Users and SSH access
How to SSH into a customer environment — port 2409, the app user, sudo escalation, and SSH key management.
Every StoreFrame environment is a Linux VM you can access over SSH. This page covers the connection details, what you can do as each user, and how to manage SSH keys.
Connection details
ssh app@<subdomain>.<domain> -p 2409| Setting | Value |
|---|---|
| Port | 2409 |
| User | app |
| Authentication | SSH key only (password auth disabled) |
Port 2409 is intentional. Customer environments listen on a non-standard port to reduce noise from automated scanners. Do not try port 22 — it will not work.
Users on a customer environment
Each environment has two accounts you interact with:
app — your working user
The app user owns your Magento installation. SSH as app for all routine work.
- Home directory:
/var/www - Project root:
/var/www/<subdomain>.<domain>/ - Group memberships:
users,admin,docker,syslog
Because app is a member of the docker group, you can run Docker commands directly without sudo:
docker ps
docker logs nginx --tail 100
docker exec -it php bashroot via sudo
The app user has passwordless sudo through the admin group. Use it when you need elevated access:
sudo systemctl status ssh
sudo apt install <package>
sudo restic-restore listKeep sudo usage to administrative tasks. Everything under /var/www/<subdomain>.<domain>/ is owned by app, so you rarely need it for application work.
What you can do as app
Once connected, your Magento installation is at /var/www/<subdomain>.<domain>/application/:
# Run Magento CLI commands
cd /var/www/<subdomain>.<domain>/application
bin/magento cache:flush
bin/magento indexer:reindex
bin/magento setup:static-content:deploy
# Read application logs
tail -f var/log/exception.log
tail -f var/log/system.log
# Check running containers
docker ps
docker logs mariadb --tail 50
# Enter a container
docker exec -it php bashWhat requires sudo
| Task | Command |
|---|---|
| Install system packages | sudo apt install <package> |
| Restart a container | sudo docker restart <name> or run as app (docker group) |
Edit files under /etc/ | sudo nano /etc/... |
| Run the backup helper | sudo restic-restore list |
| Check system logs | sudo tail /var/log/auth.log |
docker commands work without sudo because app is in the docker group. The sudo in the backup section is a convention from the helper script — see Backups for details.
Managing SSH keys
Keys are added to each environment separately.
On an environment
Go to the environment's Settings → SSH keys page and add your public key. The platform adds it to the authorized_keys file of the app user on that environment, usually within about a minute.
Organization key library
Keys saved under Settings → Organization → SSH keys are a library. When you create a new environment you can pick one of them, and it is installed on that environment. Saving a key to the library does not add it to environments that are already running; add it on each environment as described above.
Finding your public key
cat ~/.ssh/id_ed25519.pub
# or
cat ~/.ssh/id_rsa.pubIf you don't have an SSH key yet, generate one:
ssh-keygen -t ed25519 -C "your-email@example.com"Security notes
- Password authentication is disabled. Only public-key auth works.
- Root login over SSH is restricted — you must SSH as
appand escalate withsudo. - SSH runs on a non-standard port to reduce scan noise. A firewall on the VM limits inbound connections.
- All SSH authentication attempts are logged to
/var/log/auth.log.
If you get a Permission denied (publickey) error, check that the key is added on that environment's SSH keys page (not only in the organization library) and wait a minute for the platform to apply it.