Using AutoSSH for creating RemoteForward SSH tunnels into containers.
1.0K
This image can be used for tunneling traffic from a remote endpoint onto containers, using the SSH protocol, which can be very useful if you docker-node or even swarm is located behind NAT. Also this image can be used for "proxying" from a stack to an external service, through SSH.
For the setup to work, the sshd running on the remote server must be have the following enabled
GatewayPorts yes
And if tunneling of privileged ports (< 1024) it requires that the services logs in as root at the remote end, which requires the following configuration
PermitRootLogin yes
Login is done using keys, and the public key of the service must be added to the
authorized_keys file on the remote endpoint, for the user that is used for
login.
The public key that MUST be added to the remote endpoint is printed on container startup
Which ports should be tunneled is controlled by setting environment variables in the container.
TARGET - The target/remote endpoint on which to login.
Fx. [email protected]TARGET_PORT - The port on which the sshd is listening on the target-hostR_TUNNEL_* - All remote-forward-descriptions are converted into -R arguments
on the ssh connection. (Note names of R_TUNNEL_* variables MUST
be unique, but the suffix is not of importance)L_TUNNEL_* - All local-forward-descriptions are converted into -L arguments
on the ssh connection. (Note names of L_TUNNEL_* variables MUST bu unique,
but the suffix is not of importance)KEY_FILE - Can be used for overriding the name of the key to be generated or
to force autossh to use a specific key.KEY_ALGO - Can be used to override the algorithm used when generating a new
key, defaults to ed25519SSH_OPTS - Can be used for passing arguments directly to the ssh-client such
as -v for a bit of debugging.A single volume is defined in the container /root/.ssh this volume will hold
the generated pubic/private key-pair, as well as the config file that will
hold some general configuration.
It is also using this volume possible to move tunnel configuration away from
environment variables and store it in the config file using RemoteForward and
LocalForward
A small example of how this could be used id found here here
A special host-name can be used if connections to the host machine is required.
If the hostname docker.host is used, this will be substituted with the IP of
the Host machine (fetched from the default-route in the container).
Content type
Image
Digest
Size
4.7 MB
Last updated
almost 7 years ago
docker pull thorsager/auto-ssh-rtunnel