opencode 容器内置 SSH:镜像内置 sshd 并开机自启

- Dockerfile: openssh-client 换成 openssh-server
- 新增 sshd-hardening.conf: 仅公钥认证,禁密码/转发
- 新增 authorized_keys: 授权公钥
- 构建期生成 host key,保证镜像内指纹稳定
- entrypoint.sh: exec opencode 前拉起 sshd,幂等且失败不阻断主服务
- compose: 发布 3333:22
This commit is contained in:
mavis-agent
2026-10-02 19:27:20 +08:00
parent 3197e1b7e5
commit e04ea2d1de
5 changed files with 57 additions and 1 deletions
+15 -1
View File
@@ -28,7 +28,7 @@ RUN apt-get update && apt-get install -y \
software-properties-common \
gnupg \
lsb-release \
openssh-client \
openssh-server \
rsync \
tar \
xz-utils \
@@ -86,10 +86,24 @@ RUN mkdir -p \
COPY settings.xml /root/.m2/settings.xml
# ---------- SSH 服务端 ----------
# 加固配置:仅公钥认证,关闭密码与各类转发
COPY sshd-hardening.conf /etc/ssh/sshd_config.d/99-hardening.conf
# 授权公钥(公钥非机密,可安全入镜像;轮换需重建镜像)
COPY authorized_keys /root/.ssh/authorized_keys
# 构建期生成 host key,保证同一镜像内主机指纹稳定
RUN chmod 700 /root/.ssh && chmod 600 /root/.ssh/authorized_keys \
&& ssh-keygen -A \
&& mkdir -p /run/sshd
EXPOSE 3004
EXPOSE 3005
EXPOSE 22
RUN ln -fs /usr/share/zoneinfo/Asia/Shanghai /etc/localtime && \
dpkg-reconfigure -f noninteractive tzdata
+1
View File
@@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC8c3cjfzpSqmWpKBiUz2GVZVNNOX3bDGsVeiGtm8gkr wol-trade-container
+2
View File
@@ -26,6 +26,8 @@ services:
ports:
- "3004:3004"
- "3005:3005"
# SSH(宿主机 3333 -> 容器 22)
- "3333:22"
volumes:
+16
View File
@@ -51,6 +51,22 @@ echo "Starting OpenCode Web..."
echo "User: ${OPENCODE_SERVER_USERNAME}"
echo "Port: 3004"
# 启动 SSH 服务(仅当已安装 openssh-server)
# 幂等:sshd 已在运行时跳过;启动失败不阻断主服务
if [ -x /usr/sbin/sshd ] && ! pgrep -x sshd >/dev/null 2>&1; then
mkdir -p /run/sshd
# -e 让日志走 stderr,便于 docker logs 排查
if /usr/sbin/sshd -e; then
echo "SSH: sshd 已启动,监听 0.0.0.0:22"
else
echo "SSH: sshd 启动失败(不影响主服务)"
fi
else
echo "SSH: 未安装或已在运行,跳过"
fi
echo
exec opencode web \
--hostname 0.0.0.0 \
--port 3004
+23
View File
@@ -0,0 +1,23 @@
# opencode 开发容器 SSH 加固配置
# 策略:仅公钥认证,关闭密码/交互式认证与各类转发
Port 22
# 仅允许 root 用密钥登录,禁用一切密码通道
PermitRootLogin prohibit-password
PubkeyAuthentication yes
PasswordAuthentication no
PermitEmptyPasswords no
KbdInteractiveAuthentication no
GSSAPIAuthentication no
HostbasedAuthentication no
# 收紧认证面
MaxAuthTries 3
LoginGraceTime 30
AllowUsers root
# 不需要转发,排掉隧道滥用
X11Forwarding no
AllowAgentForwarding no
AllowTcpForwarding no
PermitTunnel no