5 KiB
Install Restricted Production Chart Diagnostics
This handoff is for the agent administering the Coolify Docker host for
chart.amow.com.
The implementation files are:
ops/chart-debug-command
ops/install-chart-debug
Run the installer on the Coolify Docker host as root, not inside the chart application container.
Dedicated key
Install this public key:
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics
Expected fingerprint:
SHA256:i2VPhUqgN9gHcta27aH6HV8d5YMvKABQ1EXworhnjGw
The private key must never be copied to production or pasted into chat. It stays on the diagnostics client at:
/home/chris/.ssh/chart_debug_ed25519
Security requirements
- Do not add
chart-debugto the Docker group. - Do not enable password authentication for the account.
- Do not add an unrestricted SSH key.
- Do not grant a normal production shell.
- Keep the wrapper, configuration and sudoers file root-owned.
- Keep the account password locked.
- Preserve the
restrictand forced-command options inauthorized_keys. - Verify arbitrary commands and malformed arguments are denied.
- Do not print container environment variables or application secrets.
- Redact OAuth
code,session, andstatequery parameters from access logs. - Ensure
statuspasses its token to curl through stdin, not an argv-Hargument visible through/proc. - Resolve the container into a variable before Docker calls so selector failure propagates with the documented return code.
The account may run only:
logs --since DURATION
status
container-state
recent-deploy
capture-read CAPTURE_ID
capture-delete CAPTURE_ID
Installation
1. Identify the chart container
docker ps --format 'table {{.ID}}\t{{.Names}}\t{{.Image}}'
The Coolify resource UUID is:
dgvch0xqv8uvjfor7dl8bwl9
A likely stable selector is:
^dgvch0xqv8uvjfor7dl8bwl9
Do not assume it. Verify the regex matches exactly one running chart container and will continue matching after a Coolify redeploy.
2. Run the installer
From a checkout containing ops/:
sudo ./ops/install-chart-debug \
--public-key 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics' \
--container-pattern '^VERIFIED-STABLE-PREFIX' \
--url https://chart.amow.com
3. Verify account and file security
passwd -S chart-debug
stat -c '%U:%G %a %n' \
/usr/local/sbin/chart-debug-command \
/etc/chart-debug.conf \
/etc/sudoers.d/chart-debug \
/home/chart-debug/.ssh/authorized_keys
visudo -cf /etc/sudoers.d/chart-debug
Expected permissions:
| Path | Owner | Mode |
|---|---|---|
/usr/local/sbin/chart-debug-command |
root:root |
755 |
/etc/chart-debug.conf |
root:root |
600 |
/etc/sudoers.d/chart-debug |
root:root |
440 |
/home/chart-debug/.ssh/authorized_keys |
chart-debug:chart-debug |
600 |
The account status must show a locked password.
4. Test allowed commands locally
sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'container-state'
sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'logs --since 5m'
sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'status'
sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'recent-deploy'
5. Verify denial behavior
if sudo -u chart-debug sudo -n \
/usr/local/sbin/chart-debug-command 'shell'
then
echo 'ERROR: arbitrary command was allowed'
exit 1
else
echo 'arbitrary command correctly denied'
fi
Also verify these fail closed:
- Invalid durations.
- Extra arguments.
- Invalid capture IDs.
- A container selector matching zero containers.
- A container selector matching multiple containers.
6. Verify SSH policy
If sshd uses AllowUsers, add chart-debug. Keep password authentication
disabled. Ensure the firewall permits SSH from the diagnostics client's network.
Do not modify the installed forced-command authorized_keys entry.
7. Verify auditing
journalctl -t chart-debug
Report back
Return only:
- Production SSH hostname or IP.
- SSH port.
- Exact stable container regex.
- Whether each allowed command succeeded.
- Confirmation arbitrary commands were denied.
- Confirmation the account password is locked.
- Confirmation the account is not in the Docker group.
- Errors with secrets redacted.
Do not return CHART_AUTH_TOKEN, Schwab credentials, container environment, or
private key material.
Client verification
After receiving the host and port:
ssh -i ~/.ssh/chart_debug_ed25519 \
-p PORT chart-debug@HOST 'logs --since 20m'
Other examples:
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST status
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST container-state
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST recent-deploy