4 ms·
creating a new project by just SSH'ing in seems interesting but.. like.. what's the security model for such a thing? Do other platforms do this? ...asking for
by dimitropoulos 3y ago
creating a new project by just SSH'ing in seems interesting but.. like.. what's the security model for such a thing? Do other platforms do this? ...asking for a friend :)
- qudat 3y agoThe most important thing to know here is authentication and authorization is based on public-key cryptography (via SSH). Users create an account by SSH'ing into our server (e.g. `ssh new@pgs.sh`), we record the public-key used to remote into it. Then to use the service you either a) run SSH commands (e.g. `ssh {user}@pgs.sh help`) or copy files to our server (e.g. `scp -r ./public/* {user}@pgs.sh:/my-project`). Under the hood, we use golang's ssh library to forward files being uploaded to our object storage service, record entries into our postgres database, and then have our web service serve those files.
- dimitropoulos 3y agodoes that mean I (or you?) can never recover my account if I lose my private key?
- qudat 3y agoGreat question! That's correct. We do help people recover lost accounts when requested which typically involves some proof they owned the account. At the top of the feature backlog we plan on adding recovery codes so a user can access their account when they lose their private key. But currently, our recommendation is to keep your private key that you use to access pico services somewhere you won't lose.
- mlfreeman 3y agohow does one add a public key from a second box? does ssh-copy-id work?
- qudat 3y agoThat's actually a really great idea that we hadn't considered, thanks! Currently the only way to have multiple public keys is to log into the CMS: `ssh {user}@pgs.sh` and then go to "Manage Keys" and then there's an option to add another public key (press "n").
- chatmasta 3y agoGitHub and GitLab both do this. They only give you enough of a shell for Git commands. I'm not sure how GitHub's is implemented, but GitLab's used to be a locked down Unix shell (i.e. in theory only the commands needed for Git would be accessible, with the caveat that there could be bugs) and now [0] it is a Go program [1] that listens for SSH connections and implements an in-process shell that only supports Git commands. Fun fact: you can create a GitLab PAT with an SSH command. (Another useful trick, to verify your SSH keys are configured properly for Git, is to run `ssh -T git@github.com` which will print a welcome message including your username.) [0] https://about.gitlab.com/blog/2022/08/17/why-we-have-implemented-our-own-sshd-solution-on-gitlab-sass/ https://about.gitlab.com/blog/2022/08/17/why-we-have-impleme... [1] https://gitlab.com/gitlab-org/gitlab-shell https://gitlab.com/gitlab-org/gitlab-shell