SFTP Server within a Docker container
418

This is an Debian based image, which installs the very minimum needed to run an SFTP server.
Each SFTP user gets a user account within the container. No account within the
container gets any passwords set, so the only ways to access the container are
using docker exec, or via the SSH server listening on port 22.
The SSH server is configured to require public key authentication for all
logins, and all logins are restricted to sftp only. Additionally, each login
is chroot'ed to a directory containing only the user's SFTP files and
authorized_keys file.
Basically there's multiple layers of protection to make exposing this as an Internet facing service as safe as possible. Usual disclaimers apply about taking responsibility for your own security.
docker run -d --name sftp -p 2222:22 -v /var/sftp:/data semhoun/sftp
services:
sftp:
container_name: sftp
ports:
- 2222:22
volumes:
- /var/sftp:/data
image: semhoun/sftp
Manage users by creating a file in /var/sftp/users/<username>.pub -
the file should contain a public key per line (e.g. exactly like an
authorized_keys file). The owner UID of the file will be the uid of the user
within the container. Files owned by root will be ignored.
The files are polled for changes roughly every 5 minutes.
The SFTP files are created within /data/userdata/<username>/sftp
/data volumeThe /data volume is structured specifically to support the OpenSSH server
chroot approach, as well as containing other persistence data.
/data/serverThis holds the RSA and ECDSA keys for the SSH server.
/data/usersThis is intended to be managed from outside the container. It contains a file
per user, and is polled by the container to grant or deny access. Files should
have a .pub suffix.
.pub) defines the
usernameCaution: You need to make sure that each UID is unique, or undefined things will happen within the container.
/data/userdata/<username>A directory for each configured user, which is owned by root. This becomes the chroot directory for the logged in user.
/data/userdata/<username>/authorized_keysThe authorized_keys file for the specified user.
/data/userdata/<username>/sftpThe directory within the chroot that the internal-sftp subsystem is
instructed to use as the sftp-root. It's owned by the uid allocated to the
user, with a group of 1001 ("sftpusers" internally).
This is where the data that the user actually uploads ends up.
Content type
Image
Digest
sha256:fd76e4c2f…
Size
55.6 MB
Last updated
about 2 years ago
docker pull semhoun/sftp