dd1b847a05fc025a114a036e4404b9dd308d549d
sish-client
Opens SSH reverse tunnels to a sish edge and reconnects
every 5s when the session drops. Image: registry.traberph.de/public/sish-client.
docker run -d --read-only --tmpfs /tmp \
-e SISH_HOST=edge.example.com \
-e SISH_HOST_KEY="ssh-ed25519 AAAA..." \
-e SISH_ROUTES="app.example.com:443=app:8443" \
-v ./id_ed25519:/secrets/id_ed25519:ro \
registry.traberph.de/public/sish-client:latest
| Variable | Default | |
|---|---|---|
SISH_HOST |
required | Edge host |
SISH_HOST_KEY |
required | Edge host key, "<type> <base64>" (first two fields of its .pub file) |
SISH_ROUTES |
required | Comma-separated host:bind-port=target:port |
SISH_PORT |
2222 |
sish SSH port |
SISH_KEY_FILE |
/secrets/id_ed25519 |
Private key |
SISH_SNI_PROXY |
true |
true: sish routes by SNI and passes TLS through. false: HTTP routing by Host header |
SISH_PROXY_PROTOCOL |
2 |
PROXY header sent to the target: 1, 2 or off |
HTTP (:80) routes need SISH_SNI_PROXY=false and a separate instance from SNI (:443) routes.
If sish rejects any route, the session fails and is retried, so a bad route shows up in the logs.
Requirements
/tmpmust be writable (e.g. a memoryemptyDir), the root filesystem can be read-only.- Run as uid
65534(the image default). ssh refuses to start for uids missing from/etc/passwd. - The key file must be readable by uid 65534, e.g. a Secret volume with
defaultMode: 0440andfsGroup: 65534. ssh rejects keys owned by 65534 that others can read.
Security
- The edge is authenticated only by
SISH_HOST_KEY. There is no trust-on-first-use and no fallback: a wrong or missing key fails the connection. - All ssh_config files are ignored (
-F /dev/null). Agent and X11 forwarding are off, so the edge can only open connections to the configured route targets. - PROXY protocol: the target trusts the PROXY header for the client IP. It must only accept
PROXY connections from this client (e.g. listen on
127.0.0.1in the sidecar and set trusted IPs), otherwise anything that can reach that port can spoof client IPs. If the target does not expect a PROXY header, setSISH_PROXY_PROTOCOL=off. - Whoever controls the edge sees HTTP traffic, and with
SISH_SNI_PROXY=truestill sees the SNI hostnames and client IPs, but not TLS contents. - The base image follows
alpine:3. Rebuild regularly to pick up OpenSSH fixes.
Languages
Shell
86.1%
Dockerfile
13.9%