opencode 容器内置 SSH:镜像内置 sshd 并开机自启
- Dockerfile: openssh-client 换成 openssh-server - 新增 sshd-hardening.conf: 仅公钥认证,禁密码/转发 - 新增 authorized_keys: 授权公钥 - 构建期生成 host key,保证镜像内指纹稳定 - entrypoint.sh: exec opencode 前拉起 sshd,幂等且失败不阻断主服务 - compose: 发布 3333:22
This commit is contained in:
+15
-1
@@ -28,7 +28,7 @@ RUN apt-get update && apt-get install -y \
|
||||
software-properties-common \
|
||||
gnupg \
|
||||
lsb-release \
|
||||
openssh-client \
|
||||
openssh-server \
|
||||
rsync \
|
||||
tar \
|
||||
xz-utils \
|
||||
@@ -86,10 +86,24 @@ RUN mkdir -p \
|
||||
|
||||
COPY settings.xml /root/.m2/settings.xml
|
||||
|
||||
# ---------- SSH 服务端 ----------
|
||||
# 加固配置:仅公钥认证,关闭密码与各类转发
|
||||
COPY sshd-hardening.conf /etc/ssh/sshd_config.d/99-hardening.conf
|
||||
|
||||
# 授权公钥(公钥非机密,可安全入镜像;轮换需重建镜像)
|
||||
COPY authorized_keys /root/.ssh/authorized_keys
|
||||
|
||||
# 构建期生成 host key,保证同一镜像内主机指纹稳定
|
||||
RUN chmod 700 /root/.ssh && chmod 600 /root/.ssh/authorized_keys \
|
||||
&& ssh-keygen -A \
|
||||
&& mkdir -p /run/sshd
|
||||
|
||||
EXPOSE 3004
|
||||
|
||||
EXPOSE 3005
|
||||
|
||||
EXPOSE 22
|
||||
|
||||
RUN ln -fs /usr/share/zoneinfo/Asia/Shanghai /etc/localtime && \
|
||||
dpkg-reconfigure -f noninteractive tzdata
|
||||
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC8c3cjfzpSqmWpKBiUz2GVZVNNOX3bDGsVeiGtm8gkr wol-trade-container
|
||||
@@ -26,6 +26,8 @@ services:
|
||||
ports:
|
||||
- "3004:3004"
|
||||
- "3005:3005"
|
||||
# SSH(宿主机 3333 -> 容器 22)
|
||||
- "3333:22"
|
||||
|
||||
volumes:
|
||||
|
||||
|
||||
@@ -51,6 +51,22 @@ echo "Starting OpenCode Web..."
|
||||
echo "User: ${OPENCODE_SERVER_USERNAME}"
|
||||
echo "Port: 3004"
|
||||
|
||||
# 启动 SSH 服务(仅当已安装 openssh-server)
|
||||
# 幂等:sshd 已在运行时跳过;启动失败不阻断主服务
|
||||
if [ -x /usr/sbin/sshd ] && ! pgrep -x sshd >/dev/null 2>&1; then
|
||||
mkdir -p /run/sshd
|
||||
# -e 让日志走 stderr,便于 docker logs 排查
|
||||
if /usr/sbin/sshd -e; then
|
||||
echo "SSH: sshd 已启动,监听 0.0.0.0:22"
|
||||
else
|
||||
echo "SSH: sshd 启动失败(不影响主服务)"
|
||||
fi
|
||||
else
|
||||
echo "SSH: 未安装或已在运行,跳过"
|
||||
fi
|
||||
|
||||
echo
|
||||
|
||||
exec opencode web \
|
||||
--hostname 0.0.0.0 \
|
||||
--port 3004
|
||||
@@ -0,0 +1,23 @@
|
||||
# opencode 开发容器 SSH 加固配置
|
||||
# 策略:仅公钥认证,关闭密码/交互式认证与各类转发
|
||||
Port 22
|
||||
|
||||
# 仅允许 root 用密钥登录,禁用一切密码通道
|
||||
PermitRootLogin prohibit-password
|
||||
PubkeyAuthentication yes
|
||||
PasswordAuthentication no
|
||||
PermitEmptyPasswords no
|
||||
KbdInteractiveAuthentication no
|
||||
GSSAPIAuthentication no
|
||||
HostbasedAuthentication no
|
||||
|
||||
# 收紧认证面
|
||||
MaxAuthTries 3
|
||||
LoginGraceTime 30
|
||||
AllowUsers root
|
||||
|
||||
# 不需要转发,排掉隧道滥用
|
||||
X11Forwarding no
|
||||
AllowAgentForwarding no
|
||||
AllowTcpForwarding no
|
||||
PermitTunnel no
|
||||
Reference in New Issue
Block a user