Sign inSign up

christianmaier/hvergelmir-persistence2-ssh

By christianmaier

•Updated about 12 hours ago

OpenSSH on Alpine as a tunnel to one MariaDB container: keys only, no shell, no root, nothing else.

Image
Networking
Security
Databases & storage
0

240

christianmaier/hvergelmir-persistence2-ssh repository overview

⁠hvergelmir-persistence2-ssh

An OpenSSH server whose only job is to forward connections to a MariaDB container reachable as mariadb:3306. It is the single way into hvergelmir-persistence2-mariadb⁠, which publishes no port of its own.

Built for one deployment. It is public because it holds no secrets, not because it is meant for general use.

⁠What it allows, and what not

AllowedRefused
login as tunnel with an ed25519 public key from PERSISTENCE2_KEYSpasswords, keyboard-interactive, root, any other user, other key types
local forwards to exactly mariadb:3306any other target, remote forwards, Unix sockets, agent and X11 forwarding
every session: shell, command, terminal, sftp (MaxSessions 0; ForceCommand and the nologin shell as further lines)
  • No root: sshd runs as tunnel (10001). It needs no capabilities and works on a read-only file system.
  • Logs go to stderr. Each login is logged with its key fingerprint; the entrypoint logs which client each fingerprint belongs to. Key material is never logged.
  • Limits for clients like AWS Lambda, whose cold starts arrive together and which are frozen between calls:
    • MaxStartups 50:30:100;
    • LoginGraceTime 10;
    • an unanswering client is dropped after 5½ minutes;
    • no lockout per source address (PerSourcePenalties no), since clients may share addresses and keys cannot be guessed.

⁠Configuration

PERSISTENCE2_KEYScomma-separated <client>:<base64 of an ssh-ed25519 public key>. On each start the entrypoint writes authorized_keys from it and puts restrict,port-forwarding,permitopen="mariadb:3306" in front of every key; anything that is not one valid ed25519 key stops the start.
PERSISTENCE2_STAGEcomment of a newly made host key
/var/lib/sshd (volume)the host key, made on the first start. Keep it, so clients can pin it.
/run/sshd (tmpfs)owned by 10001, mode 0700
port2222
ssh:
  image: christianmaier/hvergelmir-persistence2-ssh:<commit>@sha256:<digest>
  read_only: true
  cap_drop: [ALL]
  security_opt: ["no-new-privileges:true"]
  tmpfs:
    - /run/sshd:uid=10001,gid=10001,mode=0700
  environment:
    PERSISTENCE2_KEYS: "dbeaver:AAAAC3NzaC1lZDI1NTE5AAAA…"
  volumes:
    - hostkeys:/var/lib/sshd
  ports:
    - "2222:2222"

A client then opens the tunnel and connects to 127.0.0.1:3306:

ssh -N -L 3306:mariadb:3306 -p 2222 tunnel@<host>

The healthcheck sends an SSH identification and expects sshd's banner back.

Platform: linux/amd64. Alpine 3.24 pinned by digest; each tag is the Git commit it was built from.

Tag summary

Content type

Image

Digest

sha256:cab68ee14…

Size

4.7 MB

Last updated

about 12 hours ago

docker pull christianmaier/hvergelmir-persistence2-ssh:1fe30451