# Embedded SSH

> Octelium documentation. Canonical page: <https://octelium.com/docs/octelium/latest/management/core/service/embedded-ssh>.

In addition to providing the application-layer `SSH` mode where *Users* can access SSH servers in a secretless way without having distribute and share private keys or passwords with them (read more [here](https://octelium.com/docs/octelium/latest/management/core/service/ssh.md)), Octelium also offers an "embedded" SSH mode where the connected `octelium` client itself, when using the `--essh` flag in the `octelium connect` command, can serve SSH by running an embedded SSH server from within the `octelium` client without having to rely on an existing SSH server on the host it is running on. Just like in the typical application-layer `SSH` mode, embedded SSH seamlessly provides secretless access for *Users* without having to share and distribute private keys or passwords.

This mode is especially useful to SSH into fleets of hosts such as embedded IoT devices, containers and other confined environments where it is not possible or practical to run a standalone SSH server on every and each one of them.

Embedded SSH is capable of serving SSH even at "rootless" mode. In other words, the `octelium` client is capable of serving embedded SSH even when running as an unprivileged non-root user.

You can create an embedded SSH *Service* as follows:

```yaml
kind: Service
metadata:
  name: essh1
spec:
  mode: SSH
#!mark(1:3)
  config:
    ssh:
      eSSHMode: true
```

A *User* can simply announce their intent to serve embedded SSH when connecting to the *Cluster* via the `--essh` flag as follows:

```bash
export OCTELIUM_DOMAIN=example.com
# In this example we are running octelium and serving SSH as an unprivileged OS user without sudo
octelium connect --essh
```

Now connected, authorized *Users* can simply SSH into the host of a certain *Session* by using the *Session*'s name as the SSH user (read more [here](https://octelium.com/docs/octelium/latest/user/cli/connect.md#serving-embedded-ssh) and [here](https://octelium.com/docs/octelium/latest/user/cli/access.md#embedded-ssh)). Here is an example:

```bash
export OCTELIUM_DOMAIN=example.com
# Connect to the Cluster via the detached mode
octelium connect -d
# OR
sudo -E octelium connect

#You can optionally list the current Sessions as follows:
octeliumctl get sess

# Once you obtain the Session name, use it as the SSH user as follows:
ssh usr1-abcdef@essh1
```

> **Note:**
>
> The *Cluster* comes with a built-in `essh.octelium` *Service* that operates in embedded SSH mode, so you do not need to create your own embedded SSH *Service* in order to SSH into the hosts of connected *Sessions* that are serving embedded SSH. You can simply use it as `ssh usr1-abcdef@essh.octelium` or via the `octelium ssh` command (read more [here](https://octelium.com/docs/octelium/latest/user/cli/access.md#embedded-ssh)).
