vincentycyao/base:sshš Dockerfileā
This container provides a fully featured Ubuntu 20.04 development environment with SSH access, Miniconda, Git/Git-LFS, build tools, and optional VS Code CLI support. It is designed for interactive development, remote debugging, and running long-lived dev pods in Kubernetes. The image automatically launches an SSH server and supports password-less authentication via mounted authorized_keys.
git, git-lfs, vim, curl, wget, build-essential, OpenMPI/root/Documents/Tools/miniconda/root/Documents/Tools/bin# Setup ssh tunnel via VSCode
code tunnel
sleep infinity, tail -f /dev/null)docker pull vincentycyao/base:ssh
This is to test the password-less SSH access with key authentication.
# Suppose your public key is ~/.ssh/id_rsa.pub
docker run -d \
--name dev-container \
--platform linux/amd64 \
-p 2222:22 \
-v $HOME/.ssh/id_rsa.pub:/root/.ssh/authorized_keys \
vincentycyao/base:ssh
-p 2222:22 so you can SSH into the container from your host machine./root/.ssh/authorized_keys to enable password-less SSH access.Test the SSH port forwarding:
# root is the user name in the container, do not change
ssh -p 2222 root@localhost
or
# Check port info
lsof -i :2222
This section explains how to create a Kubernetes pod, setup port-forwarding on the headnode of the cluster, establish ssh connection from a local machine to the pod. The traffic flow:
your laptop (ssh to pod) ā localhost:2222
ā
āā headānode forwards to its own localhost:2222
ā
āā kubectl portāforward forwards to pod:22 (sshd)
First, base64-encode your local machineās SSH public key:
echo -n <your-local-machine-public-key> | base64
Create a YAML file (e.g. ssh-public-key.yaml) using the output:
apiVersion: v1
kind: Secret
metadata:
name: ssh-public-key
type: Opaque
data:
authorized_keys: <BASE64_ENCODED_PUBLIC_KEY>
Apply the secret to the cluster:
kubectl apply -f ssh-public-key.yaml
Create a yaml file:
apiVersion: v1
kind: Pod
metadata:
name: dev-ssh
spec:
containers:
- name: dev-ssh
image: vincentycyao/base:ssh
command: ["bash", "-lc", "service ssh start && sleep infinity"]
ports:
- containerPort: 22
volumeMounts:
- mountPath: /root/.ssh/authorized_keys
name: ssh-key
subPath: authorized_keys
readOnly: true
volumes:
- name: ssh-key
secret:
secretName: ssh-public-key
Apply
kubectl apply -f pod.yaml
# (In the headnode)
# Replace <pod-name>
# 22 is the listening port in the container
# 2222 can be changed to any free port
kubectl port-forward pod/<pod-name> 2222:22
# (In the local machine)
# Replace <user>, <headnode>
# 2222 can be changed to any free port
# The first 2222 is the port on the local machine
# The second 2222 is the port on the headnode
ssh -N -L 2222:localhost:2222 <user>@<headnode>
# (In a local terminal or IDE)
# root is the username in the container, do not change
ssh -p 2222 root@localhost
Content type
Image
Digest
sha256:99e574983ā¦
Size
596.1 MB
Last updated
10 months ago
docker pull vincentycyao/base:ssh