Publishing docs — all chapters

What SFTP is for

SFTP is the file-transfer part of SSH. If you can log in to a machine with SSH, you can publish to it: a VPS, shared web hosting, or a box at home. You get the most control, and you look after the machine.

In Site Settings → Publishing, set Publish Using to SFTP.

The server

FieldWhat to enter
HostYour server’s address: a domain such as ftp.example.com, or an IP address such as 203.0.113.10.
UserYour SSH login, for example deploy.
Port22 for almost everyone. Change it only if your host runs SSH on another port.
Remote PathThe folder your web server serves from, for example /var/www/fieldnotes. On shared hosting it is often /public_html or /www. Selfish creates the folders it needs inside it.

Finding your details

Where these live depends on your host.

Kind of hostWhere to look
A VPS (Hetzner, DigitalOcean, Linode)Host is the server’s IP or domain. User is the account you log in as. The path is wherever your web server’s root points, often /var/www/html.
Shared hosting, cPanel or PleskLook for “SFTP” or “SSH access” in the control panel. The path is usually public_html inside your home folder.
A home server or NASHost is its local address or a domain, with SSH switched on. The port has to be reachable from the device you publish from.

How to publish a website over SFTP goes through each of these in more depth, and How to host a static blog on your own server sets a server up from nothing.

Authentication

Under Authentication, choose Password or SSH Private Key.

For a key, paste an OpenSSH private key or choose Import… to read it from a file, and enter its Passphrase if it has one. RSA and Ed25519 keys are supported. Other kinds, such as ECDSA, aren’t yet.

Either way, the secret is stored in the Keychain, never in the site’s data.

Host-key trust

The first time Selfish reaches a server it remembers that server’s SSH host key and shows you its SHA256: fingerprint. This is trust on first use, the same model SSH itself uses. If the key ever changes, uploads are blocked, which is real protection against a server being impersonated.

  1. The first time you connect, compare the fingerprint with what your host published, or with the output of ssh-keyscan.
  2. If the key later changes, Selfish stops the upload and warns you. Find out why before you carry on.
  3. When you have changed the key yourself, by rebuilding the server for example, use Reset Trusted Host Key under Security and trust the new one.

Test Connection

Test Connection checks the login and the remote path, creating the folder if it isn’t there yet. It also looks inside the folder you chose. If it finds the host’s web folder in there (public_html, www, htdocs and the like), it tells you, because a site uploaded beside that folder rather than into it won’t show. The message names the path to use.

What a publish does

Selfish keeps its record of what it uploaded in .selfish-manifest.json, next to your site. The first publish uploads everything, to create it. How publishing works has the detail.

Finishing touches on your server

Problems? See Troubleshooting.