Files
mesh-catalog/modules/sshd/module.json
T
jschoubben e145e2236c sshd: the daemon it owns starts at boot
The module said the service must be running and nothing about boot, so the
machine's own way back in was enabled only because something before the mesh
had enabled it. All four machines happen to be enabled today; none of them is
enabled because the mesh says so, and a machine adopted tomorrow would run ssh
until its first reboot.

Not `state: running` alone for the same reason the module exists: this is the
one daemon whose absence cannot be fixed remotely.
2026-09-28 21:43:27 +02:00

41 lines
1.1 KiB
JSON

{
"module": "sshd",
"version": "1",
"capabilities": [
"package-manager",
"service-manager"
],
"listens": [
{
"port": 22,
"protocol": "tcp",
"from": "anywhere",
"why": "the operator's own door. From anywhere because the machines that need it are exactly the ones not on the mesh yet \u2014 and locking the operator out is the one failure a firewall must never arrange"
}
],
"resources": [
{
"id": "package",
"type": "package",
"package": "openssh"
},
{
"id": "config",
"type": "file",
"path": "/etc/ssh/sshd_config.d/10-mesh.conf",
"mode": "0644",
"content": "# Managed by the mesh (module sshd). Replaced on every push; edit the catalogue instead.\nPort 22\nPermitRootLogin no\nPasswordAuthentication no\nPubkeyAuthentication yes\nKbdInteractiveAuthentication no\nUsePAM yes\nX11Forwarding no\nPrintMotd no\nAcceptEnv LANG LC_*\n"
},
{
"id": "run",
"type": "service",
"unit": "sshd.service",
"state": "running",
"boot": "enabled",
"restart-on": [
"config"
]
}
]
}