From 8688bd91d37804c8bd00d8c9655833fe87a6bd18 Mon Sep 17 00:00:00 2001 From: Philipp Traber Date: Mon, 5 Oct 2026 18:32:49 +0200 Subject: [PATCH] sketch coreos --- coreos/cirrus.yaml | 117 +++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 117 insertions(+) create mode 100755 coreos/cirrus.yaml diff --git a/coreos/cirrus.yaml b/coreos/cirrus.yaml new file mode 100755 index 0000000..842cf14 --- /dev/null +++ b/coreos/cirrus.yaml @@ -0,0 +1,117 @@ +variant: fcos +version: 1.6.0 +# cirrus: 5001 admin sshd | 5002 sish SSH | 22,80,443 raw TCP -> k8s gateway + +passwd: + users: + - name: core + ssh_authorized_keys: + - ssh-ed25519 AAAA_REPLACE_ADMIN_KEY admin + +storage: + directories: + - path: /var/lib/sish/keys # sish host key, generated on first start + mode: 0700 + user: { id: 65532 } + group: { id: 65532 } + files: + - path: /var/lib/sish/pubkeys/clients # k8s tunnel client keys (authorized_keys format) + mode: 0644 + contents: + inline: | + ssh-ed25519 AAAA_REPLACE_CLIENT_KEY k8s-tunnel + - path: /etc/ssh/sshd_config.d/10-cirrus.conf + mode: 0644 + contents: + + inline: | + Port 5001 + AuthenticationMethods publickey + PermitRootLogin no + AllowUsers core + - path: /etc/cirrus/sshd_port_5001.cil # 5001 is commplex_link_port_t + mode: 0644 + contents: + inline: | + (allow sshd_t commplex_link_port_t (tcp_socket (name_bind))) + - path: /etc/containers/systemd/sish.container + mode: 0644 + contents: + inline: | + [Unit] + Description=sish tunnel server + + [Container] + ContainerName=sish + Image=ghcr.io/antoniomika/sish:v2.24.0 + Network=host + User=65532 + Group=65532 + DropCapability=all + AddCapability=CAP_NET_BIND_SERVICE + NoNewPrivileges=true + ReadOnly=true + Volume=/var/lib/sish/keys:/keys:Z + Volume=/var/lib/sish/pubkeys:/pubkeys:ro,Z + Exec=--ssh-address=:5002 \ + --domain=cirrus.example.com \ + --private-keys-directory=/keys \ + --authentication-keys-directory=/pubkeys \ + --http-address=127.0.0.1:5080 \ + --http-request-port-override=5080 \ + --https-request-port-override=5080 \ + --port-bind-range=22,80,443 \ + --bind-random-ports=false \ + --force-requested-ports=true \ + --force-tcp-address=true \ + --tcp-load-balancer=true \ + --idle-connection=false \ + --proxy-protocol=true \ + --proxy-protocol-version=userdefined + + [Service] + Restart=always + RestartSec=5 + + [Install] + WantedBy=multi-user.target + - path: /etc/sysconfig/nftables.conf + mode: 0600 + overwrite: true + contents: + inline: | + table inet cirrus + delete table inet cirrus + table inet cirrus { + chain input { + type filter hook input priority filter; policy drop; + ct state established,related accept + ct state invalid drop + iif "lo" accept + meta l4proto { icmp, ipv6-icmp } accept + udp sport 67 udp dport 68 accept + ip6 saddr fe80::/10 udp sport 547 udp dport 546 accept + tcp dport { 22, 80, 443, 5001, 5002 } accept + } + } + +systemd: + units: + - name: sshd-port-selinux.service + enabled: true + contents: | + [Unit] + Description=Allow sshd to bind 5001/tcp (SELinux) + Before=sshd.service + + [Service] + Type=oneshot + RemainAfterExit=yes + ExecCondition=/bin/sh -c '! /usr/sbin/semodule -l | grep -qx sshd_port_5001' + ExecStart=/usr/sbin/semodule -i /etc/cirrus/sshd_port_5001.cil + + [Install] + WantedBy=multi-user.target + - name: nftables.service + enabled: true +