# Install Restricted Production Chart Diagnostics This handoff is for the agent administering the Coolify Docker host for `chart.amow.com`. The implementation files are: ```text ops/chart-debug-command ops/install-chart-debug ``` Run the installer on the Coolify Docker **host** as root, not inside the chart application container. ## Dedicated key Install this public key: ```text ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics ``` Expected fingerprint: ```text SHA256:i2VPhUqgN9gHcta27aH6HV8d5YMvKABQ1EXworhnjGw ``` The private key must never be copied to production or pasted into chat. It stays on the diagnostics client at: ```text /home/chris/.ssh/chart_debug_ed25519 ``` ## Security requirements - Do not add `chart-debug` to the Docker group. - Do not enable password authentication for the account. - Do not add an unrestricted SSH key. - Do not grant a normal production shell. - Keep the wrapper, configuration and sudoers file root-owned. - Keep the account password locked. - Preserve the `restrict` and forced-command options in `authorized_keys`. - Verify arbitrary commands and malformed arguments are denied. - Do not print container environment variables or application secrets. - Ensure `status` passes its token to curl through stdin, not an argv `-H` argument visible through `/proc`. - Resolve the container into a variable before Docker calls so selector failure propagates with the documented return code. The account may run only: ```text logs --since DURATION status container-state recent-deploy capture-read CAPTURE_ID capture-delete CAPTURE_ID ``` ## Installation ### 1. Identify the chart container ```bash docker ps --format 'table {{.ID}}\t{{.Names}}\t{{.Image}}' ``` The Coolify resource UUID is: ```text dgvch0xqv8uvjfor7dl8bwl9 ``` A likely stable selector is: ```text ^dgvch0xqv8uvjfor7dl8bwl9 ``` Do not assume it. Verify the regex matches exactly one running chart container and will continue matching after a Coolify redeploy. ### 2. Run the installer From a checkout containing `ops/`: ```bash sudo ./ops/install-chart-debug \ --public-key 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics' \ --container-pattern '^VERIFIED-STABLE-PREFIX' \ --url https://chart.amow.com ``` ### 3. Verify account and file security ```bash passwd -S chart-debug stat -c '%U:%G %a %n' \ /usr/local/sbin/chart-debug-command \ /etc/chart-debug.conf \ /etc/sudoers.d/chart-debug \ /home/chart-debug/.ssh/authorized_keys visudo -cf /etc/sudoers.d/chart-debug ``` Expected permissions: | Path | Owner | Mode | |---|---|---:| | `/usr/local/sbin/chart-debug-command` | `root:root` | `755` | | `/etc/chart-debug.conf` | `root:root` | `600` | | `/etc/sudoers.d/chart-debug` | `root:root` | `440` | | `/home/chart-debug/.ssh/authorized_keys` | `chart-debug:chart-debug` | `600` | The account status must show a locked password. ### 4. Test allowed commands locally ```bash sudo -u chart-debug sudo -n \ /usr/local/sbin/chart-debug-command 'container-state' sudo -u chart-debug sudo -n \ /usr/local/sbin/chart-debug-command 'logs --since 5m' sudo -u chart-debug sudo -n \ /usr/local/sbin/chart-debug-command 'status' sudo -u chart-debug sudo -n \ /usr/local/sbin/chart-debug-command 'recent-deploy' ``` ### 5. Verify denial behavior ```bash if sudo -u chart-debug sudo -n \ /usr/local/sbin/chart-debug-command 'shell' then echo 'ERROR: arbitrary command was allowed' exit 1 else echo 'arbitrary command correctly denied' fi ``` Also verify these fail closed: - Invalid durations. - Extra arguments. - Invalid capture IDs. - A container selector matching zero containers. - A container selector matching multiple containers. ### 6. Verify SSH policy If `sshd` uses `AllowUsers`, add `chart-debug`. Keep password authentication disabled. Ensure the firewall permits SSH from the diagnostics client's network. Do not modify the installed forced-command `authorized_keys` entry. ### 7. Verify auditing ```bash journalctl -t chart-debug ``` ## Report back Return only: - Production SSH hostname or IP. - SSH port. - Exact stable container regex. - Whether each allowed command succeeded. - Confirmation arbitrary commands were denied. - Confirmation the account password is locked. - Confirmation the account is not in the Docker group. - Errors with secrets redacted. Do not return `CHART_AUTH_TOKEN`, Schwab credentials, container environment, or private key material. ## Client verification After receiving the host and port: ```bash ssh -i ~/.ssh/chart_debug_ed25519 \ -p PORT chart-debug@HOST 'logs --since 20m' ``` Other examples: ```bash ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST status ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST container-state ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST recent-deploy ```