48 lines
2.4 KiB
Markdown
48 lines
2.4 KiB
Markdown
# sish-client
|
|
|
|
Opens SSH reverse tunnels to a [sish](https://github.com/antoniomika/sish) edge and reconnects
|
|
every 5s when the session drops. Image: `registry.traberph.de/public/sish-client`.
|
|
|
|
```sh
|
|
docker run -d --read-only --tmpfs /tmp \
|
|
-e SISH_HOST=edge.example.com \
|
|
-e SISH_HOST_KEY="ssh-ed25519 AAAA..." \
|
|
-e SISH_ROUTES="app.example.com:443=app:8443" \
|
|
-v ./id_ed25519:/secrets/id_ed25519:ro \
|
|
registry.traberph.de/public/sish-client:latest
|
|
```
|
|
|
|
| Variable | Default | |
|
|
|---|---|---|
|
|
| `SISH_HOST` | *required* | Edge host |
|
|
| `SISH_HOST_KEY` | *required* | Edge host key, `"<type> <base64>"` (first two fields of its `.pub` file) |
|
|
| `SISH_ROUTES` | *required* | Comma-separated `host:bind-port=target:port` |
|
|
| `SISH_PORT` | `2222` | sish SSH port |
|
|
| `SISH_KEY_FILE` | `/secrets/id_ed25519` | Private key |
|
|
| `SISH_SNI_PROXY` | `true` | `true`: sish routes by SNI and passes TLS through. `false`: HTTP routing by `Host` header |
|
|
| `SISH_PROXY_PROTOCOL` | `2` | PROXY header sent to the target: `1`, `2` or `off` |
|
|
|
|
HTTP (:80) routes need `SISH_SNI_PROXY=false` and a separate instance from SNI (:443) routes.
|
|
If sish rejects any route, the session fails and is retried, so a bad route shows up in the logs.
|
|
|
|
## Requirements
|
|
|
|
- `/tmp` must be writable (e.g. a memory `emptyDir`), the root filesystem can be read-only.
|
|
- Run as uid `65534` (the image default). ssh refuses to start for uids missing from `/etc/passwd`.
|
|
- The key file must be readable by uid 65534, e.g. a Secret volume with `defaultMode: 0440`
|
|
and `fsGroup: 65534`. ssh rejects keys owned by 65534 that others can read.
|
|
|
|
## Security
|
|
|
|
- The edge is authenticated only by `SISH_HOST_KEY`. There is no trust-on-first-use and no
|
|
fallback: a wrong or missing key fails the connection.
|
|
- All ssh_config files are ignored (`-F /dev/null`). Agent and X11 forwarding are off, so the
|
|
edge can only open connections to the configured route targets.
|
|
- **PROXY protocol:** the target trusts the PROXY header for the client IP. It must only accept
|
|
PROXY connections from this client (e.g. listen on `127.0.0.1` in the sidecar and set trusted
|
|
IPs), otherwise anything that can reach that port can spoof client IPs. If the target does not
|
|
expect a PROXY header, set `SISH_PROXY_PROTOCOL=off`.
|
|
- Whoever controls the edge sees HTTP traffic, and with `SISH_SNI_PROXY=true` still sees the
|
|
SNI hostnames and client IPs, but not TLS contents.
|
|
- The base image follows `alpine:3`. Rebuild regularly to pick up OpenSSH fixes.
|