Very clean alpine image with openssh installed. Can be used to create tunnels into Kubernetes
406
This image was created with the specific purpose of running inside Kubernetes (more specifically self hosted bare metal clusters) and to assist with creating ssh tunnels from outside a Kubernetes cluster into it. Mostly for admin or development purposes.
For instance, if you have a database running inside Kubernetes and you have an admin tool that you (or other people) want to connect to it from the internet, but you don't want to expose your database through a service with externalIPs, and you also don't want to give other people kubectl access to your cluster. Then, you can expose this container instead on an externalIPs and use it as a security gate into the cluster, using different users, passwords and keys to provide additional access level control.
You can deploy this container in the Kubernetes dashboard namespace using the following yaml
apiVersion: v1
kind: Service
metadata:
name: ssh
namespace: kubernetes-dashboard
spec:
# put the list of external IPs below of your kubernetes nodes
externalIPs:
- 1.2.3.4
selector:
app: ssh
ports:
- protocol: TCP
port: 6922
targetPort: 22
---
kind: PersistentVolumeClaim
apiVersion: v1
metadata:
name: ssh
namespace: kubernetes-dashboard
finalizers:
- kubernetes.io/pvc-protection
spec:
accessModes:
- ReadWriteOnce
resources:
requests:
storage: 1Gi
volumeMode: Filesystem
---
kind: Deployment
apiVersion: apps/v1
metadata:
name: ssh
namespace: kubernetes-dashboard
labels:
app: ssh
spec:
replicas: 1
selector:
matchLabels:
app: ssh
template:
metadata:
labels:
app: ssh
spec:
volumes:
- name: ssh
persistentVolumeClaim:
claimName: ssh
containers:
- name: ssh
image: techss/sshd:latest
imagePullPolicy: Always
securityContext:
privileged: true
volumeMounts:
- name: ssh
mountPath: /data
You have to mount a volume to /data to keep things persistent.
After the first startup you need to exec into the container and copy the file /data_startup.sh to the /data folder as startup.sh like so:
cp /startup.sh /data/startup.sh
When the container starts for the first time it would have generated all the needed ssh keys for you in /etc/ssh. And we want to keep things persistant by copying all of them to the /data folder like so:
cp -r /etc/ssh /data/etc-ssh
You can edit that /data/startup.sh file to add user's with passwords. Simply duplicate the lines starting with 'adduser' and 'echo' to add users and set their passwords.
Afterwards the container will have to be restarted in order for the new users to take effect.
Content type
Image
Digest
sha256:9acdabd8f…
Size
17.3 MB
Last updated
over 2 years ago
docker pull techss/sshd