This commit is contained in:
@@ -7,6 +7,7 @@ ENV DOCKER_RUN_DIR=/run/dind
|
||||
|
||||
COPY k8s.repo /etc/yum.repos.d/k8s.repo
|
||||
COPY startup.bash /usr/sbin/startup.bash
|
||||
COPY startwm-xfce.sh /etc/xrdp/startwm-xfce.sh
|
||||
|
||||
RUN dnf install -y \
|
||||
https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-44.noarch.rpm \
|
||||
@@ -18,7 +19,28 @@ RUN dnf install -y \
|
||||
&& wget -O /etc/yum.repos.d/kanidm.repo https://download.opensuse.org/repositories/network:/idm/Fedora_44/network:idm.repo \
|
||||
&& wget -O /etc/yum.repos.d/docker-ce.repo https://download.docker.com/linux/fedora/docker-ce.repo \
|
||||
&& dnf install -y kanidm-clients docker-ce-cli docker-buildx-plugin docker-compose-plugin \
|
||||
xfce4-session xfwm4 xfce4-panel xfdesktop xfce4-settings xfce4-terminal xfce4-appfinder \
|
||||
xfce4-notifyd xfce4-screenshooter Thunar dbus-x11 dbus-daemon adwaita-icon-theme xdg-utils \
|
||||
google-noto-sans-fonts google-noto-sans-mono-fonts liberation-fonts \
|
||||
firefox thunderbird xrdp xorgxrdp openssl fuse3 \
|
||||
&& dnf clean all -y \
|
||||
&& chmod +x /usr/sbin/startup.bash
|
||||
&& chmod +x /usr/sbin/startup.bash /etc/xrdp/startwm-xfce.sh \
|
||||
&& rm -f /etc/xrdp/cert.pem /etc/xrdp/key.pem /etc/xrdp/rsakeys.ini \
|
||||
&& rm -f /etc/xdg/autostart/xfce-polkit.desktop /etc/xdg/autostart/geoclue-demo-agent.desktop /etc/xdg/autostart/localsearch-3.desktop \
|
||||
&& sed -i \
|
||||
-e 's|^security_layer=.*|security_layer=tls|' \
|
||||
-e 's|^certificate=.*|certificate=/etc/xrdp/tls/cert.pem|' \
|
||||
-e 's|^key_file=.*|key_file=/etc/xrdp/tls/key.pem|' \
|
||||
-e 's|^autorun=.*|autorun=Xorg|' \
|
||||
-e '/^\[Xvnc\]/,$d' \
|
||||
/etc/xrdp/xrdp.ini \
|
||||
&& sed -i \
|
||||
-e 's|^EnableUserWindowManager=.*|EnableUserWindowManager=false|' \
|
||||
-e 's|^DefaultWindowManager=.*|DefaultWindowManager=/etc/xrdp/startwm-xfce.sh|' \
|
||||
-e 's|^AllowRootLogin=.*|AllowRootLogin=false|' \
|
||||
/etc/xrdp/sesman.ini \
|
||||
&& printf 'PasswordAuthentication no\nKbdInteractiveAuthentication no\n' > /etc/ssh/sshd_config.d/20-no-password.conf
|
||||
|
||||
EXPOSE 22 3389
|
||||
|
||||
CMD ["/usr/sbin/startup.bash"]
|
||||
|
||||
15
jump-box/README.md
Normal file
15
jump-box/README.md
Normal file
@@ -0,0 +1,15 @@
|
||||
# jump-box
|
||||
|
||||
## GUI (XFCE over RDP) first-time setup
|
||||
|
||||
1. **Set a password for RDP logins:** Generate a hash and mount it at `/etc/xrdp/secrets/password-hash`:
|
||||
```sh
|
||||
openssl passwd -6 > password-hash
|
||||
```
|
||||
2. **Optional: mount a persistent TLS cert** as `cert.pem` + `key.pem` under `/etc/xrdp/tls/`
|
||||
```sh
|
||||
openssl req -x509 -newkey rsa:3072 -nodes -days 3650 -keyout key.pem -out cert.pem -subj "/CN=jump-box"
|
||||
```
|
||||
3. **Expose the port:** expose TCP `3389`.
|
||||
4. **Optional iGPU setup:** Pass through `/dev/dri`; the user is added to its render group on boot.
|
||||
5. **Connect:** For Remmina, set colour depth to "GFX AVC444" and network type to "Automatic detection" to get H.264
|
||||
@@ -10,7 +10,7 @@ mkdir -p "$(dirname "/etc/ssh/sshd_config.d/10-hostkeys.conf")"
|
||||
printf 'HostKey %s\n' "${keys[@]}" > "/etc/ssh/sshd_config.d/10-hostkeys.conf"
|
||||
|
||||
# Setup the DinD socket:
|
||||
if [ -n DOCKER_RUN_DIR ]; then
|
||||
if [ -n "${DOCKER_RUN_DIR:-}" ]; then
|
||||
ln -s "$DOCKER_RUN_DIR/docker.sock" /var/run/docker.sock || echo "Failed to symlink Docker socket!"
|
||||
fi
|
||||
|
||||
@@ -37,6 +37,38 @@ if [ -f "/home/$TARGET_USER/.on-boot.sh" ]; then
|
||||
sudo -u "$TARGET_USER" "/home/$TARGET_USER/.on-boot.sh"
|
||||
fi
|
||||
|
||||
# Set the target user's password for RDP logins (SSH remains key-only):
|
||||
if [ -f /etc/xrdp/secrets/password-hash ]; then
|
||||
usermod -p "$(cat /etc/xrdp/secrets/password-hash)" "$TARGET_USER"
|
||||
else
|
||||
echo "No /etc/xrdp/secrets/password-hash -- RDP logins will not work!" >&2
|
||||
fi
|
||||
|
||||
# Use a mounted xrdp TLS cert if present, otherwise generate a self-signed one:
|
||||
if [ ! -f /etc/xrdp/tls/cert.pem ] || [ ! -f /etc/xrdp/tls/key.pem ]; then
|
||||
echo "No xrdp TLS cert in /etc/xrdp/tls, generating a self-signed one..."
|
||||
mkdir -p /etc/xrdp/tls
|
||||
openssl req -x509 -newkey rsa:3072 -nodes -days 3650 \
|
||||
-keyout /etc/xrdp/tls/key.pem -out /etc/xrdp/tls/cert.pem \
|
||||
-subj "/CN=$(hostname)" 2>/dev/null
|
||||
chgrp xrdp /etc/xrdp/tls/key.pem /etc/xrdp/tls/cert.pem
|
||||
chmod 640 /etc/xrdp/tls/key.pem /etc/xrdp/tls/cert.pem
|
||||
fi
|
||||
[ -s /etc/xrdp/rsakeys.ini ] || xrdp-keygen xrdp /etc/xrdp/rsakeys.ini >/dev/null
|
||||
|
||||
# Give the target user access to the iGPU, if passed through:
|
||||
if [ -e /dev/dri/renderD128 ]; then
|
||||
render_gid="$(stat -c %g /dev/dri/renderD128)"
|
||||
getent group "$render_gid" >/dev/null || groupadd --gid "$render_gid" host-render
|
||||
usermod -aG "$(getent group "$render_gid" | cut -d: -f1)" "$TARGET_USER"
|
||||
fi
|
||||
|
||||
# Start the system D-Bus (no systemd here) and xrdp for the desktop:
|
||||
mkdir -p /run/dbus /run/xrdp
|
||||
dbus-daemon --system --fork
|
||||
xrdp-sesman
|
||||
xrdp
|
||||
|
||||
echo "Ready."
|
||||
tail -f /var/log/container-stdout.log &
|
||||
|
||||
|
||||
13
jump-box/startwm-xfce.sh
Normal file
13
jump-box/startwm-xfce.sh
Normal file
@@ -0,0 +1,13 @@
|
||||
#!/usr/bin/bash -l
|
||||
|
||||
# xrdp session entrypoint: start an XFCE desktop on the xorgxrdp display.
|
||||
# Lives in /etc/xrdp (not ~/.xsession) since the home dir is mounted and shared with the CLI setup.
|
||||
|
||||
unset DBUS_SESSION_BUS_ADDRESS
|
||||
export XDG_RUNTIME_DIR="/tmp/runtime-$(id -u)"
|
||||
mkdir -p -m 0700 "$XDG_RUNTIME_DIR"
|
||||
export XDG_SESSION_TYPE=x11
|
||||
export XDG_CURRENT_DESKTOP=XFCE
|
||||
export MOZ_ENABLE_WAYLAND=0
|
||||
|
||||
exec dbus-launch --exit-with-session startxfce4
|
||||
Reference in New Issue
Block a user