scp, sftp and rsync

scp, sftp and rsync Instead of FTP

FTP sends passwords and files in clear text and needs extra ports for data. SSH already does its job with your keys and ~/.ssh/config aliases, so a web server needs no FTP daemon.

File transfer options for a web server
Tool Encrypted Best at Watch out for
FTP No Nothing today Clear-text passwords
FTPS TLS Old hosting panels Certificates, extra ports
scp SSH One file or a few Recopies whole files
sftp SSH Scripted file work No delta transfers
rsync 13,872 SSH Deploys and backups A misplaced --delete

Since OpenSSH 9.0 23,707 , scp speaks the SFTP protocol underneath (scp -v logs command sftp), and scp -O restores the legacy protocol for very old servers. sftp -b file runs a batch of put, ls and rm commands unattended. rsync sends only what changed. -a preserves permissions and times, -z compresses, -i itemizes each change, and --delete removes server files gone locally, so preview with --dry-run first.

Previewing and running an rsync deploy, then syncing one changeShell
rsync -azi --delete --exclude-from=site/.rsync-exclude --dry-run site/ web1:site/
rsync -az --delete --exclude-from=site/.rsync-exclude site/ web1:site/
echo 'body{margin:0;font-family:sans-serif}' > site/public/css/app.css
rsync -azi --delete --exclude-from=site/.rsync-exclude --stats site/ web1:site/ \
  | grep -E '^<|speedup'
Output
created directory site
cd+++++++++ ./
<f+++++++++ .rsync-exclude
cd+++++++++ public/
<f+++++++++ public/hero.jpg
...
<f.st...... public/css/app.css
total size is 200,083  speedup is 482.13

The exclude file lists .git/, .env and storage/logs/, so secrets and logs never leave your machine. Mind the trailing slash: site/ copies the directory's contents, while site would create site/site on the server. On Windows, WinSCP 14,725 and FileZilla 4,598 speak SFTP with the same keys.