This post was originally published on go2linux.org. The domain is no longer mine, but I am the original author. I am republishing it here on garron.me with corrections and improvements.

sshfs mounts a directory from a remote machine onto a local directory, using nothing but SSH. If you can log in to the server with ssh, you can mount it: the server needs no extra software and no configuration. Files are encrypted in transit, and every local program can open them as if they were on your disk.

Keep in mind that every read and write travels over the network. On a slow link, access is slow too.

Install sshfs

Debian and Ubuntu:

sudo apt install sshfs

Fedora:

sudo dnf install fuse-sshfs

Arch Linux:

sudo pacman -S sshfs

The package pulls in FUSE, which lets a regular user mount filesystems without root. Old guides tell you to install fuse-utils, run modprobe fuse and add your user to the fuse group; none of that is needed on a current distribution.

Mount a remote directory

Create an empty directory to use as the mount point, then mount:

mkdir -p ~/remote
sshfs user@server.example.com:/var/www ~/remote

You run this as your normal user, with no sudo. The first time, SSH asks you to accept the host key, and then for the password unless you use SSH keys.

If you leave the remote path empty, you get the remote home directory:

sshfs user@server.example.com: ~/remote

Check that it is mounted:

df -h ~/remote

Unmount

fusermount -u ~/remote

On some systems the command is fusermount3. umount ~/remote also works.

Useful options

A different SSH port:

sshfs -p 2222 user@server.example.com:/var/www ~/remote

A specific private key (use the full path):

sshfs -o IdentityFile=/home/me/.ssh/id_ed25519 user@server.example.com:/var/www ~/remote

Reconnect automatically when the connection drops — worth using on any laptop or unstable link:

sshfs -o reconnect,ServerAliveInterval=15,ServerAliveCountMax=3 user@server.example.com:/var/www ~/remote

Read-only, when you only want to look and not risk changing anything:

sshfs -o ro user@server.example.com:/var/www ~/remote

Show the remote files as owned by your local user, when the user IDs on both machines differ:

sshfs -o idmap=user user@server.example.com:/var/www ~/remote

Anything you have in ~/.ssh/config (host aliases, port, key, jump host) is honored, so with a Host web entry there the command is just sshfs web:/var/www ~/remote.

Let other users see the mount

By default only the user who mounted the filesystem can access it; even root is denied. To open it to others, uncomment this line in /etc/fuse.conf:

user_allow_other

Then mount with:

sshfs -o allow_other,default_permissions user@server.example.com:/var/www ~/remote

default_permissions makes the kernel enforce the normal file permission checks for those other users.

Mount from /etc/fstab

To mount on demand, the first time something touches the directory, add a line like this to /etc/fstab:

[email protected]:/var/www  /mnt/remote  fuse.sshfs  noauto,x-systemd.automount,_netdev,reconnect,IdentityFile=/home/me/.ssh/id_ed25519,allow_other,default_permissions  0  0

Then reload systemd:

sudo systemctl daemon-reload
sudo systemctl restart remote-fs.target

Three things to get right here:

  • The mount is performed by root, so password login cannot work. Use a key without a passphrase and give its full path in IdentityFile.
  • Root must already know the server's host key. Run sudo ssh [email protected] once and accept it.
  • allow_other is what lets your normal user read a mount made by root.

A hung mount

If the connection dies and the mount point stops responding, you will see:

ls: cannot access '/home/me/remote': Transport endpoint is not connected

Force a lazy unmount and mount again:

fusermount -uz ~/remote

The reconnect option shown above avoids most of these cases.

Project status and an alternative

sshfs works and is packaged by every major distribution, but upstream development has slowed to minimal maintenance, so do not expect new features. For occasional access to files on a server it is still the simplest tool there is.

If you want an actively developed alternative, rclone can mount the same SFTP server. Define the server once with rclone config (choose the sftp type), then:

rclone mount myserver:/var/www ~/remote --vfs-cache-mode writes --daemon

Unmount it the same way, with fusermount -u ~/remote.

See also

man sshfs — full reference.