SSH and PowerShell
How the runner connects to Linux and Windows hosts, and how to prepare them.
Every host is reached over SSH from the runner. The host's system, set in Admin → Hosts, decides the shell: Linux runs commands in the account's POSIX shell, Windows runs them in PowerShell.
Prepare a Linux host
Any server with an SSH daemon works. Create or choose the account each person will use, with the least rights that do the job, and allow it to sign in with a password or a key.
For a key, add the public key to the account's ~/.ssh/authorized_keys on the server, and store the private key in Orlok as the person's credential.
Prepare a Windows host
Windows hosts need the OpenSSH server, built into Windows Server 2019 and later and into Windows 10 and 11. In an administrator PowerShell:
Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0
Start-Service sshd
Set-Service -Name sshd -StartupType Automatic
The installer opens port 22 in Windows Firewall. Orlok works whether the server's default SSH shell is cmd.exe or PowerShell: each command is sent to powershell -NoProfile -NonInteractive -EncodedCommand, so no quoting layer can change it.
Keys for administrators live elsewhere on Windows. For an account in the local Administrators group, OpenSSH reads public keys from
C:\ProgramData\ssh\administrators_authorized_keys, not from the user's profile. That file must be readable only by Administrators and SYSTEM.
Credentials
Each person stores their own credential for a host in Account → Credentials:
- a password, with its username;
- or an SSH key, with its username and, if the key has one, its passphrase.
A credential is tried on its hosts as soon as it is saved. See Credentials.
How the runner connects
- The host key is trusted on the first connection that gets in and enforced from then on. Orlok prefers an Ed25519 key, then ECDSA, then RSA.
- A connection gives up after 10 seconds if the host does not answer.
- Agent forwarding, X11 and port forwarding are off. Only the credential stored in Orlok is offered: no other key and no agent.
- With a password, Orlok tries it once. A wrong password fails at once instead of asking again.
Commands on Windows
On a Windows host the colleague writes PowerShell. A command succeeds when PowerShell reports success; otherwise the job fails with the program's exit code, or 1. Progress bars are switched off, so the output stays readable.
What runs without asking in ask mode is listed in Modes: every Get-* cmdlet, the pipeline helpers such as Where-Object and Select-Object, and classic tools such as ipconfig and systeminfo. Lines that use variables, foreach, try or .NET methods can only be approved once.