Users and SSH access

How to SSH into a customer environment — port 2409, the app user, sudo escalation, and SSH key management.

Every StoreFrame environment is a Linux VM you can access over SSH. This page covers the connection details, what you can do as each user, and how to manage SSH keys.

Connection details

ssh app@<subdomain>.<domain> -p 2409
SettingValue
Port2409
Userapp
AuthenticationSSH key only (password auth disabled)

Port 2409 is intentional. Customer environments listen on a non-standard port to reduce noise from automated scanners. Do not try port 22 — it will not work.

Users on a customer environment

Each environment has two accounts you interact with:

app — your working user

The app user owns your Magento installation. SSH as app for all routine work.

  • Home directory: /var/www
  • Project root: /var/www/<subdomain>.<domain>/
  • Group memberships: users, admin, docker, syslog

Because app is a member of the docker group, you can run Docker commands directly without sudo:

docker ps
docker logs nginx --tail 100
docker exec -it php bash

root via sudo

The app user has passwordless sudo through the admin group. Use it when you need elevated access:

sudo systemctl status ssh
sudo apt install <package>
sudo restic-restore list

Keep sudo usage to administrative tasks. Everything under /var/www/<subdomain>.<domain>/ is owned by app, so you rarely need it for application work.

What you can do as app

Once connected, your Magento installation is at /var/www/<subdomain>.<domain>/application/:

# Run Magento CLI commands
cd /var/www/<subdomain>.<domain>/application
bin/magento cache:flush
bin/magento indexer:reindex
bin/magento setup:static-content:deploy

# Read application logs
tail -f var/log/exception.log
tail -f var/log/system.log

# Check running containers
docker ps
docker logs mariadb --tail 50

# Enter a container
docker exec -it php bash

What requires sudo

TaskCommand
Install system packagessudo apt install <package>
Restart a containersudo docker restart <name> or run as app (docker group)
Edit files under /etc/sudo nano /etc/...
Run the backup helpersudo restic-restore list
Check system logssudo tail /var/log/auth.log

docker commands work without sudo because app is in the docker group. The sudo in the backup section is a convention from the helper script — see Backups for details.

Managing SSH keys

Keys are added to each environment separately.

On an environment

Go to the environment's Settings → SSH keys page and add your public key. The platform adds it to the authorized_keys file of the app user on that environment, usually within about a minute.

Organization key library

Keys saved under Settings → Organization → SSH keys are a library. When you create a new environment you can pick one of them, and it is installed on that environment. Saving a key to the library does not add it to environments that are already running; add it on each environment as described above.

Finding your public key

cat ~/.ssh/id_ed25519.pub
# or
cat ~/.ssh/id_rsa.pub

If you don't have an SSH key yet, generate one:

ssh-keygen -t ed25519 -C "your-email@example.com"

Security notes

  • Password authentication is disabled. Only public-key auth works.
  • Root login over SSH is restricted — you must SSH as app and escalate with sudo.
  • SSH runs on a non-standard port to reduce scan noise. A firewall on the VM limits inbound connections.
  • All SSH authentication attempts are logged to /var/log/auth.log.

If you get a Permission denied (publickey) error, check that the key is added on that environment's SSH keys page (not only in the organization library) and wait a minute for the platform to apply it.

On this page