chart/docs/install_debug_charts.md

4.9 KiB

Install Restricted Production Chart Diagnostics

This handoff is for the agent administering the Coolify Docker host for chart.amow.com.

The implementation files are:

ops/chart-debug-command
ops/install-chart-debug

Run the installer on the Coolify Docker host as root, not inside the chart application container.

Dedicated key

Install this public key:

ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics

Expected fingerprint:

SHA256:i2VPhUqgN9gHcta27aH6HV8d5YMvKABQ1EXworhnjGw

The private key must never be copied to production or pasted into chat. It stays on the diagnostics client at:

/home/chris/.ssh/chart_debug_ed25519

Security requirements

  • Do not add chart-debug to the Docker group.
  • Do not enable password authentication for the account.
  • Do not add an unrestricted SSH key.
  • Do not grant a normal production shell.
  • Keep the wrapper, configuration and sudoers file root-owned.
  • Keep the account password locked.
  • Preserve the restrict and forced-command options in authorized_keys.
  • Verify arbitrary commands and malformed arguments are denied.
  • Do not print container environment variables or application secrets.
  • Ensure status passes its token to curl through stdin, not an argv -H argument visible through /proc.
  • Resolve the container into a variable before Docker calls so selector failure propagates with the documented return code.

The account may run only:

logs --since DURATION
status
container-state
recent-deploy
capture-read CAPTURE_ID
capture-delete CAPTURE_ID

Installation

1. Identify the chart container

docker ps --format 'table {{.ID}}\t{{.Names}}\t{{.Image}}'

The Coolify resource UUID is:

dgvch0xqv8uvjfor7dl8bwl9

A likely stable selector is:

^dgvch0xqv8uvjfor7dl8bwl9

Do not assume it. Verify the regex matches exactly one running chart container and will continue matching after a Coolify redeploy.

2. Run the installer

From a checkout containing ops/:

sudo ./ops/install-chart-debug \
  --public-key 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics' \
  --container-pattern '^VERIFIED-STABLE-PREFIX' \
  --url https://chart.amow.com

3. Verify account and file security

passwd -S chart-debug

stat -c '%U:%G %a %n' \
  /usr/local/sbin/chart-debug-command \
  /etc/chart-debug.conf \
  /etc/sudoers.d/chart-debug \
  /home/chart-debug/.ssh/authorized_keys

visudo -cf /etc/sudoers.d/chart-debug

Expected permissions:

Path Owner Mode
/usr/local/sbin/chart-debug-command root:root 755
/etc/chart-debug.conf root:root 600
/etc/sudoers.d/chart-debug root:root 440
/home/chart-debug/.ssh/authorized_keys chart-debug:chart-debug 600

The account status must show a locked password.

4. Test allowed commands locally

sudo -u chart-debug sudo -n \
  /usr/local/sbin/chart-debug-command 'container-state'

sudo -u chart-debug sudo -n \
  /usr/local/sbin/chart-debug-command 'logs --since 5m'

sudo -u chart-debug sudo -n \
  /usr/local/sbin/chart-debug-command 'status'

sudo -u chart-debug sudo -n \
  /usr/local/sbin/chart-debug-command 'recent-deploy'

5. Verify denial behavior

if sudo -u chart-debug sudo -n \
  /usr/local/sbin/chart-debug-command 'shell'
then
  echo 'ERROR: arbitrary command was allowed'
  exit 1
else
  echo 'arbitrary command correctly denied'
fi

Also verify these fail closed:

  • Invalid durations.
  • Extra arguments.
  • Invalid capture IDs.
  • A container selector matching zero containers.
  • A container selector matching multiple containers.

6. Verify SSH policy

If sshd uses AllowUsers, add chart-debug. Keep password authentication disabled. Ensure the firewall permits SSH from the diagnostics client's network.

Do not modify the installed forced-command authorized_keys entry.

7. Verify auditing

journalctl -t chart-debug

Report back

Return only:

  • Production SSH hostname or IP.
  • SSH port.
  • Exact stable container regex.
  • Whether each allowed command succeeded.
  • Confirmation arbitrary commands were denied.
  • Confirmation the account password is locked.
  • Confirmation the account is not in the Docker group.
  • Errors with secrets redacted.

Do not return CHART_AUTH_TOKEN, Schwab credentials, container environment, or private key material.

Client verification

After receiving the host and port:

ssh -i ~/.ssh/chart_debug_ed25519 \
  -p PORT chart-debug@HOST 'logs --since 20m'

Other examples:

ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST status
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST container-state
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST recent-deploy