e04ea2d1de
- Dockerfile: openssh-client 换成 openssh-server - 新增 sshd-hardening.conf: 仅公钥认证,禁密码/转发 - 新增 authorized_keys: 授权公钥 - 构建期生成 host key,保证镜像内指纹稳定 - entrypoint.sh: exec opencode 前拉起 sshd,幂等且失败不阻断主服务 - compose: 发布 3333:22
24 lines
562 B
Plaintext
24 lines
562 B
Plaintext
# opencode 开发容器 SSH 加固配置
|
|
# 策略:仅公钥认证,关闭密码/交互式认证与各类转发
|
|
Port 22
|
|
|
|
# 仅允许 root 用密钥登录,禁用一切密码通道
|
|
PermitRootLogin prohibit-password
|
|
PubkeyAuthentication yes
|
|
PasswordAuthentication no
|
|
PermitEmptyPasswords no
|
|
KbdInteractiveAuthentication no
|
|
GSSAPIAuthentication no
|
|
HostbasedAuthentication no
|
|
|
|
# 收紧认证面
|
|
MaxAuthTries 3
|
|
LoginGraceTime 30
|
|
AllowUsers root
|
|
|
|
# 不需要转发,排掉隧道滥用
|
|
X11Forwarding no
|
|
AllowAgentForwarding no
|
|
AllowTcpForwarding no
|
|
PermitTunnel no
|