SSH server allowing authenticated users to open TCP forwards only to approved destinations
947
This image runs an SSH server that allows authenticated users to open TCP forwards only to explicitly authorized destinations. It is useful as a small jump host in Kubernetes for reaching internal services such as MySQL.
sshd on port 22jump user for SSH accessAUTHORIZED_KEYSPermitOpen using AUTHORIZED_DESTINATIONS| Variable | Description |
|---|---|
AUTHORIZED_KEYS | One or more SSH public keys, separated by newlines. |
AUTHORIZED_DESTINATIONS | Space-separated list of allowed host:port destinations for TCP forwarding. |
Example:
AUTHORIZED_DESTINATIONS="db-a.internal:3306 db-b.internal:3306"
Replace the placeholders with your own image tag, allowed destinations, and public SSH keys.
services:
ssh-tunnel:
image: kumojin/ssh-server:1.0.0
container_name: ssh-tunnel
ports:
- "2222:22"
environment:
AUTHORIZED_DESTINATIONS: "<db-host-1>:3306 <db-host-2>:3306"
AUTHORIZED_KEYS: |
<ssh-public-key-1>
<ssh-public-key-2>
Then connect through the published SSH port:
ssh -N -L 3306:<allowed-db-host>:3306 [email protected] -p 2222 -i <private-key>
Replace the placeholders with your own image tag, allowed destinations, and public SSH keys.
apiVersion: apps/v1
kind: Deployment
metadata:
labels:
name: mysql-proxy
name: mysql-proxy
namespace: dev
spec:
replicas: 1
selector:
matchLabels:
app: mysql-proxy
template:
metadata:
labels:
app: mysql-proxy
spec:
containers:
- image: kumojin/ssh-server:1.0.0
name: mysql-proxy
env:
- name: AUTHORIZED_DESTINATIONS
value: "<db-host-1>:3306 <db-host-2>:3306 <db-host-3>:3306"
- name: AUTHORIZED_KEYS
value: |
<ssh-public-key-1>
<ssh-public-key-2>
ports:
- containerPort: 22
protocol: TCP
nodeSelector:
eks.amazonaws.com/nodegroup: dev
restartPolicy: Always
---
apiVersion: v1
kind: Service
metadata:
name: mysql-proxy
namespace: dev
spec:
ports:
- name: ssh
nodePort: 30022
port: 22
protocol: TCP
targetPort: 22
selector:
app: mysql-proxy
sessionAffinity: None
type: LoadBalancer
Once the service is reachable, open a local tunnel with SSH:
ssh -N -L 3306:<allowed-db-host>:3306 jump@<ssh-service-address> -p 30022 -i <private-key>
You can then connect your MySQL client to 127.0.0.1:3306.
AUTHORIZED_KEYS is not set.AUTHORIZED_DESTINATIONS can be forwarded to.Content type
Image
Digest
sha256:e4036c8bf…
Size
6.3 MB
Last updated
6 months ago
docker pull jmaitrehenry/ssh-tunnel