← SFTP: transfers and batch operations
06 / 6 · 40 MIN

Diagnosis and RUN handover

Prepare validation, rotation, and recovery using evidence from the scheduled path.

Concept and mechanism

Valid configuration does not prove the partner can deliver and the consumer can accept the file. In OpenSSH, sshd -T with connection parameters in -C helps observe effective configuration, including applicable Match conditions. Use this as configuration evidence complemented by authorized functional validation. For diagnosis, correlate account, host, file, delivery identity, stage, and outcome. internal-sftp needs its own logging arguments; do not assume it inherits daemon LogLevel. On some systems, the chroot environment has additional logging requirements. Check the installed platform and protect evidence against unnecessary exposure of credentials and content.

Guided application

During rotation, confirm the key used by scheduled execution before retiring the previous one under the plan. An operator-terminal test can use another agent or configuration file. At RUN handover, define contacts, public-key inventory, permissions, deadlines, alerts, and handling for missing, late, or duplicate deliveries. If confirmation disappears near cut-off, reconcile the identifier at the consumer and communicate deadline risk. Safe resending depends on the idempotency contract rather than SFTP alone. Examples are fictional, and this course involved no executed transfers, SSH connections, or key changes. Review deployed versions and supported extensions before applying the documented behavior.

IN PRACTICE

Lost confirmation: reconcile first; repeat only under the agreed contract.

Common pitfalls

Syntax as delivery; inherited logging; manual test as scheduler; a new name as duplicate-free retry.

Related topics: Transport and server trust · Permissions and isolation · Batch and observable failures

Take this idea with you

Provide operational autonomy with clear success, failure, and uncertainty criteria.

Create account

Reference: OpenSSH effective server configuration checks · DR SFTP 2026-09; selected OpenSSH client, server and extension behavior