockets at ~/.ssh/sockets/<TARGETNAME.sock using ssh -f -N -M -S, testing connection liveness, gracefully terminating via -O exit, removing…. Ssh Connection Management is an agent skill from GoogleCloudPlatform/gcsfuse.sock using ssh -f -N -M -S, testing connection liveness, gracefully terminating via -O exit, removing stale control sockets, and recreating sockets when remote user permissions or groups change.

How do I install Ssh Connection Management in Claude Code?

Run `npx skills add GoogleCloudPlatform/gcsfuse --skill ssh-connection-management -a claude-code`. Or copy the skill folder (.agents/skills/ssh-connection-management in GoogleCloudPlatform/gcsfuse) into .claude/skills/ssh-connection-management in your project. Claude Code loads it when a task matches its description.

How do I install Ssh Connection Management in Codex?

Run `npx skills add GoogleCloudPlatform/gcsfuse --skill ssh-connection-management -a codex`. Or copy the skill folder (.agents/skills/ssh-connection-management in GoogleCloudPlatform/gcsfuse) into .agents/skills/ssh-connection-management in your project. Codex loads it when a task matches its description.

Can I use Ssh Connection Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add GoogleCloudPlatform/gcsfuse --skill ssh-connection-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ssh-connection-management, .gemini/skills/ssh-connection-management, .github/skills/ssh-connection-management and .opencode/skills/ssh-connection-management in your project.

What does Ssh Connection Management need to run?

Going by SKILL.md and its folder, Ssh Connection Management needs the command-line tools its instructions call (ssh and gcloud).

Does Ssh Connection Management access the network?

SKILL.md contains no URLs. Its commands use ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ssh Connection Management safe to install?

Our automated static check of SKILL.md flagged 10 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Ssh Connection Management use?

Ssh Connection Management is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ssh Connection Management use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ssh Connection Management?

Skills that share tags, products or a category with Ssh Connection Management: Gmail Inbox Watcher (googleworkspace/cli, 31k stars), Cloud Cost Optimization (wshobson/agents, 40k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ssh Connection Management?

GoogleCloudPlatform (a GitHub organization) maintains it in GoogleCloudPlatform/gcsfuse, which has 2,312 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 7, 2026.

Source: GoogleCloudPlatform/gcsfuse on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.