4 ms·
If I understand you correctly, the admin of sshd has turned off forwarding. You'll have to set you your own userspace forwarder if the admin hasn't also clampe
by tezza 13y ago
If I understand you correctly, the admin of sshd has turned off forwarding.
You'll have to set you your own userspace forwarder if the admin hasn't also clamped down the firewall config too tight.
If they HAVE clamped down the config, you could still invoke netcat on the remote side and use some form of kermit tunneling to get to the remote target side.
- malandrew 13y agoNot quite. The server is an amazon elastic beanstalk image that comes with it turned off. I can turn it back on after the machine is provisioned, but I want to be able to turn it on before the machine is provisioned so that the npm install with git urls pointing to private repos works. Basically, once I SSH and I'm root during the provisioning process, how do I programmatically set up ssh-agent for an in progress ssh session so that all future commands have access to the SSH_AUTH_SOCKET on my localhost.
- tezza 13y agoWell, you'll need a bit of trial and error here. Try changing the sshd config and send the sshd a reload signal. Normally that keeps existing connections alive. YMMV.
- Robin_Message 13y agoThat sounds like the wrong way to do it tbh. What about a deployment key? Not sure if that is any easier on eb though. Some other ideas: http://stackoverflow.com/questions/13476138/setting-up-private-github-access-with-aws-elastic-beanstalk-and-ruby-container http://stackoverflow.com/questions/13476138/setting-up-priva...
- malandrew 13y agoTried that. I got it to work, but it's super hackish and brittle. Basically, Github supports deployment keys, but they need to be unique per repo, so if I have many repos I want to clone (for each private npm module) I will need to clone multiple keys. Then since ssh only allows different keys based on the hostname or username, and all git clones are git@github.com, you have to create a script for the GIT_SSH env var to choose the right key based on the value of $2 passed to the GIT_SSH script. The only way a deployment key makes sense is to make a dummy user with read only access to the repos you need, which is yet another undesirable hack.
- malandrew 13y agoTurns out what I want to do is impossible without something like spiped. I dug into the source of the cli tool and it looks like it doesn't rely on ssh at all. Instead it does all the provisioning through amazon APIs. i.e. Amazon is sshing into the machine for provisioning purposes, not my machine. Basically, I need to expose my ssh-agent socket to the world via a TCP socket exposed to the world. The server would then install spiped, get the symmetric key that allows it to connect to my ssh-agent-port and set up the SSH_AUTH_SOCK to proxy requests to my machine. This is still more secure than ever letting your private key ever leave your machine. While I don't think I need it anymore since I can mount the unix domain socket anywhere, I did find this script useful and think others here may as well: https://github.com/wwalker/ssh-find-agent/ https://github.com/wwalker/ssh-find-agent/
- count 13y agoNot quite sure I understand where int he process you need it to be on, but is putting a config script ('/scripts') in the EB deployment repo that sets things up and/or turns on the SSH forwarding that you need? A quick sed script to replace the SSH forwarding line with one that turns it on and a HUP to the daemon, and you'd be good to go? http://docs.aws.amazon.com/elasticbeanstalk/latest/dg/customize-containers-ec2.html#customize-containers-format-container_commands http://docs.aws.amazon.com/elasticbeanstalk/latest/dg/custom... Container commands run 'before' your app is deployed, so you can pull in deps/etc.