Lanyard SSH Agent Switchboard

jwilger1 pts0 comments

Lanyard — one socket for every SSH agentSkip to contentPRODUCTION READY Version 1.0 is stable for single-owner Linux workstations. Review the security boundary before operating with production credentials.SSH AGENT ROUTING / LINUX<br>LANYARD One socket. Every agent within reach.<br>Keep Git signing and SSH authentication working as you move between a local 1Password agent and forwarded laptop sessions—even inside the same long-running terminal-multiplexer session, whether you use Zellij, tmux, or another multiplexer.<br>INSTALL LANYARD →READ THE ROUTING MODEL

01 / ARRIVESSH in with agent forwarding.<br>Your laptop’s agent appears at a temporary socket.

02 / ATTACHJoin an existing multiplexer session.<br>Zellij, tmux, or another multiplexer still remembers whichever socket started it.

03 / ROUTEPoint everything at Lanyard.<br>The socket stays put. The available agents can change underneath it.

How Lanyard routes SSH agent requestsThree agent sources converge at Lanyard, which exposes one stable socket to SSH, Git, and terminal multiplexers.FORWARDED AGENTREGISTERED AGENT1PASSWORDLANYARDTRY · PROMOTE · FAIL CLOSEDSSHGIT SIGNMUX SESSIONFIG. 01 Requests enter through one stable socket. Lanyard finds a key without making your shell remember where it lives.<br>01Lanyard never stores private keys. It speaks the standard SSH agent protocol to agents you already trust.<br>02Identities are combined and deduplicated. Signing tries current agents in policy order without relying on stale identity-list results.<br>03A successful signer moves to the front of the line for that key. Timeouts and failures fall through to the next candidate.<br>04If no agent can sign, Lanyard fails closed. Mutation, key import, and agent locking are deliberately out of service.

agent lanyard socket multiplexer stable agents

Related Articles