69 lines
2.4 KiB
Bash
Executable file
69 lines
2.4 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
|
|
usage() {
|
|
cat <<'EOF'
|
|
Usage: sudo ./ops/install-chart-debug \
|
|
--public-key 'ssh-ed25519 AAAA...' \
|
|
--container-pattern '^chart-app-' \
|
|
[--url https://chart.amow.com]
|
|
EOF
|
|
}
|
|
|
|
public_key=""
|
|
container_pattern=""
|
|
public_url="https://chart.amow.com"
|
|
while [[ $# -gt 0 ]]; do
|
|
case "$1" in
|
|
--public-key) public_key=${2:-}; shift 2 ;;
|
|
--container-pattern) container_pattern=${2:-}; shift 2 ;;
|
|
--url) public_url=${2:-}; shift 2 ;;
|
|
*) usage >&2; exit 2 ;;
|
|
esac
|
|
done
|
|
|
|
[[ $EUID -eq 0 ]] || { echo "run as root" >&2; exit 1; }
|
|
[[ "$public_key" =~ ^(ssh-ed25519|sk-ssh-ed25519@openssh.com)[[:space:]]+[A-Za-z0-9+/=]+([[:space:]].*)?$ ]] || {
|
|
echo "an Ed25519 public key is required" >&2; exit 2;
|
|
}
|
|
[[ -n "$container_pattern" && "$container_pattern" != *$'\n'* ]] || {
|
|
echo "a container-name regex is required" >&2; exit 2;
|
|
}
|
|
[[ "$public_url" =~ ^https://[^/]+$ ]] || { echo "--url must be an HTTPS origin" >&2; exit 2; }
|
|
|
|
script_dir=$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)
|
|
install -o root -g root -m 0755 "$script_dir/chart-debug-command" /usr/local/sbin/chart-debug-command
|
|
|
|
if ! id chart-debug >/dev/null 2>&1; then
|
|
useradd --create-home --shell /bin/bash chart-debug
|
|
fi
|
|
passwd --lock chart-debug >/dev/null
|
|
install -d -o chart-debug -g chart-debug -m 0700 /home/chart-debug/.ssh
|
|
|
|
forced='restrict,command="/usr/bin/sudo -n /usr/local/sbin/chart-debug-command \"$SSH_ORIGINAL_COMMAND\""'
|
|
printf '%s %s\n' "$forced" "$public_key" \
|
|
> /home/chart-debug/.ssh/authorized_keys
|
|
chown chart-debug:chart-debug /home/chart-debug/.ssh/authorized_keys
|
|
chmod 0600 /home/chart-debug/.ssh/authorized_keys
|
|
|
|
printf 'CHART_CONTAINER_PATTERN=%q\nCHART_PUBLIC_URL=%q\n' \
|
|
"$container_pattern" "$public_url" > /etc/chart-debug.conf
|
|
chown root:root /etc/chart-debug.conf
|
|
chmod 0600 /etc/chart-debug.conf
|
|
|
|
cat > /etc/sudoers.d/chart-debug <<'EOF'
|
|
Defaults:chart-debug !requiretty
|
|
chart-debug ALL=(root) NOPASSWD: /usr/local/sbin/chart-debug-command *
|
|
EOF
|
|
chmod 0440 /etc/sudoers.d/chart-debug
|
|
visudo -cf /etc/sudoers.d/chart-debug >/dev/null
|
|
|
|
matches=0
|
|
while read -r _ name; do
|
|
[[ "$name" =~ $container_pattern ]] && matches=$((matches + 1))
|
|
done < <(docker ps --format '{{.ID}} {{.Names}}')
|
|
[[ $matches -eq 1 ]] || {
|
|
echo "warning: container pattern currently matches $matches running containers" >&2
|
|
}
|
|
|
|
echo "installed restricted chart-debug access"
|