Skip to main content

SSH into AWS EC2 instances from your Mac

Public instances with their key pair, private ones through a bastion, a private database through a tunnel: each saved once as a profile.

By Lucas Russo, developer of SSHive · Updated

EC2 instances come in two shapes: public ones you reach directly with the key pair AWS gave you, and private ones in a VPC subnet that only a bastion or a VPN can reach. Behind them there is often an RDS database that answers only inside the VPC. With the OpenSSH client, that becomes ssh -i ~/keys/app.pem -J ec2-user@bastion ec2-user@10.0.1.42 typed from memory. In SSHive each machine is a profile: the bastion once, each private instance pointing at it, and the database tunnel on the bastion's profile. When the bastion's address changes, you edit one profile.

A public instance and its .pem key

AWS hands you a .pem file when you create a key pair. The cleanest way to use it in SSHive is to import it once: open Settings > SSH Keys > Import a key and paste the file's content. SSHive then keeps the key encrypted, and the profile no longer depends on a file sitting in Downloads. Create a profile with the instance's public DNS name or IP and the user of its AMI: ec2-user on Amazon Linux, ubuntu on Ubuntu, admin on Debian. The instance's security group must allow port 22 from your address.

Private instances through a bastion

Application servers belong in private subnets, reached through a bastion in the public subnet. Create the bastion's profile first (public address, user, key). In the profile of a private instance, enter its private IP, then open Advanced options > Jump Chain (multi-hop), choose Add hop and pick the bastion. SSHive connects to the bastion first and opens the session to the instance through it. Each hop signs in with its own profile, so the bastion and the instance can use different keys. A chain holds up to five hops, and it is a Pro feature. The jump host guide goes through it screen by screen.

A private RDS database from TablePlus or DBeaver

RDS sits in a private subnet, and your database client on the Mac cannot reach it. The bastion can. On the bastion's profile, add a local tunnel: local port 5432, remote host mydb.xxxxxxxx.eu-west-1.rds.amazonaws.com, remote port 5432. Connect to the bastion, then point TablePlus or DBeaver at localhost:5432 with the database credentials. The name is resolved on the bastion, inside the VPC, which is why it works. This part fits in the free version: it is a single local tunnel on a direct connection.

What is free here, and what needs Pro

A public instance with its key, SFTP, and the RDS tunnel on the bastion all work in the free version, within 5 profiles and 2 sessions at once. Private instances need SSHive Pro, because the jump chain is a Pro feature; Pro also removes the profile and session limits and adds broadcast, for sending the same command to a group of instances. It costs $12.99, once.

Frequently asked questions

Can I go through AWS Session Manager instead of an open port 22?+
Yes, through a port forward. With the Session Manager plugin for the AWS CLI installed on the Mac, run this in the Terminal: aws ssm start-session --target i-0123456789abcdef0 --document-name AWS-StartPortForwardingSession --parameters '{"portNumber":["22"], "localPortNumber":["2222"]}' Then connect an SSHive profile to localhost, port 2222, with the instance's user and key. The instance needs no inbound rule for port 22.
What happens when the instance's IP address changes?+
Stopping and starting an instance gives it a new public IP and a new public DNS name, unless an Elastic IP is attached. Either attach one to the machines you connect to often, or reach them through the bastion by private IP, which stays the same for the life of the instance. Either way, only one profile needs editing.
Can I copy files to S3 from SSHive?+
SSHive speaks SSH and SFTP, not S3. In the instance's SSH session, aws s3 cp does the job, and with an instance role attached it needs no access keys. The SFTP pane is for the instance's own disk.

Try SSHive Free for macOS

Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.