Sign inSign up

vincentycyao/base

By vincentycyao

•Updated 5 months ago

Image
0

139

vincentycyao/base repository overview

⁠vincentycyao/base:ssh

šŸ™ Dockerfile⁠

This container provides a fully featured Ubuntu 20.04 development environment with SSH access, Miniconda, Git/Git-LFS, build tools, and optional VS Code CLI support. It is designed for interactive development, remote debugging, and running long-lived dev pods in Kubernetes. The image automatically launches an SSH server and supports password-less authentication via mounted authorized_keys.

⁠✨ Features

  • Ubuntu 20.04 base OS
  • Preinstalled: git, git-lfs, vim, curl, wget, build-essential, OpenMPI
  • SSH server enabled (root login allowed via public key only)
  • Miniconda installed under /root/Documents/Tools/miniconda
  • Custom tools under /root/Documents/Tools/bin
  • šŸ”„ VS Code Remote CLI support
    # Setup ssh tunnel via VSCode
    code tunnel
    
  • Fish shell included
  • Designed for long-running interactive sessions (sleep infinity, tail -f /dev/null)
  • Suitable for Kubernetes dev pods or local testing via Docker

ā šŸš€ Pull the image

docker pull vincentycyao/base:ssh

⁠🧪 Running the Container (Local Docker)

This is to test the password-less SSH access with key authentication.

# Suppose your public key is ~/.ssh/id_rsa.pub
docker run -d \
  --name dev-container \
  --platform linux/amd64 \
  -p 2222:22 \
  -v $HOME/.ssh/id_rsa.pub:/root/.ssh/authorized_keys \
  vincentycyao/base:ssh
  • forward port 2222 → 22 using -p 2222:22 so you can SSH into the container from your host machine.
  • You'll also need to mount your public key into the container at /root/.ssh/authorized_keys to enable password-less SSH access.

Test the SSH port forwarding:

# root is the user name in the container, do not change
ssh -p 2222 root@localhost

or

# Check port info
lsof -i :2222

ā ā˜ļø Running in Kubernetes (interactive dev pod)

This section explains how to create a Kubernetes pod, setup port-forwarding on the headnode of the cluster, establish ssh connection from a local machine to the pod. The traffic flow:

your laptop (ssh to pod)  →  localhost:2222
  │
  └─ head‑node forwards to its own localhost:2222
    │
    └─ kubectl port‑forward forwards to pod:22 (sshd)
⁠1. Create a Kubernetes Secret with your local machine's public key.

First, base64-encode your local machine’s SSH public key:

echo -n <your-local-machine-public-key> | base64

Create a YAML file (e.g. ssh-public-key.yaml) using the output:

apiVersion: v1
kind: Secret
metadata:
  name: ssh-public-key
type: Opaque
data:
  authorized_keys: <BASE64_ENCODED_PUBLIC_KEY>

Apply the secret to the cluster:

kubectl apply -f ssh-public-key.yaml
⁠2. Deploy the Pod (or Deployment) that mounts the secret

Create a yaml file:

apiVersion: v1
kind: Pod
metadata:
  name: dev-ssh
spec:
  containers:
  - name: dev-ssh
    image: vincentycyao/base:ssh
    command: ["bash", "-lc", "service ssh start && sleep infinity"]
    ports:
    - containerPort: 22
    volumeMounts:
    - mountPath: /root/.ssh/authorized_keys
      name: ssh-key
      subPath: authorized_keys
      readOnly: true
  volumes:
  - name: ssh-key
    secret:
      secretName: ssh-public-key

Apply

kubectl apply -f pod.yaml
⁠3. Port-forward in the k8s cluster headnode
# (In the headnode)
# Replace <pod-name>
# 22 is the listening port in the container
# 2222 can be changed to any free port
kubectl port-forward pod/<pod-name> 2222:22
  • Expose the pod’s SSH port (22) to the headnode on port 2222
⁠4. Port‑forward from the your local machine to the k8s headnode
# (In the local machine)
# Replace <user>, <headnode>
# 2222 can be changed to any free port
# The first 2222 is the port on the local machine
# The second 2222 is the port on the headnode
ssh -N -L 2222:localhost:2222 <user>@<headnode>
  • Tunnel your local port 2222 to the headnode’s port 2222
⁠Connect to the pod from a local machine
# (In a local terminal or IDE)
# root is the username in the container, do not change
ssh -p 2222 root@localhost

Tag summary

Content type

Image

Digest

sha256:99e574983…

Size

596.1 MB

Last updated

10 months ago

docker pull vincentycyao/base:ssh