76 lines
2.9 KiB
Bash
76 lines
2.9 KiB
Bash
#!/bin/bash -e
|
|
|
|
# Write an sshd_config.d drop-in with a HostKey line for each key in /etc/ssh/keys,
|
|
# then exec any given command (e.g. /usr/sbin/sshd -D -e).
|
|
set -euo pipefail
|
|
shopt -s nullglob
|
|
keys=( /etc/ssh/keys/ssh_host_*_key )
|
|
(( ${#keys[@]} )) || { echo "no host keys in /etc/ssh/keys" >&2; exit 1; }
|
|
mkdir -p "$(dirname "/etc/ssh/sshd_config.d/10-hostkeys.conf")"
|
|
printf 'HostKey %s\n' "${keys[@]}" > "/etc/ssh/sshd_config.d/10-hostkeys.conf"
|
|
|
|
# Setup the DinD socket:
|
|
if [ -n "${DOCKER_RUN_DIR:-}" ]; then
|
|
ln -s "$DOCKER_RUN_DIR/docker.sock" /var/run/docker.sock || echo "Failed to symlink Docker socket!"
|
|
fi
|
|
|
|
# Setup the target user and their group
|
|
echo "Setting up target user ${TARGET_USER} (uid=${TARGET_UID}, gid=${TARGET_GID})..."
|
|
groupadd --gid "$TARGET_GID" "$TARGET_USER"
|
|
|
|
# --no-create-home since we assume the home dir will be mounted in the container
|
|
adduser --gid "$TARGET_GID" --uid "$TARGET_UID" --no-create-home "$TARGET_USER"
|
|
touch /var/log/container-stdout.log
|
|
chown "$TARGET_USER":"$TARGET_USER" /var/log/container-stdout.log
|
|
|
|
# This only really matters for the first-run:
|
|
chown "$TARGET_USER":"$TARGET_USER" "/home/$TARGET_USER"
|
|
|
|
# Make the target user a sudoer:
|
|
echo "$TARGET_USER ALL=(ALL) NOPASSWD:ALL" > /etc/sudoers.d/target-user
|
|
chmod 440 /etc/sudoers.d/target-user
|
|
visudo -cf /etc/sudoers.d/target-user
|
|
|
|
# If the target user has an on-boot script defined, run it:
|
|
if [ -f "/home/$TARGET_USER/.on-boot.sh" ]; then
|
|
echo "Running on-boot script..."
|
|
sudo -u "$TARGET_USER" "/home/$TARGET_USER/.on-boot.sh"
|
|
fi
|
|
|
|
# Set the target user's password for RDP logins (SSH remains key-only):
|
|
if [ -f /etc/xrdp/secrets/password-hash ]; then
|
|
usermod -p "$(cat /etc/xrdp/secrets/password-hash)" "$TARGET_USER"
|
|
else
|
|
echo "No /etc/xrdp/secrets/password-hash -- RDP logins will not work!" >&2
|
|
fi
|
|
|
|
# Use a mounted xrdp TLS cert if present, otherwise generate a self-signed one:
|
|
if [ ! -f /etc/xrdp/tls/cert.pem ] || [ ! -f /etc/xrdp/tls/key.pem ]; then
|
|
echo "No xrdp TLS cert in /etc/xrdp/tls, generating a self-signed one..."
|
|
mkdir -p /etc/xrdp/tls
|
|
openssl req -x509 -newkey rsa:3072 -nodes -days 3650 \
|
|
-keyout /etc/xrdp/tls/key.pem -out /etc/xrdp/tls/cert.pem \
|
|
-subj "/CN=$(hostname)" 2>/dev/null
|
|
chgrp xrdp /etc/xrdp/tls/key.pem /etc/xrdp/tls/cert.pem
|
|
chmod 640 /etc/xrdp/tls/key.pem /etc/xrdp/tls/cert.pem
|
|
fi
|
|
[ -s /etc/xrdp/rsakeys.ini ] || xrdp-keygen xrdp /etc/xrdp/rsakeys.ini >/dev/null
|
|
|
|
# Give the target user access to the iGPU, if passed through:
|
|
if [ -e /dev/dri/renderD128 ]; then
|
|
render_gid="$(stat -c %g /dev/dri/renderD128)"
|
|
getent group "$render_gid" >/dev/null || groupadd --gid "$render_gid" host-render
|
|
usermod -aG "$(getent group "$render_gid" | cut -d: -f1)" "$TARGET_USER"
|
|
fi
|
|
|
|
# Start the system D-Bus (no systemd here) and xrdp for the desktop:
|
|
mkdir -p /run/dbus /run/xrdp
|
|
dbus-daemon --system --fork
|
|
xrdp-sesman
|
|
xrdp
|
|
|
|
echo "Ready."
|
|
tail -f /var/log/container-stdout.log &
|
|
|
|
/usr/sbin/sshd -D
|