Sign inSign up

jmaitrehenry/ssh-tunnel

By jmaitrehenry

•Updated 6 months ago

SSH server allowing authenticated users to open TCP forwards only to approved destinations

Image
0

947

jmaitrehenry/ssh-tunnel repository overview

⁠SSH tunnel container

This image runs an SSH server that allows authenticated users to open TCP forwards only to explicitly authorized destinations. It is useful as a small jump host in Kubernetes for reaching internal services such as MySQL.

⁠What it does

  • Starts sshd on port 22
  • Creates a jump user for SSH access
  • Loads public keys from AUTHORIZED_KEYS
  • Restricts SSH port forwarding with PermitOpen using AUTHORIZED_DESTINATIONS

⁠Required environment variables

VariableDescription
AUTHORIZED_KEYSOne or more SSH public keys, separated by newlines.
AUTHORIZED_DESTINATIONSSpace-separated list of allowed host:port destinations for TCP forwarding.

Example:

AUTHORIZED_DESTINATIONS="db-a.internal:3306 db-b.internal:3306"

⁠Docker Compose example

Replace the placeholders with your own image tag, allowed destinations, and public SSH keys.

services:
  ssh-tunnel:
    image: kumojin/ssh-server:1.0.0
    container_name: ssh-tunnel
    ports:
      - "2222:22"
    environment:
      AUTHORIZED_DESTINATIONS: "<db-host-1>:3306 <db-host-2>:3306"
      AUTHORIZED_KEYS: |
        <ssh-public-key-1>
        <ssh-public-key-2>

Then connect through the published SSH port:

ssh -N -L 3306:<allowed-db-host>:3306 [email protected] -p 2222 -i <private-key>

⁠Kubernetes example

Replace the placeholders with your own image tag, allowed destinations, and public SSH keys.

apiVersion: apps/v1
kind: Deployment
metadata:
  labels:
    name: mysql-proxy
  name: mysql-proxy
  namespace: dev
spec:
  replicas: 1
  selector:
    matchLabels:
      app: mysql-proxy
  template:
    metadata:
      labels:
        app: mysql-proxy
    spec:
      containers:
        - image: kumojin/ssh-server:1.0.0
          name: mysql-proxy
          env:
            - name: AUTHORIZED_DESTINATIONS
              value: "<db-host-1>:3306 <db-host-2>:3306 <db-host-3>:3306"
            - name: AUTHORIZED_KEYS
              value: |
                <ssh-public-key-1>
                <ssh-public-key-2>
          ports:
            - containerPort: 22
              protocol: TCP
      nodeSelector:
        eks.amazonaws.com/nodegroup: dev
      restartPolicy: Always
---
apiVersion: v1
kind: Service
metadata:
  name: mysql-proxy
  namespace: dev
spec:
  ports:
    - name: ssh
      nodePort: 30022
      port: 22
      protocol: TCP
      targetPort: 22
  selector:
    app: mysql-proxy
  sessionAffinity: None
  type: LoadBalancer

⁠Connecting through the tunnel

Once the service is reachable, open a local tunnel with SSH:

ssh -N -L 3306:<allowed-db-host>:3306 jump@<ssh-service-address> -p 30022 -i <private-key>

You can then connect your MySQL client to 127.0.0.1:3306.

⁠Notes

  • The container exits if AUTHORIZED_KEYS is not set.
  • Only destinations listed in AUTHORIZED_DESTINATIONS can be forwarded to.
  • The image is intended for TCP forwarding, not for interactive shell access.

Tag summary

Content type

Image

Digest

sha256:e4036c8bf…

Size

6.3 MB

Last updated

6 months ago

docker pull jmaitrehenry/ssh-tunnel