Add WireGuard-only SSH recovery path
This commit is contained in:
@@ -46,7 +46,7 @@ ip -4 route replace default dev wg0
|
||||
ip -6 route replace default dev wg0 2>/dev/null || true
|
||||
|
||||
cleanup() {
|
||||
kill "${proxy_ui_pid:-}" "${proxy_router_pid:-}" 2>/dev/null || true
|
||||
kill "${proxy_ui_pid:-}" "${proxy_router_pid:-}" "${proxy_ssh_pid:-}" 2>/dev/null || true
|
||||
wg-quick down "$RUNTIME" 2>/dev/null || true
|
||||
}
|
||||
trap cleanup EXIT INT TERM
|
||||
@@ -65,4 +65,13 @@ proxy_ui_pid=$!
|
||||
socat TCP-LISTEN:8081,bind=0.0.0.0,reuseaddr,fork TCP:router:8081 &
|
||||
proxy_router_pid=$!
|
||||
|
||||
# Emergency SSH path for unattended operation. Bind explicitly to WireGuard's
|
||||
# IPv4 address, never to a Docker-facing interface or the physical host. The
|
||||
# target is the host-side gateway of the fixed frontend bridge. Host sshd still
|
||||
# enforces its normal key-only authentication policy.
|
||||
wg_ipv4=$(ip -4 -o address show dev wg0 | awk 'NR == 1 { split($4, address, "/"); print address[1] }')
|
||||
[ -n "$wg_ipv4" ] || { echo "WireGuard IPv4 address is missing" >&2; exit 1; }
|
||||
socat TCP-LISTEN:22,bind="$wg_ipv4",reuseaddr,fork TCP:172.30.10.1:22 &
|
||||
proxy_ssh_pid=$!
|
||||
|
||||
wait "$proxy_ui_pid"
|
||||
|
||||
Reference in New Issue
Block a user