chart/docs/install_debug_charts.md

205 lines
5 KiB
Markdown

# Install Restricted Production Chart Diagnostics
This handoff is for the agent administering the Coolify Docker host for
`chart.amow.com`.
The implementation files are:
```text
ops/chart-debug-command
ops/install-chart-debug
```
Run the installer on the Coolify Docker **host** as root, not inside the chart
application container.
## Dedicated key
Install this public key:
```text
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics
```
Expected fingerprint:
```text
SHA256:i2VPhUqgN9gHcta27aH6HV8d5YMvKABQ1EXworhnjGw
```
The private key must never be copied to production or pasted into chat. It stays
on the diagnostics client at:
```text
/home/chris/.ssh/chart_debug_ed25519
```
## Security requirements
- Do not add `chart-debug` to the Docker group.
- Do not enable password authentication for the account.
- Do not add an unrestricted SSH key.
- Do not grant a normal production shell.
- Keep the wrapper, configuration and sudoers file root-owned.
- Keep the account password locked.
- Preserve the `restrict` and forced-command options in `authorized_keys`.
- Verify arbitrary commands and malformed arguments are denied.
- Do not print container environment variables or application secrets.
- Redact OAuth `code`, `session`, and `state` query parameters from access logs.
- Ensure `status` passes its token to curl through stdin, not an argv `-H`
argument visible through `/proc`.
- Resolve the container into a variable before Docker calls so selector failure
propagates with the documented return code.
The account may run only:
```text
logs --since DURATION
status
container-state
recent-deploy
capture-read CAPTURE_ID
capture-delete CAPTURE_ID
```
## Installation
### 1. Identify the chart container
```bash
docker ps --format 'table {{.ID}}\t{{.Names}}\t{{.Image}}'
```
The Coolify resource UUID is:
```text
dgvch0xqv8uvjfor7dl8bwl9
```
A likely stable selector is:
```text
^dgvch0xqv8uvjfor7dl8bwl9
```
Do not assume it. Verify the regex matches exactly one running chart container
and will continue matching after a Coolify redeploy.
### 2. Run the installer
From a checkout containing `ops/`:
```bash
sudo ./ops/install-chart-debug \
--public-key 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics' \
--container-pattern '^VERIFIED-STABLE-PREFIX' \
--url https://chart.amow.com
```
### 3. Verify account and file security
```bash
passwd -S chart-debug
stat -c '%U:%G %a %n' \
/usr/local/sbin/chart-debug-command \
/etc/chart-debug.conf \
/etc/sudoers.d/chart-debug \
/home/chart-debug/.ssh/authorized_keys
visudo -cf /etc/sudoers.d/chart-debug
```
Expected permissions:
| Path | Owner | Mode |
|---|---|---:|
| `/usr/local/sbin/chart-debug-command` | `root:root` | `755` |
| `/etc/chart-debug.conf` | `root:root` | `600` |
| `/etc/sudoers.d/chart-debug` | `root:root` | `440` |
| `/home/chart-debug/.ssh/authorized_keys` | `chart-debug:chart-debug` | `600` |
The account status must show a locked password.
### 4. Test allowed commands locally
```bash
sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'container-state'
sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'logs --since 5m'
sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'status'
sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'recent-deploy'
```
### 5. Verify denial behavior
```bash
if sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'shell'
then
echo 'ERROR: arbitrary command was allowed'
exit 1
else
echo 'arbitrary command correctly denied'
fi
```
Also verify these fail closed:
- Invalid durations.
- Extra arguments.
- Invalid capture IDs.
- A container selector matching zero containers.
- A container selector matching multiple containers.
### 6. Verify SSH policy
If `sshd` uses `AllowUsers`, add `chart-debug`. Keep password authentication
disabled. Ensure the firewall permits SSH from the diagnostics client's network.
Do not modify the installed forced-command `authorized_keys` entry.
### 7. Verify auditing
```bash
journalctl -t chart-debug
```
## Report back
Return only:
- Production SSH hostname or IP.
- SSH port.
- Exact stable container regex.
- Whether each allowed command succeeded.
- Confirmation arbitrary commands were denied.
- Confirmation the account password is locked.
- Confirmation the account is not in the Docker group.
- Errors with secrets redacted.
Do not return `CHART_AUTH_TOKEN`, Schwab credentials, container environment, or
private key material.
## Client verification
After receiving the host and port:
```bash
ssh -i ~/.ssh/chart_debug_ed25519 \
-p PORT chart-debug@HOST 'logs --since 20m'
```
Other examples:
```bash
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST status
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST container-state
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST recent-deploy
```