make wanted changes
Signed-off-by: Ivan Schaller <ivan@schaller.sh>
This commit is contained in:
parent
ff7fdf4350
commit
a112241c76
5 changed files with 47 additions and 70 deletions
62
Dockerfile
62
Dockerfile
|
|
@ -1,62 +1,20 @@
|
||||||
FROM golang:1.20.3-alpine3.17 AS build
|
FROM golang AS build
|
||||||
|
|
||||||
# environment settings
|
RUN mkdir /endlessh
|
||||||
ARG GOOS="linux" \
|
ADD . /endlessh
|
||||||
CGO_ENABLED="0"
|
WORKDIR /endlessh
|
||||||
|
RUN go mod tidy
|
||||||
|
RUN go build -o endlessh .
|
||||||
|
|
||||||
# copy files to container
|
FROM gcr.io/distroless/base
|
||||||
COPY . "/tmp/endlessh-go/"
|
|
||||||
|
|
||||||
# set build workdir
|
|
||||||
WORKDIR "/tmp/endlessh-go/"
|
|
||||||
|
|
||||||
# build app
|
|
||||||
RUN \
|
|
||||||
go mod tidy \
|
|
||||||
&& go build -o "endlessh-go"
|
|
||||||
|
|
||||||
|
|
||||||
FROM alpine:3.17
|
|
||||||
|
|
||||||
# labels
|
|
||||||
LABEL org.opencontainers.image.title=endlessh-go
|
LABEL org.opencontainers.image.title=endlessh-go
|
||||||
LABEL org.opencontainers.image.description="Endlessh: an SSH tarpit"
|
LABEL org.opencontainers.image.description="Endlessh: an SSH tarpit"
|
||||||
LABEL org.opencontainers.image.vendor="Shizun Ge"
|
LABEL org.opencontainers.image.vendor="Shizun Ge"
|
||||||
LABEL org.opencontainers.image.licenses=GPLv3
|
LABEL org.opencontainers.image.licenses=GPLv3
|
||||||
|
|
||||||
|
COPY --from=build /endlessh/endlessh /endlessh
|
||||||
# install packages
|
|
||||||
RUN \
|
|
||||||
echo "**** installing base packages ****" \
|
|
||||||
&& apk update \
|
|
||||||
&& apk --no-cache add \
|
|
||||||
ca-certificates \
|
|
||||||
bash \
|
|
||||||
procps \
|
|
||||||
tzdata
|
|
||||||
|
|
||||||
# prepare container
|
|
||||||
RUN \
|
|
||||||
echo "**** create default user ****" \
|
|
||||||
&& addgroup -S -g 2000 abc \
|
|
||||||
&& adduser -S -D -H -s /bin/bash -u 2000 -G abc abc
|
|
||||||
|
|
||||||
# cleanup installation
|
|
||||||
RUN \
|
|
||||||
echo "**** cleanup ****" \
|
|
||||||
&& rm -rf \
|
|
||||||
/tmp/* \
|
|
||||||
/var/cache/apk/* \
|
|
||||||
/var/tmp/*
|
|
||||||
|
|
||||||
# copy files to container
|
|
||||||
COPY --from=build "/tmp/endlessh-go/endlessh-go" "/usr/local/bin/"
|
|
||||||
|
|
||||||
# ssh / prometheus port
|
|
||||||
EXPOSE 2222 2112
|
EXPOSE 2222 2112
|
||||||
|
USER nobody
|
||||||
USER abc
|
ENTRYPOINT ["/endlessh"]
|
||||||
|
|
||||||
ENTRYPOINT ["/usr/local/bin/endlessh-go"]
|
|
||||||
|
|
||||||
CMD ["-logtostderr", "-v=1"]
|
CMD ["-logtostderr", "-v=1"]
|
||||||
|
|
|
||||||
26
README.md
26
README.md
|
|
@ -33,8 +33,6 @@ Then you can try to connect to the endlessh server. Your SSH client should hang
|
||||||
ssh -p 2222 localhost
|
ssh -p 2222 localhost
|
||||||
```
|
```
|
||||||
|
|
||||||
The default container user has uid/gid 2000.
|
|
||||||
|
|
||||||
If you want log like the [C implementation](https://github.com/skeeto/endlessh), you need to set both CLI arguments `-logtostderr` and `-v=1`, then the log will go to stderr. You can set different log destinations via CLI arguments.
|
If you want log like the [C implementation](https://github.com/skeeto/endlessh), you need to set both CLI arguments `-logtostderr` and `-v=1`, then the log will go to stderr. You can set different log destinations via CLI arguments.
|
||||||
|
|
||||||
Also check out [examples](./examples/README.md) for the setup of the full stack.
|
Also check out [examples](./examples/README.md) for the setup of the full stack.
|
||||||
|
|
@ -85,26 +83,18 @@ Usage of ./endlessh-go
|
||||||
comma-separated list of pattern=N settings for file-filtered logging
|
comma-separated list of pattern=N settings for file-filtered logging
|
||||||
```
|
```
|
||||||
|
|
||||||
## Using privileged ports (<1024)
|
|
||||||
|
|
||||||
If you want to run the image with privileged ports (below 1025), you need to set the container user to root:
|
|
||||||
|
|
||||||
```yml
|
|
||||||
user: root
|
|
||||||
```
|
|
||||||
|
|
||||||
## Metrics
|
## Metrics
|
||||||
|
|
||||||
Endlessh-go exports the following Prometheus metrics.
|
Endlessh-go exports the following Prometheus metrics.
|
||||||
|
|
||||||
| Metric | Type | Description |
|
| Metric | Type | Description |
|
||||||
| ------------------------------------ | ----- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
|--------------------------------------|-------|--------------|
|
||||||
| endlessh_client_open_count_total | count | Total number of clients that tried to connect to this host. |
|
| endlessh_client_open_count_total | count | Total number of clients that tried to connect to this host. |
|
||||||
| endlessh_client_closed_count_total | count | Total number of clients that stopped connecting to this host. |
|
| endlessh_client_closed_count_total | count | Total number of clients that stopped connecting to this host. |
|
||||||
| endlessh_sent_bytes_total | count | Total bytes sent to clients that tried to connect to this host. |
|
| endlessh_sent_bytes_total | count | Total bytes sent to clients that tried to connect to this host. |
|
||||||
| endlessh_trapped_time_seconds_total | count | Total seconds clients spent on endlessh. |
|
| endlessh_trapped_time_seconds_total | count | Total seconds clients spent on endlessh. |
|
||||||
| endlessh_client_open_count | count | Number of connections of clients. <br> Labels: <br> <ul><li> `ip`: IP of the client </li> <li> `country`: Country of the IP </li> <li> `location`: Country, Region, and City </li> <li> `geohash`: Geohash of the location </li></ul> |
|
| endlessh_client_open_count | count | Number of connections of clients. <br> Labels: <br> <ul><li> `ip`: IP of the client </li> <li> `country`: Country of the IP </li> <li> `location`: Country, Region, and City </li> <li> `geohash`: Geohash of the location </li></ul> |
|
||||||
| endlessh_client_trapped_time_seconds | count | Seconds a client spends on endlessh. <br> Labels: <br> <ul><li> `ip`: IP of the client </li></ul> |
|
| endlessh_client_trapped_time_seconds | count | Seconds a client spends on endlessh. <br> Labels: <br> <ul><li> `ip`: IP of the client </li></ul> |
|
||||||
|
|
||||||
The metrics is off by default, you can turn it via the CLI argument `-enable_prometheus`.
|
The metrics is off by default, you can turn it via the CLI argument `-enable_prometheus`.
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -1,6 +1,19 @@
|
||||||
# Examples
|
# Examples
|
||||||
|
|
||||||
|
> The default container user has uid 65534.
|
||||||
|
|
||||||
## docker-simple
|
## docker-simple
|
||||||
|
|
||||||
An example how to setup endlessh-go, Prometheus, and Grafana using [docker compose](https://docs.docker.com/compose/).
|
An example how to setup endlessh-go, Prometheus, and Grafana using [docker compose](https://docs.docker.com/compose/).
|
||||||
|
|
||||||
|
## docker-maxmind
|
||||||
|
|
||||||
|
An example how to setup endlessh-go with the Maxmind GeoIP Database.
|
||||||
|
|
||||||
|
### Using privileged ports (<1024) on docker
|
||||||
|
|
||||||
|
If you want to run the image with privileged ports (below 1025), you need to set the container user to root:
|
||||||
|
|
||||||
|
```yml
|
||||||
|
user: root
|
||||||
|
```
|
||||||
|
|
|
||||||
16
examples/docker-maxmind/README.md
Normal file
16
examples/docker-maxmind/README.md
Normal file
|
|
@ -0,0 +1,16 @@
|
||||||
|
## docker compose
|
||||||
|
|
||||||
|
This is an example how to setup endlessh-go with the Maxmind GeoIP Database using [docker compose](https://docs.docker.com/compose/). The reference of the compose file can be found [here](https://docs.docker.com/compose/compose-file/).
|
||||||
|
|
||||||
|
To start the stack, in the _examples_ folder, run:
|
||||||
|
|
||||||
|
```
|
||||||
|
sudo docker-compose up -d
|
||||||
|
```
|
||||||
|
|
||||||
|
The GeoIP Database will be saved in a mounted volume in: `./geo-data`. And the endlessh-go container will use this database to do the location lookups.
|
||||||
|
|
||||||
|
This example exposes the following ports. Except the SSH port, you should not expose other ports to public without protections (not included in this example) in production.
|
||||||
|
|
||||||
|
- **2222**: The SSH port. You may test endlessh-go by running `ssh -p 2222 localhost`. Your SSH client should hang. View the log of endlessh-go by running `sudo docker logs endlessh`.
|
||||||
|
- **2112**: The Prometheus metrics exported by endlessh-go. Go to [http://localhost:2112/metrics](http://localhost:2112/metrics) in your web browser to view the metrics.
|
||||||
Loading…
Reference in a new issue