Files
w2ming-docker/opencode/sshd-hardening.conf
T
mavis-agent e04ea2d1de opencode 容器内置 SSH:镜像内置 sshd 并开机自启
- Dockerfile: openssh-client 换成 openssh-server
- 新增 sshd-hardening.conf: 仅公钥认证,禁密码/转发
- 新增 authorized_keys: 授权公钥
- 构建期生成 host key,保证镜像内指纹稳定
- entrypoint.sh: exec opencode 前拉起 sshd,幂等且失败不阻断主服务
- compose: 发布 3333:22
2026-10-02 19:27:20 +08:00

24 lines
562 B
Plaintext

# opencode 开发容器 SSH 加固配置
# 策略:仅公钥认证,关闭密码/交互式认证与各类转发
Port 22
# 仅允许 root 用密钥登录,禁用一切密码通道
PermitRootLogin prohibit-password
PubkeyAuthentication yes
PasswordAuthentication no
PermitEmptyPasswords no
KbdInteractiveAuthentication no
GSSAPIAuthentication no
HostbasedAuthentication no
# 收紧认证面
MaxAuthTries 3
LoginGraceTime 30
AllowUsers root
# 不需要转发,排掉隧道滥用
X11Forwarding no
AllowAgentForwarding no
AllowTcpForwarding no
PermitTunnel no