Add host-key handling to jump-box
All checks were successful
ci/woodpecker/manual/woodpecker Pipeline was successful
All checks were successful
ci/woodpecker/manual/woodpecker Pipeline was successful
This commit is contained in:
@@ -1,5 +1,15 @@
|
|||||||
#!/bin/bash -e
|
#!/bin/bash -e
|
||||||
|
|
||||||
|
# Write an sshd_config.d drop-in with a HostKey line for each key in /etc/ssh/keys,
|
||||||
|
# then exec any given command (e.g. /usr/sbin/sshd -D -e).
|
||||||
|
set -euo pipefail
|
||||||
|
shopt -s nullglob
|
||||||
|
keys=( /etc/ssh/keys/ssh_host_*_key )
|
||||||
|
(( ${#keys[@]} )) || { echo "no host keys in /etc/ssh/keys" >&2; exit 1; }
|
||||||
|
mkdir -p "$(dirname "/etc/ssh/sshd_config.d/10-hostkeys.conf")"
|
||||||
|
printf 'HostKey %s\n' "${keys[@]}" > "/etc/ssh/sshd_config.d/10-hostkeys.conf"
|
||||||
|
|
||||||
|
# Setup the target user and their group
|
||||||
echo "Setting up target user ${TARGET_USER} (uid=${TARGET_UID}, gid=${TARGET_GID})..."
|
echo "Setting up target user ${TARGET_USER} (uid=${TARGET_UID}, gid=${TARGET_GID})..."
|
||||||
groupadd --gid "$TARGET_GID" "$TARGET_USER"
|
groupadd --gid "$TARGET_GID" "$TARGET_USER"
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user