sketch coreos
This commit is contained in:
Executable
+117
@@ -0,0 +1,117 @@
|
|||||||
|
variant: fcos
|
||||||
|
version: 1.6.0
|
||||||
|
# cirrus: 5001 admin sshd | 5002 sish SSH | 22,80,443 raw TCP -> k8s gateway
|
||||||
|
|
||||||
|
passwd:
|
||||||
|
users:
|
||||||
|
- name: core
|
||||||
|
ssh_authorized_keys:
|
||||||
|
- ssh-ed25519 AAAA_REPLACE_ADMIN_KEY admin
|
||||||
|
|
||||||
|
storage:
|
||||||
|
directories:
|
||||||
|
- path: /var/lib/sish/keys # sish host key, generated on first start
|
||||||
|
mode: 0700
|
||||||
|
user: { id: 65532 }
|
||||||
|
group: { id: 65532 }
|
||||||
|
files:
|
||||||
|
- path: /var/lib/sish/pubkeys/clients # k8s tunnel client keys (authorized_keys format)
|
||||||
|
mode: 0644
|
||||||
|
contents:
|
||||||
|
inline: |
|
||||||
|
ssh-ed25519 AAAA_REPLACE_CLIENT_KEY k8s-tunnel
|
||||||
|
- path: /etc/ssh/sshd_config.d/10-cirrus.conf
|
||||||
|
mode: 0644
|
||||||
|
contents:
|
||||||
|
|
||||||
|
inline: |
|
||||||
|
Port 5001
|
||||||
|
AuthenticationMethods publickey
|
||||||
|
PermitRootLogin no
|
||||||
|
AllowUsers core
|
||||||
|
- path: /etc/cirrus/sshd_port_5001.cil # 5001 is commplex_link_port_t
|
||||||
|
mode: 0644
|
||||||
|
contents:
|
||||||
|
inline: |
|
||||||
|
(allow sshd_t commplex_link_port_t (tcp_socket (name_bind)))
|
||||||
|
- path: /etc/containers/systemd/sish.container
|
||||||
|
mode: 0644
|
||||||
|
contents:
|
||||||
|
inline: |
|
||||||
|
[Unit]
|
||||||
|
Description=sish tunnel server
|
||||||
|
|
||||||
|
[Container]
|
||||||
|
ContainerName=sish
|
||||||
|
Image=ghcr.io/antoniomika/sish:v2.24.0
|
||||||
|
Network=host
|
||||||
|
User=65532
|
||||||
|
Group=65532
|
||||||
|
DropCapability=all
|
||||||
|
AddCapability=CAP_NET_BIND_SERVICE
|
||||||
|
NoNewPrivileges=true
|
||||||
|
ReadOnly=true
|
||||||
|
Volume=/var/lib/sish/keys:/keys:Z
|
||||||
|
Volume=/var/lib/sish/pubkeys:/pubkeys:ro,Z
|
||||||
|
Exec=--ssh-address=:5002 \
|
||||||
|
--domain=cirrus.example.com \
|
||||||
|
--private-keys-directory=/keys \
|
||||||
|
--authentication-keys-directory=/pubkeys \
|
||||||
|
--http-address=127.0.0.1:5080 \
|
||||||
|
--http-request-port-override=5080 \
|
||||||
|
--https-request-port-override=5080 \
|
||||||
|
--port-bind-range=22,80,443 \
|
||||||
|
--bind-random-ports=false \
|
||||||
|
--force-requested-ports=true \
|
||||||
|
--force-tcp-address=true \
|
||||||
|
--tcp-load-balancer=true \
|
||||||
|
--idle-connection=false \
|
||||||
|
--proxy-protocol=true \
|
||||||
|
--proxy-protocol-version=userdefined
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Restart=always
|
||||||
|
RestartSec=5
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
- path: /etc/sysconfig/nftables.conf
|
||||||
|
mode: 0600
|
||||||
|
overwrite: true
|
||||||
|
contents:
|
||||||
|
inline: |
|
||||||
|
table inet cirrus
|
||||||
|
delete table inet cirrus
|
||||||
|
table inet cirrus {
|
||||||
|
chain input {
|
||||||
|
type filter hook input priority filter; policy drop;
|
||||||
|
ct state established,related accept
|
||||||
|
ct state invalid drop
|
||||||
|
iif "lo" accept
|
||||||
|
meta l4proto { icmp, ipv6-icmp } accept
|
||||||
|
udp sport 67 udp dport 68 accept
|
||||||
|
ip6 saddr fe80::/10 udp sport 547 udp dport 546 accept
|
||||||
|
tcp dport { 22, 80, 443, 5001, 5002 } accept
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
systemd:
|
||||||
|
units:
|
||||||
|
- name: sshd-port-selinux.service
|
||||||
|
enabled: true
|
||||||
|
contents: |
|
||||||
|
[Unit]
|
||||||
|
Description=Allow sshd to bind 5001/tcp (SELinux)
|
||||||
|
Before=sshd.service
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=oneshot
|
||||||
|
RemainAfterExit=yes
|
||||||
|
ExecCondition=/bin/sh -c '! /usr/sbin/semodule -l | grep -qx sshd_port_5001'
|
||||||
|
ExecStart=/usr/sbin/semodule -i /etc/cirrus/sshd_port_5001.cil
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
|
- name: nftables.service
|
||||||
|
enabled: true
|
||||||
|
|
||||||
Reference in New Issue
Block a user