Production control plane · Official release published · Client integration pending

CLIENT × RESIDENT AGENT

Keep the SSH working context online

A native client and resident agent keep persistent terminals, monitoring, files, and system tools in the context of the same host.

W

Windows

Desktop client

See downloads for live records
A

Android

Mobile companion

See downloads for live records
m

macOS

Independent desktop client

Planned · Downloads not open
i

iOS

Independent mobile companion

Planned · Downloads not open

Make the client and agent boundary obvious

The client authenticates and initiates, SSH is the only entry point, and the resident agent exposes structured capabilities through a server-local socket.

NODE 01

Native client

Hosts, credentials, trust, and operation entry points stay local.

CLIENT
LINK 02

SSH tunnel

Reuse SSH authentication and encryption without a new public port.

PURE SSH
CORE 03

Resident agent

Listen only on the server-local socket and provide structured capabilities.

AGENT
STATE 04

tmux / redb

Terminal context and monitoring history persist on the server.

SERVER STATE
TOOLS 05

Files and systems

Reliable transfers and system actions use explicit protocols.

STRUCTURED
PURE SSH

Works without the agent

Standard terminals, port forwarding, and access grants keep a native SSH path.

Fallback boundary
RESIDENT AGENT

Client × agent integration

Persistent terminals, monitoring history, files, AI, systems, and apps use the structured protocol.

Primary path

One workspace, nine clearly bounded modules

Every module states its dependency and result. The product docs continue with architecture, boundaries, interfaces, and verification.

MIXED

Host management

Connections, authentication, host keys, and real reachability results.

Connection entry
MIXED

Terminal

Choose persistent tmux or a standard SSH PTY by task.

Resume context
AGENT

Monitoring

Snapshots, live subscriptions, history, and top processes.

Structured status
AGENT

Files

Browse, search, edit, and transfer with integrity checks.

Same host context
PURE SSH

Port forwarding

Map server-reachable ports safely to the client machine.

Native SSH
AGENT

AI assistant

Invoke structured tools behind permission, confirmation, and audit gates.

Bring your model
AGENT

System management

Read system facts and manage processes or firewalls explicitly.

Visible actions
AGENT

Application center

Focus on Docker, common apps, and systemd services.

Capability modules
PURE SSH

Access grants

Issue isolated access keys and revoke them by stable marker.

Least access

From the first host to a complete workflow

Tutorials form an executable path from first connection to daily operations instead of a loose article collection.

STEP 01

Add a host

Complete SSH authentication and host-key trust.

Verify connection
STEP 02

Deploy the agent

Probe server architecture and select the matching agent and tmux pair.

Paired deployment
STEP 03

Persistent terminal

Disconnect deliberately, then verify task and screen recovery.

tmux
STEP 04

Monitoring history

Inspect live detail, historical ranges, and processes.

redb
STEP 05

File transfer

Upload or download and verify integrity results.

Chunk verification
STEP 06

AI assistant

Use your own model and begin with read-only diagnosis.

Permission gate

A direct SSH data plane and restrained cloud control plane

The two paths stay separate: Creation Cloud never enters the SSH data plane between the client and your server.

SSH DATA PLANE

Client to user server

The agent uses a local socket, host-key changes require confirmation, and SSH, tmux, or user processes are never ended without authorization.

Cloud is not in this path
CLOUD CONTROL PLANE

Accounts, devices, and optional sync

Host and AI provider accounts sync only when the user asks. Trusted clients encrypt secrets, and the service stores versioned opaque ciphertext only.

No plaintext sensitive data

Accounts support devices and sync, never SSH

The Creation Cloud control plane is deployed on the production server with accounts, devices, sync, model metadata, encrypted vault envelopes, releases, downloads, and administration. Production client integration ships separately.

ACCOUNT

Profile and security

Account status, security settings, and password boundaries.

Account password ≠ vault password
DEVICE

Devices

Register, rename, and revoke trusted devices.

No SSH host records
SYNC

Sync

Host and AI resource revisions, generations, and manual-sync outcomes.

No persistent conflicts
MODEL

Models

Read administrator-managed global model names, vendors, API formats, and API URLs.

Client-encrypted manual sync only
VAULT

Vault

Show resource ciphertext versions, generations, and required metadata only.

Server cannot decrypt
RELEASE

Downloads

Expose compatible releases, sources, and download history.

Real records

Answer the questions that decide adoption

The home page keeps only high-value decision questions; the FAQ page carries the full explanation.

Does Creation Cloud proxy SSH?

No. The SSH data plane remains direct from the client to your server. Cloud only provides account, device, and optional sync controls.

Can I use Creation-SSH without the agent?

A standard SSH terminal, port forwarding, and access grants remain available. Persistent sessions, monitoring, and structured management depend on the agent.

Are host addresses and private keys uploaded?

Host names, addresses, ports, tags, status, connection settings, credentials, and AI provider settings sync only as client-encrypted ciphertext. known_hosts, terminal content, and command history never upload.

Is the vault password the account password?

No. The account password signs you in. The vault password derives encryption keys only on trusted clients and is never uploaded.

How can I verify a download?

Formal download entries expose platform, architecture, source, file size, and SHA256 for verification before installation.

Is Android a full desktop copy?

No. Android is a mobile companion focused on inspection, lightweight actions, and continuity with desktop workflows.

Related SSH topics

  • SSH
  • AI-SSH
QQ COMMUNITY / QR QQ community QR awaiting upload
Join the QQ community Scan to join Creation-SSH users · Click to enlarge