sshd: the operator's door is a module #107

Merged
jschoubben merged 1 commits from feat/sshd-module into main 2026-09-26 18:15:09 +00:00
Showing only changes of commit a85b0ee346 - Show all commits
+39
View File
@@ -0,0 +1,39 @@
{
"module": "sshd",
"version": "1",
"capabilities": [
"package-manager",
"service-manager"
],
"listens": [
{
"port": 22,
"protocol": "tcp",
"from": "anywhere",
"why": "the operator's own door. From anywhere because the machines that need it are exactly the ones not on the mesh yet \u2014 and locking the operator out is the one failure a firewall must never arrange"
}
],
"resources": [
{
"id": "package",
"type": "package",
"package": "openssh"
},
{
"id": "config",
"type": "file",
"path": "/etc/ssh/sshd_config.d/10-mesh.conf",
"mode": "0644",
"content": "# Managed by the mesh (module sshd). Replaced on every push; edit the catalogue instead.\nPort 22\nPermitRootLogin no\nPasswordAuthentication no\nPubkeyAuthentication yes\nKbdInteractiveAuthentication no\nUsePAM yes\nX11Forwarding no\nPrintMotd no\nAcceptEnv LANG LC_*\n"
},
{
"id": "run",
"type": "service",
"unit": "sshd.service",
"state": "running",
"restart-on": [
"config"
]
}
]
}