My idea was to build small docker container which will be acting as Linux jumpbox. This project is based on already exiting one https://github.com/warden/docker-jumpbox but it has been rewritten and size of image has been reduced.
This is just general guidance and you don't need to follow it step-by-step. You can user your own build image or use mine. Source code for this container can be find in GitHub repository https://github.com/monsoft/ssh-docker-jumpbox . There is more description there as well.
Create directory where 'authorized_keys' file will be stored. I use '/opt/jumpboxX':
$ sudo mkdir -p /opt/jumpbox1
Each user is authenticated by ssh key during login, and to be able to do it, specially 'crafted' file is required. It's like normal authorized_keys file but with username at the beginning. General file format is:
username:ssh_public_key
Created file need to be placed in previously created directory:
/opt/jumpbox1/authorized_keys
I prefer to use separated volume to store and preserver users local files.
$ docker volume create jumpbox1
When all previous setups are in place, start container:
$ docker run -d --name=jumpbox1 --hostname=jumpbox1 \
-e USERS="test1 test2" \
-v /opt/jumpbox1/authorized-keys:/etc/authorized-keys:ro \
-v jumpbox1:/home \
-p 1022:22 monsoft/ssh-jumpbox
As USERS variable, we passing usernames for which we created corresponding lines in authorized_keys file.
For redundancy/loadbalancing purpose this ssh-jumpbox can be deployed as Docker Stack on Swarm.
Open file 'ssh-jumpbox_compose.yml' in your favourite editor and place below lines into it
version: "3.2"
services:
ssh-jumpbox1:
image: monsoft/ssh-jumpbox
environment:
USERS: 'test1 test2"'
ports:
- "1022:22"
networks:
- jumpbox1
volumes:
- ssh-jumpbox1:/home
- /opt/jumpbox1/authorized-keys:/etc/authorized-keys
deploy:
mode: replicated
replicas: 2
volumes:
ssh-jumpbox1:
networks:
jumpbox1:
driver: overlay
attachable: true
To deploye ssh-jumpbox stack run below command
$ docker stack deploy -c ssh-jumpbox_compose.yml ssh-jumpbox-dev1
or if you build your own image and pushed it to private Docker Hub repository
$ docker stack deploy -c ssh-jumpbox_compose.yml ssh-jumpbox-dev1 --with-registry-auth
Content type
Image
Digest
Size
41 MB
Last updated
over 7 years ago
docker pull monsoft/ssh-jumpbox