Sign inSign up

s4l3h1/ssh

By s4l3h1

•Updated about 1 year ago

OpenSSH Server with GitHub key integration

Image
0

1.7K

s4l3h1/ssh repository overview

⁠OpenSSH Server Docker Container

A configurable OpenSSH server Docker container with GitHub public key integration and dual port support.

⁠Features

  • Dual Port Support: Listens on ports 22 and 2222 simultaneously
  • GitHub Integration: Automatically fetches and configures public keys from GitHub users
  • Flexible Authentication: Supports both password and key-based authentication
  • Root Access: Secure root login with keys only (password prohibited)
  • Gateway Ports: Enabled for port forwarding capabilities

⁠Environment Variables

VariableDescriptionRequiredDefault
SSH_USERUsername for SSH accessYes-
SSH_PASSWORDPassword for SSH_USER (optional)No-
GITHUB_USERGitHub username to fetch public keysNo-

⁠Authentication Logic

  • If SSH_PASSWORD is provided: Password authentication enabled for SSH_USER
  • If SSH_PASSWORD is empty: Password authentication disabled
  • If GITHUB_USER is provided: Public keys fetched and added to both SSH_USER and root
  • Root login: Only allowed with public keys (password prohibited)
  • Startup fails if: Both SSH_PASSWORD is empty AND no GitHub public keys are found

⁠Quick Start

⁠Build the Image
docker build -t openssh-server .
⁠Run with Password Authentication
docker run -d \
  --name ssh-server \
  -p 2222:22 \
  -p 2223:2222 \
  -e SSH_USER=myuser \
  -e SSH_PASSWORD=mypassword \
  openssh-server
⁠Run with GitHub Keys Only
docker run -d \
  --name ssh-server \
  -p 2222:22 \
  -p 2223:2222 \
  -e SSH_USER=myuser \
  -e GITHUB_USER=your-github-username \
  openssh-server
⁠Run with Both Password and GitHub Keys
docker run -d \
  --name ssh-server \
  -p 2222:22 \
  -p 2223:2222 \
  -e SSH_USER=myuser \
  -e SSH_PASSWORD=mypassword \
  -e GITHUB_USER=your-github-username \
  openssh-server

⁠Connecting to the Server

⁠Connect as Regular User
# Using default port (22)
ssh myuser@localhost -p 2222

# Using custom port (2222)
ssh myuser@localhost -p 2223
⁠Connect as Root (GitHub keys required)
# Only works if GITHUB_USER was provided and has public keys
ssh root@localhost -p 2222

⁠File Structure

.
├── Dockerfile          # Main container definition
├── entrypoint.sh       # Container startup script
├── custom.conf         # SSH daemon configuration
└── README.md          # This file

⁠SSH Configuration

The container uses a modular SSH configuration approach:

  • Default config: Uses system default /etc/ssh/sshd_config
  • Custom config: Additional settings in /etc/ssh/sshd_config.d/custom.conf
  • Dynamic config: Password authentication setting added at runtime
⁠Custom SSH Settings
  • Port 2222 (in addition to default 22)
  • Root login with keys only (prohibit-password)
  • Public key authentication enabled
  • Gateway ports enabled for port forwarding

⁠Security Notes

  • Root password authentication is completely disabled
  • Container fails to start if no authentication method is available
  • GitHub public keys are fetched over HTTPS
  • SSH keys are properly secured with correct permissions (600/700)

⁠Troubleshooting

⁠Container Fails to Start

Check if at least one authentication method is configured:

docker logs ssh-server

Common issues:

  • SSH_USER not provided
  • Both SSH_PASSWORD empty and GITHUB_USER has no public keys
  • GitHub user doesn't exist or has no public keys
⁠Cannot Connect

Verify the container is running and ports are exposed:

docker ps
docker port ssh-server
⁠GitHub Keys Not Working

Check if the GitHub user has public keys:

curl https://github.com/your-username.keys

⁠Examples

⁠Development Setup
docker run -d \
  --name dev-ssh \
  -p 2222:22 \
  -e SSH_USER=developer \
  -e SSH_PASSWORD=devpass \
  -e GITHUB_USER=your-github-username \
  openssh-server
⁠Production Setup (Keys Only)
docker run -d \
  --name prod-ssh \
  --restart unless-stopped \
  -p 22:22 \
  -p 2222:2222 \
  -e SSH_USER=admin \
  -e GITHUB_USER=your-github-username \
  openssh-server

⁠License

This project is provided as-is for educational and development purposes.

Tag summary

Content type

Image

Digest

sha256:579c60e97…

Size

43.9 MB

Last updated

about 1 year ago

docker pull s4l3h1/ssh