204 lines
4.9 KiB
Markdown
204 lines
4.9 KiB
Markdown
# Install Restricted Production Chart Diagnostics
|
|
|
|
This handoff is for the agent administering the Coolify Docker host for
|
|
`chart.amow.com`.
|
|
|
|
The implementation files are:
|
|
|
|
```text
|
|
ops/chart-debug-command
|
|
ops/install-chart-debug
|
|
```
|
|
|
|
Run the installer on the Coolify Docker **host** as root, not inside the chart
|
|
application container.
|
|
|
|
## Dedicated key
|
|
|
|
Install this public key:
|
|
|
|
```text
|
|
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics
|
|
```
|
|
|
|
Expected fingerprint:
|
|
|
|
```text
|
|
SHA256:i2VPhUqgN9gHcta27aH6HV8d5YMvKABQ1EXworhnjGw
|
|
```
|
|
|
|
The private key must never be copied to production or pasted into chat. It stays
|
|
on the diagnostics client at:
|
|
|
|
```text
|
|
/home/chris/.ssh/chart_debug_ed25519
|
|
```
|
|
|
|
## Security requirements
|
|
|
|
- Do not add `chart-debug` to the Docker group.
|
|
- Do not enable password authentication for the account.
|
|
- Do not add an unrestricted SSH key.
|
|
- Do not grant a normal production shell.
|
|
- Keep the wrapper, configuration and sudoers file root-owned.
|
|
- Keep the account password locked.
|
|
- Preserve the `restrict` and forced-command options in `authorized_keys`.
|
|
- Verify arbitrary commands and malformed arguments are denied.
|
|
- Do not print container environment variables or application secrets.
|
|
- Ensure `status` passes its token to curl through stdin, not an argv `-H`
|
|
argument visible through `/proc`.
|
|
- Resolve the container into a variable before Docker calls so selector failure
|
|
propagates with the documented return code.
|
|
|
|
The account may run only:
|
|
|
|
```text
|
|
logs --since DURATION
|
|
status
|
|
container-state
|
|
recent-deploy
|
|
capture-read CAPTURE_ID
|
|
capture-delete CAPTURE_ID
|
|
```
|
|
|
|
## Installation
|
|
|
|
### 1. Identify the chart container
|
|
|
|
```bash
|
|
docker ps --format 'table {{.ID}}\t{{.Names}}\t{{.Image}}'
|
|
```
|
|
|
|
The Coolify resource UUID is:
|
|
|
|
```text
|
|
dgvch0xqv8uvjfor7dl8bwl9
|
|
```
|
|
|
|
A likely stable selector is:
|
|
|
|
```text
|
|
^dgvch0xqv8uvjfor7dl8bwl9
|
|
```
|
|
|
|
Do not assume it. Verify the regex matches exactly one running chart container
|
|
and will continue matching after a Coolify redeploy.
|
|
|
|
### 2. Run the installer
|
|
|
|
From a checkout containing `ops/`:
|
|
|
|
```bash
|
|
sudo ./ops/install-chart-debug \
|
|
--public-key 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIAdYzYs9RJ9Az9ypyYhrKsqdfbdv0EbjOGQVox+UyZBz chart-debug restricted production diagnostics' \
|
|
--container-pattern '^VERIFIED-STABLE-PREFIX' \
|
|
--url https://chart.amow.com
|
|
```
|
|
|
|
### 3. Verify account and file security
|
|
|
|
```bash
|
|
passwd -S chart-debug
|
|
|
|
stat -c '%U:%G %a %n' \
|
|
/usr/local/sbin/chart-debug-command \
|
|
/etc/chart-debug.conf \
|
|
/etc/sudoers.d/chart-debug \
|
|
/home/chart-debug/.ssh/authorized_keys
|
|
|
|
visudo -cf /etc/sudoers.d/chart-debug
|
|
```
|
|
|
|
Expected permissions:
|
|
|
|
| Path | Owner | Mode |
|
|
|---|---|---:|
|
|
| `/usr/local/sbin/chart-debug-command` | `root:root` | `755` |
|
|
| `/etc/chart-debug.conf` | `root:root` | `600` |
|
|
| `/etc/sudoers.d/chart-debug` | `root:root` | `440` |
|
|
| `/home/chart-debug/.ssh/authorized_keys` | `chart-debug:chart-debug` | `600` |
|
|
|
|
The account status must show a locked password.
|
|
|
|
### 4. Test allowed commands locally
|
|
|
|
```bash
|
|
sudo -u chart-debug sudo -n \
|
|
/usr/local/sbin/chart-debug-command 'container-state'
|
|
|
|
sudo -u chart-debug sudo -n \
|
|
/usr/local/sbin/chart-debug-command 'logs --since 5m'
|
|
|
|
sudo -u chart-debug sudo -n \
|
|
/usr/local/sbin/chart-debug-command 'status'
|
|
|
|
sudo -u chart-debug sudo -n \
|
|
/usr/local/sbin/chart-debug-command 'recent-deploy'
|
|
```
|
|
|
|
### 5. Verify denial behavior
|
|
|
|
```bash
|
|
if sudo -u chart-debug sudo -n \
|
|
/usr/local/sbin/chart-debug-command 'shell'
|
|
then
|
|
echo 'ERROR: arbitrary command was allowed'
|
|
exit 1
|
|
else
|
|
echo 'arbitrary command correctly denied'
|
|
fi
|
|
```
|
|
|
|
Also verify these fail closed:
|
|
|
|
- Invalid durations.
|
|
- Extra arguments.
|
|
- Invalid capture IDs.
|
|
- A container selector matching zero containers.
|
|
- A container selector matching multiple containers.
|
|
|
|
### 6. Verify SSH policy
|
|
|
|
If `sshd` uses `AllowUsers`, add `chart-debug`. Keep password authentication
|
|
disabled. Ensure the firewall permits SSH from the diagnostics client's network.
|
|
|
|
Do not modify the installed forced-command `authorized_keys` entry.
|
|
|
|
### 7. Verify auditing
|
|
|
|
```bash
|
|
journalctl -t chart-debug
|
|
```
|
|
|
|
## Report back
|
|
|
|
Return only:
|
|
|
|
- Production SSH hostname or IP.
|
|
- SSH port.
|
|
- Exact stable container regex.
|
|
- Whether each allowed command succeeded.
|
|
- Confirmation arbitrary commands were denied.
|
|
- Confirmation the account password is locked.
|
|
- Confirmation the account is not in the Docker group.
|
|
- Errors with secrets redacted.
|
|
|
|
Do not return `CHART_AUTH_TOKEN`, Schwab credentials, container environment, or
|
|
private key material.
|
|
|
|
## Client verification
|
|
|
|
After receiving the host and port:
|
|
|
|
```bash
|
|
ssh -i ~/.ssh/chart_debug_ed25519 \
|
|
-p PORT chart-debug@HOST 'logs --since 20m'
|
|
```
|
|
|
|
Other examples:
|
|
|
|
```bash
|
|
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST status
|
|
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST container-state
|
|
ssh -i ~/.ssh/chart_debug_ed25519 -p PORT chart-debug@HOST recent-deploy
|
|
```
|