Files
sish-client/README.md
T
traberph dd1b847a05
build / image (push) Successful in 35s
cleanup
2026-09-27 09:52:12 +02:00

48 lines
2.4 KiB
Markdown

# sish-client
Opens SSH reverse tunnels to a [sish](https://github.com/antoniomika/sish) edge and reconnects
every 5s when the session drops. Image: `registry.traberph.de/public/sish-client`.
```sh
docker run -d --read-only --tmpfs /tmp \
-e SISH_HOST=edge.example.com \
-e SISH_HOST_KEY="ssh-ed25519 AAAA..." \
-e SISH_ROUTES="app.example.com:443=app:8443" \
-v ./id_ed25519:/secrets/id_ed25519:ro \
registry.traberph.de/public/sish-client:latest
```
| Variable | Default | |
|---|---|---|
| `SISH_HOST` | *required* | Edge host |
| `SISH_HOST_KEY` | *required* | Edge host key, `"<type> <base64>"` (first two fields of its `.pub` file) |
| `SISH_ROUTES` | *required* | Comma-separated `host:bind-port=target:port` |
| `SISH_PORT` | `2222` | sish SSH port |
| `SISH_KEY_FILE` | `/secrets/id_ed25519` | Private key |
| `SISH_SNI_PROXY` | `true` | `true`: sish routes by SNI and passes TLS through. `false`: HTTP routing by `Host` header |
| `SISH_PROXY_PROTOCOL` | `2` | PROXY header sent to the target: `1`, `2` or `off` |
HTTP (:80) routes need `SISH_SNI_PROXY=false` and a separate instance from SNI (:443) routes.
If sish rejects any route, the session fails and is retried, so a bad route shows up in the logs.
## Requirements
- `/tmp` must be writable (e.g. a memory `emptyDir`), the root filesystem can be read-only.
- Run as uid `65534` (the image default). ssh refuses to start for uids missing from `/etc/passwd`.
- The key file must be readable by uid 65534, e.g. a Secret volume with `defaultMode: 0440`
and `fsGroup: 65534`. ssh rejects keys owned by 65534 that others can read.
## Security
- The edge is authenticated only by `SISH_HOST_KEY`. There is no trust-on-first-use and no
fallback: a wrong or missing key fails the connection.
- All ssh_config files are ignored (`-F /dev/null`). Agent and X11 forwarding are off, so the
edge can only open connections to the configured route targets.
- **PROXY protocol:** the target trusts the PROXY header for the client IP. It must only accept
PROXY connections from this client (e.g. listen on `127.0.0.1` in the sidecar and set trusted
IPs), otherwise anything that can reach that port can spoof client IPs. If the target does not
expect a PROXY header, set `SISH_PROXY_PROTOCOL=off`.
- Whoever controls the edge sees HTTP traffic, and with `SISH_SNI_PROXY=true` still sees the
SNI hostnames and client IPs, but not TLS contents.
- The base image follows `alpine:3`. Rebuild regularly to pick up OpenSSH fixes.