Provides a limited SSH access through which only the SSH port forwarding works.
1.2K
Sometimes it is necessary to use SSH tunneling to access a web service on a specific port that is blocked by a firewall or router. You could create just a new SSH user on your Linux server, but this user will be able to execute all server commands although they would not be necessary for SSH tunneling. In fact the only thing the user needs is to log-in and log-out again – that’s enough! Therefore we don’t want the user to be able to do anything else for security reasons.
In order to keep the service pinned to the desired node as its data volumes, we need to set node labels.
$ docker node update \
--label-add sshtunnel=true \
{node-name}
Create a storage for permanently storing the .ssh data.
$ docker volume create \
--name sshtunnel
Create a service.
$ docker service create \
--name sshtunnel \
--publish 2222:22 \
--network {mynetwork} \
--constraint node.labels.sshtunnel==true \
--mount type=volume,source=sshtunnel,destination=/home/sshtunnel/.ssh \
xpepermint/sshtunnel
Move to the volume path and edit the authorized_keys file. Add as many user keys as you like.
Content type
Image
Digest
Size
85.5 MB
Last updated
about 9 years ago
docker pull xpepermint/sshtunnel