Expand description
SSH without open ports: GET /orgs/<org>/api/v1/ssh?instance=NAME
upgrades to a websocket whose binary frames are an SSH connection’s
bytes, both ways, to an sshd the embedder starts inside the instance
(isb serve: sshd -i through incus exec, docs/guides/ssh.md). Nothing in the
instance listens, and nothing on the host opens a port: the websocket is
the daemon’s own, behind its usual authentication.
The gate is the web terminal’s (super::terminal): the caller
authenticates as for any tool and is admitted as if calling
sandbox_exec in the org, so viewers, read/deploy tokens and
--deny-tools sandbox_exec are refused. A cookie needs an Origin
naming this site; the unix socket and bearer tokens need none.
Text frames are control messages from the server only: {"type": "exit", "code"} and {"type": "error", "message"} (why the session
ended, for the person running ssh).
The client half is here too: Remote (the unix socket, or a URL and a
token) and pump, which isb ssh-proxy runs between its stdio and the
websocket for ProxyCommand.
Structs§
- SshRequest
- What the client asked for.
Enums§
- Remote
- Where
isb serveis: its unix socket (as the local user), or a URL and an API token (ISB_URL,ISB_TOKEN).
Constants§
- KEYS_
HEADER - The header a control plane puts the caller’s SSH public keys in when it
forwards a session to a server’s agent: base64url JSON, a list of
authorized_keyslines.
Statics§
- LIMITS
- SSH sessions: more than terminals (an editor or herdr holds several),
longer-lived, and kept alive by the client’s
ServerAliveInterval.
Traits§
- Conn
- A connection the websocket runs over.
Functions§
- answer_
error - A REST error answer (
{"error", "message"}) as an isb error. - keys_
header KEYS_HEADER’s value forkeys.- origin_
allowed - The unix socket and bearer tokens need no
Origin; a cookie needs one naming this site, as for the terminal. AnOriginthat is there must name this site, whatever the transport. - pump
- Shuttle bytes between
input/output(ssh’s end of aProxyCommand) and the websocket until either side ends.Okwhen the session ended normally; the server’s reason otherwise. - split_
base - A
http(s)://host[:port][/prefix]base: TLS, host, port, prefix. - ssh_
request - The request’s parameters, or what is wrong with them.