Concept and mechanism
A configuration alias may change hostname, user, port, identity, and bastion. Two apparently similar commands can therefore connect to different destinations or accounts. Diagnosis should observe effective configuration rather than a single file line. The ssh -G command evaluates applicable rules and prints configuration without opening the remote session. For many options, the first obtained value is used; specific rules should generally precede broad defaults. Some options, such as identity lists, have their own behavior that must be checked in the installed version’s manual.
Guided application
Compare configuration for an interactive session and the failing job: system account, process home directory, loaded files, and arguments. Do not alter real environment variables in this exercise; observe context only. A client started with another configuration file may ignore the rules the operator expected. Verbose logs help identify attempts, negotiation, and offered identity, but should be treated as operational data. Before sharing, remove sensitive names and paths without removing the sequence needed for diagnosis.
ssh -G batch-prod reveals Port 2222 and User deploy. The job used the hostname directly and attempted port 22 with another account.
Common pitfalls
Assuming alias and hostname are equivalent; reading defaults without evaluating Host and Match.
Related topics: Bastions, forwarding, and port exposure · Automation and changes without losing access
Reproduce failure with the same account, arguments, and effective configuration.
Reference: ssh_config(5): client configuration · OpenSSH concepts and OpenBSD-current manuals consulted 2026-09-29; distribution defaults vary