2026-09-25 15:40:20 +00:00
|
|
|
#!/bin/bash -e
|
|
|
|
|
|
2026-09-26 13:48:25 -05:00
|
|
|
# Write an sshd_config.d drop-in with a HostKey line for each key in /etc/ssh/keys,
|
|
|
|
|
# then exec any given command (e.g. /usr/sbin/sshd -D -e).
|
|
|
|
|
set -euo pipefail
|
|
|
|
|
shopt -s nullglob
|
|
|
|
|
keys=( /etc/ssh/keys/ssh_host_*_key )
|
|
|
|
|
(( ${#keys[@]} )) || { echo "no host keys in /etc/ssh/keys" >&2; exit 1; }
|
|
|
|
|
mkdir -p "$(dirname "/etc/ssh/sshd_config.d/10-hostkeys.conf")"
|
|
|
|
|
printf 'HostKey %s\n' "${keys[@]}" > "/etc/ssh/sshd_config.d/10-hostkeys.conf"
|
|
|
|
|
|
|
|
|
|
# Setup the target user and their group
|
2026-09-25 15:40:20 +00:00
|
|
|
echo "Setting up target user ${TARGET_USER} (uid=${TARGET_UID}, gid=${TARGET_GID})..."
|
|
|
|
|
groupadd --gid "$TARGET_GID" "$TARGET_USER"
|
2026-09-25 17:21:35 +00:00
|
|
|
|
|
|
|
|
# --no-create-home since we assume the home dir will be mounted in the container
|
|
|
|
|
adduser --gid "$TARGET_GID" --uid "$TARGET_UID" --no-create-home "$TARGET_USER"
|
2026-09-25 22:39:52 +00:00
|
|
|
touch /var/log/container-stdout.log
|
2026-09-25 15:40:20 +00:00
|
|
|
chown "$TARGET_USER":"$TARGET_USER" /var/log/container-stdout.log
|
|
|
|
|
|
2026-09-26 13:59:14 -05:00
|
|
|
# This only really matters for the first-run:
|
|
|
|
|
chown "$TARGET_USER":"$TARGET_USER" "/home/$TARGET_USER"
|
|
|
|
|
|
2026-09-26 14:17:38 -05:00
|
|
|
# Make the target user a sudoer:
|
|
|
|
|
echo "$TARGET_USER ALL=(ALL) NOPASSWD:ALL" > /etc/sudoers.d/target-user
|
|
|
|
|
chmod 440 /etc/sudoers.d/target-user
|
|
|
|
|
visudo -cf /etc/sudoers.d/target-user
|
|
|
|
|
|
|
|
|
|
# If the target user has an on-boot script defined, run it:
|
|
|
|
|
if [ -f "/home/$TARGET_USER/.on-boot.sh" ]; then
|
|
|
|
|
echo "Running on-boot script..."
|
|
|
|
|
sudo -u "$TARGET_USER" "/home/$TARGET_USER/.on-boot.sh"
|
|
|
|
|
fi
|
|
|
|
|
|
2026-09-25 15:40:20 +00:00
|
|
|
echo "Ready."
|
2026-09-25 17:20:18 +00:00
|
|
|
tail -f /var/log/container-stdout.log &
|
|
|
|
|
|
|
|
|
|
/usr/sbin/sshd -D
|