sketch coreos
This commit is contained in:
Executable
+117
@@ -0,0 +1,117 @@
|
||||
variant: fcos
|
||||
version: 1.6.0
|
||||
# cirrus: 5001 admin sshd | 5002 sish SSH | 22,80,443 raw TCP -> k8s gateway
|
||||
|
||||
passwd:
|
||||
users:
|
||||
- name: core
|
||||
ssh_authorized_keys:
|
||||
- ssh-ed25519 AAAA_REPLACE_ADMIN_KEY admin
|
||||
|
||||
storage:
|
||||
directories:
|
||||
- path: /var/lib/sish/keys # sish host key, generated on first start
|
||||
mode: 0700
|
||||
user: { id: 65532 }
|
||||
group: { id: 65532 }
|
||||
files:
|
||||
- path: /var/lib/sish/pubkeys/clients # k8s tunnel client keys (authorized_keys format)
|
||||
mode: 0644
|
||||
contents:
|
||||
inline: |
|
||||
ssh-ed25519 AAAA_REPLACE_CLIENT_KEY k8s-tunnel
|
||||
- path: /etc/ssh/sshd_config.d/10-cirrus.conf
|
||||
mode: 0644
|
||||
contents:
|
||||
|
||||
inline: |
|
||||
Port 5001
|
||||
AuthenticationMethods publickey
|
||||
PermitRootLogin no
|
||||
AllowUsers core
|
||||
- path: /etc/cirrus/sshd_port_5001.cil # 5001 is commplex_link_port_t
|
||||
mode: 0644
|
||||
contents:
|
||||
inline: |
|
||||
(allow sshd_t commplex_link_port_t (tcp_socket (name_bind)))
|
||||
- path: /etc/containers/systemd/sish.container
|
||||
mode: 0644
|
||||
contents:
|
||||
inline: |
|
||||
[Unit]
|
||||
Description=sish tunnel server
|
||||
|
||||
[Container]
|
||||
ContainerName=sish
|
||||
Image=ghcr.io/antoniomika/sish:v2.24.0
|
||||
Network=host
|
||||
User=65532
|
||||
Group=65532
|
||||
DropCapability=all
|
||||
AddCapability=CAP_NET_BIND_SERVICE
|
||||
NoNewPrivileges=true
|
||||
ReadOnly=true
|
||||
Volume=/var/lib/sish/keys:/keys:Z
|
||||
Volume=/var/lib/sish/pubkeys:/pubkeys:ro,Z
|
||||
Exec=--ssh-address=:5002 \
|
||||
--domain=cirrus.example.com \
|
||||
--private-keys-directory=/keys \
|
||||
--authentication-keys-directory=/pubkeys \
|
||||
--http-address=127.0.0.1:5080 \
|
||||
--http-request-port-override=5080 \
|
||||
--https-request-port-override=5080 \
|
||||
--port-bind-range=22,80,443 \
|
||||
--bind-random-ports=false \
|
||||
--force-requested-ports=true \
|
||||
--force-tcp-address=true \
|
||||
--tcp-load-balancer=true \
|
||||
--idle-connection=false \
|
||||
--proxy-protocol=true \
|
||||
--proxy-protocol-version=userdefined
|
||||
|
||||
[Service]
|
||||
Restart=always
|
||||
RestartSec=5
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
- path: /etc/sysconfig/nftables.conf
|
||||
mode: 0600
|
||||
overwrite: true
|
||||
contents:
|
||||
inline: |
|
||||
table inet cirrus
|
||||
delete table inet cirrus
|
||||
table inet cirrus {
|
||||
chain input {
|
||||
type filter hook input priority filter; policy drop;
|
||||
ct state established,related accept
|
||||
ct state invalid drop
|
||||
iif "lo" accept
|
||||
meta l4proto { icmp, ipv6-icmp } accept
|
||||
udp sport 67 udp dport 68 accept
|
||||
ip6 saddr fe80::/10 udp sport 547 udp dport 546 accept
|
||||
tcp dport { 22, 80, 443, 5001, 5002 } accept
|
||||
}
|
||||
}
|
||||
|
||||
systemd:
|
||||
units:
|
||||
- name: sshd-port-selinux.service
|
||||
enabled: true
|
||||
contents: |
|
||||
[Unit]
|
||||
Description=Allow sshd to bind 5001/tcp (SELinux)
|
||||
Before=sshd.service
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
RemainAfterExit=yes
|
||||
ExecCondition=/bin/sh -c '! /usr/sbin/semodule -l | grep -qx sshd_port_5001'
|
||||
ExecStart=/usr/sbin/semodule -i /etc/cirrus/sshd_port_5001.cil
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
- name: nftables.service
|
||||
enabled: true
|
||||
|
||||
Reference in New Issue
Block a user