Sign inSign up

techss/sshd

By techss

•Updated over 2 years ago

Very clean alpine image with openssh installed. Can be used to create tunnels into Kubernetes

Image
0

406

techss/sshd repository overview

⁠What's the purpose

This image was created with the specific purpose of running inside Kubernetes (more specifically self hosted bare metal clusters) and to assist with creating ssh tunnels from outside a Kubernetes cluster into it. Mostly for admin or development purposes.

For instance, if you have a database running inside Kubernetes and you have an admin tool that you (or other people) want to connect to it from the internet, but you don't want to expose your database through a service with externalIPs, and you also don't want to give other people kubectl access to your cluster. Then, you can expose this container instead on an externalIPs and use it as a security gate into the cluster, using different users, passwords and keys to provide additional access level control.

⁠Starting the container

You can deploy this container in the Kubernetes dashboard namespace using the following yaml

apiVersion: v1
kind: Service
metadata:
  name: ssh
  namespace: kubernetes-dashboard
spec:
  # put the list of external IPs below of your kubernetes nodes
  externalIPs:
    - 1.2.3.4
  selector:
    app: ssh
  ports:
    - protocol: TCP
      port: 6922
      targetPort: 22
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
  name: ssh
  namespace: kubernetes-dashboard
  finalizers:
    - kubernetes.io/pvc-protection
spec:
  accessModes:
    - ReadWriteOnce
  resources:
    requests:
      storage: 1Gi
  volumeMode: Filesystem

---
kind: Deployment
apiVersion: apps/v1
metadata:
  name: ssh
  namespace: kubernetes-dashboard
  labels:
    app: ssh
spec:
  replicas: 1
  selector:
    matchLabels:
      app: ssh
  template:
    metadata:
      labels:
        app: ssh
    spec:
      volumes:
        - name: ssh
          persistentVolumeClaim:
            claimName: ssh
      containers:
        - name: ssh
          image: techss/sshd:latest
          imagePullPolicy: Always
          securityContext:
            privileged: true
          volumeMounts:
            - name: ssh
              mountPath: /data

⁠After first startup

You have to mount a volume to /data to keep things persistent.

After the first startup you need to exec into the container and copy the file /data_startup.sh to the /data folder as startup.sh like so:

cp /startup.sh /data/startup.sh

When the container starts for the first time it would have generated all the needed ssh keys for you in /etc/ssh. And we want to keep things persistant by copying all of them to the /data folder like so:

cp -r /etc/ssh /data/etc-ssh

You can edit that /data/startup.sh file to add user's with passwords. Simply duplicate the lines starting with 'adduser' and 'echo' to add users and set their passwords.

Afterwards the container will have to be restarted in order for the new users to take effect.

Tag summary

Content type

Image

Digest

sha256:9acdabd8f…

Size

17.3 MB

Last updated

over 2 years ago

docker pull techss/sshd