Files
sish-client/README.md
T
traberph dd1b847a05
build / image (push) Successful in 35s
cleanup
2026-09-27 09:52:12 +02:00

2.4 KiB

sish-client

Opens SSH reverse tunnels to a sish edge and reconnects every 5s when the session drops. Image: registry.traberph.de/public/sish-client.

docker run -d --read-only --tmpfs /tmp \
  -e SISH_HOST=edge.example.com \
  -e SISH_HOST_KEY="ssh-ed25519 AAAA..." \
  -e SISH_ROUTES="app.example.com:443=app:8443" \
  -v ./id_ed25519:/secrets/id_ed25519:ro \
  registry.traberph.de/public/sish-client:latest
Variable Default
SISH_HOST required Edge host
SISH_HOST_KEY required Edge host key, "<type> <base64>" (first two fields of its .pub file)
SISH_ROUTES required Comma-separated host:bind-port=target:port
SISH_PORT 2222 sish SSH port
SISH_KEY_FILE /secrets/id_ed25519 Private key
SISH_SNI_PROXY true true: sish routes by SNI and passes TLS through. false: HTTP routing by Host header
SISH_PROXY_PROTOCOL 2 PROXY header sent to the target: 1, 2 or off

HTTP (:80) routes need SISH_SNI_PROXY=false and a separate instance from SNI (:443) routes. If sish rejects any route, the session fails and is retried, so a bad route shows up in the logs.

Requirements

  • /tmp must be writable (e.g. a memory emptyDir), the root filesystem can be read-only.
  • Run as uid 65534 (the image default). ssh refuses to start for uids missing from /etc/passwd.
  • The key file must be readable by uid 65534, e.g. a Secret volume with defaultMode: 0440 and fsGroup: 65534. ssh rejects keys owned by 65534 that others can read.

Security

  • The edge is authenticated only by SISH_HOST_KEY. There is no trust-on-first-use and no fallback: a wrong or missing key fails the connection.
  • All ssh_config files are ignored (-F /dev/null). Agent and X11 forwarding are off, so the edge can only open connections to the configured route targets.
  • PROXY protocol: the target trusts the PROXY header for the client IP. It must only accept PROXY connections from this client (e.g. listen on 127.0.0.1 in the sidecar and set trusted IPs), otherwise anything that can reach that port can spoof client IPs. If the target does not expect a PROXY header, set SISH_PROXY_PROTOCOL=off.
  • Whoever controls the edge sees HTTP traffic, and with SISH_SNI_PROXY=true still sees the SNI hostnames and client IPs, but not TLS contents.
  • The base image follows alpine:3. Rebuild regularly to pick up OpenSSH fixes.