Lesson 17 / 24
SSH Keys and Commit Signing
Keep SSH private keys in 1Password and sign Git commits with them.
Keys that never touch the disk
The 1Password SSH agent stores your private keys inside the vault and lets SSH and Git use them after you approve with biometrics. The key file never sits in ~/.ssh, so a stolen laptop disk or a stray backup does not leak it.
Sign commits with an SSH key
Git can sign commits with an SSH key instead of GPG. Paste your public key where <public key> appears and add the same key to GitHub as a signing key.
git config --global gpg.format ssh
git config --global user.signingkey "<public key>"
git config --global commit.gpgsign trueProtect private keys
Never share a private key or paste it into chat. Only the public key is shared. If a private key ever leaves your control, remove it from every server and GitHub and generate a new pair.
Quick check: Which part of an SSH key pair may you share freely?
- The private key
- Both parts
- Neither
- The public key
Answer
The public key — The public key only verifies; the private key proves identity and must stay secret.