Publishing docs — all chapters
What SFTP is for
SFTP is the file-transfer part of SSH. If you can log in to a machine with SSH, you can publish to it: a VPS, shared web hosting, or a box at home. You get the most control, and you look after the machine.
In Site Settings → Publishing, set Publish Using to SFTP.
The server
| Field | What to enter |
|---|---|
| Host | Your server’s address: a domain such as ftp.example.com, or an IP address such as 203.0.113.10. |
| User | Your SSH login, for example deploy. |
| Port | 22 for almost everyone. Change it only if your host runs SSH on another port. |
| Remote Path | The folder your web server serves from, for example /var/www/fieldnotes. On shared hosting it is often /public_html or /www. Selfish creates the folders it needs inside it. |
Finding your details
Where these live depends on your host.
| Kind of host | Where to look |
|---|---|
| A VPS (Hetzner, DigitalOcean, Linode) | Host is the server’s IP or domain. User is the account you log in as. The path is wherever your web server’s root points, often /var/www/html. |
| Shared hosting, cPanel or Plesk | Look for “SFTP” or “SSH access” in the control panel. The path is usually public_html inside your home folder. |
| A home server or NAS | Host is its local address or a domain, with SSH switched on. The port has to be reachable from the device you publish from. |
How to publish a website over SFTP goes through each of these in more depth, and How to host a static blog on your own server sets a server up from nothing.
Authentication
Under Authentication, choose Password or SSH Private Key.
For a key, paste an OpenSSH private key or choose Import… to read it from a file, and enter its Passphrase if it has one. RSA and Ed25519 keys are supported. Other kinds, such as ECDSA, aren’t yet.
Either way, the secret is stored in the Keychain, never in the site’s data.
Host-key trust
The first time Selfish reaches a server it remembers that server’s SSH host key and shows you its SHA256: fingerprint. This is trust on first use, the same model SSH itself uses. If the key ever changes, uploads are blocked, which is real protection against a server being impersonated.
- The first time you connect, compare the fingerprint with what your host published, or with the output of
ssh-keyscan. - If the key later changes, Selfish stops the upload and warns you. Find out why before you carry on.
- When you have changed the key yourself, by rebuilding the server for example, use Reset Trusted Host Key under Security and trust the new one.
Test Connection
Test Connection checks the login and the remote path, creating the folder if it isn’t there yet. It also looks inside the folder you chose. If it finds the host’s web folder in there (public_html, www, htdocs and the like), it tells you, because a site uploaded beside that folder rather than into it won’t show. The message names the path to use.
What a publish does
- Uploads only the files whose content changed since the last publish.
- Removes the files your site no longer has: a post you unpublished or deleted comes down, photos and all, and folders left empty are tidied away.
- Removes only files it recorded uploading. Nothing else in the folder is ever removed, though a file of your own with the same name as one of the site’s files would be overwritten, with the exception below.
- Leaves your own
robots.txt, favicon, touch icon or404.htmlalone if they were on the server before Selfish.
Selfish keeps its record of what it uploaded in .selfish-manifest.json, next to your site. The first publish uploads everything, to create it. How publishing works has the detail.
Finishing touches on your server
- Page not found. Point your web server’s error page at
404.html, so a bad link shows your themed page. - Addresses without .html work on most web servers as they are, because a folder’s
index.htmlis served at the folder’s address.
Problems? See Troubleshooting.