Sign inSign up

ddub/ssh-notify

By ddub

•Updated over 8 years ago

Send slack notifications upon ssh login

Image
0

891

ddub/ssh-notify repository overview

⁠ssh-notify

Send Slack notifications when a user accesses a secure shell of a node, so that there are no surprises from manual changes made after node provisioning.

Based upon similar work for google compute engine instances⁠

⁠Install

  1. create an incomming webhook in your slack team
  2. edit example/gke.yaml to change the webhook to the one created above
  3. kubectl apply -f example/gke.yaml

Now you can ssh into one of the nodes and a slack notification will be sent!

⁠Process

The example/gke.yaml provisions a daemonset to provision a pod onto each of your nodes. This pod runs a docker container that has access to /etc/pam.d and /var/lib/toolbox/ssh-notify on the host.

The docker container will

  1. Copy the notify binary into the toolbox directory
  2. Write the config.yaml file into that directory with your slack webhook address
  3. Ensures that /etc/pam.d/system-remote-login will call the notify binary with the configuration when a user logs in.

Then it will re-check every 60 seconds that this is still valid.

Tag summary

Content type

Image

Digest

Size

3.4 MB

Last updated

over 8 years ago

docker pull ddub/ssh-notify