Skip to content

Add nginx-ssh image: nginx + sshd for external SSH ingress testing - #21

Merged
rsevilla87 merged 2 commits into
cloud-bulldozer:mainfrom
mmnabeel317:nginx-ssh-image
Sep 1, 2026
Merged

rsevilla87 merged 2 commits into
cloud-bulldozer:mainfrom
mmnabeel317:nginx-ssh-image

Conversation

@mmnabeel317

Copy link
Copy Markdown
Contributor

Summary

Adds a new nginx-ssh image — a variant of the existing nginx image with OpenSSH server added. Used by kube-burner-ocp's cudn-density workload to validate external SSH ingress to BGP-advertised CUDN pod IPs.

Closes cloud-bulldozer/kube-burner-ocp#491

Changes

  • nginx-ssh/Dockerfile: Based on ubi9/ubi-minimal, installs nginx, openssh-server, openssh-clients, shadow-utils; creates a non-root sshtest user and /etc/ssh-authorized-keys directory for runtime key injection
  • nginx-ssh/root/etc/ssh/sshd_config: Configures sshtest for pubkey-only auth via a mounted AuthorizedKeysFile; sets StrictModes no globally (required because Kubernetes Secret volumes mount directories as 1777)
  • nginx-ssh/root/entrypoint.sh: Starts sshd then nginx (foreground)
  • nginx-ssh/root/etc/nginx/: Standard nginx config with TLS on 8443 and HTTP on 8080
  • nginx-ssh/root/usr/share/nginx/html/128.html: Minimal response payload for nginx health checks
  • Makefile: Added nginx-ssh to the build targets

Design decisions

  • Kept the full nginx stack (TLS/8443, mime.types, etc.) rather than a minimal nginxecho-style image, since the cudn-density workload's existing client/app pods make HTTP/HTTPS requests to the server — SSH is additive, not a replacement
  • No SSH credentials baked into the image; the authorized key is mounted at runtime via a Kubernetes Secret
  • Only 128.html is included (all other size-variant HTML files removed as unused by the workload)

Test plan

  • Verified image builds and runs locally with podman
  • Verified SSH login works as sshtest with a mounted public key (on baremetal OpenShift cluster)
  • Verified end-to-end with cudn-density --bgp (20/20 SSH checks passed)

/cc @venkataanil

Signed-off-by: Nabeel Mohd <mmnabeel317@gmail.com>
- Run sshd on port 2222 as non-root (no SCC/capabilities needed)
- Generate host keys at runtime in /tmp (OpenShift random UID compatible)
- Map running UID to 'sshtest' in /etc/passwd at startup
- Pubkey-only auth, no PAM, StrictModes disabled for K8s Secret mounts

Signed-off-by: Nabeel Mohd <mmnabeel317@gmail.com>
@rsevilla87
rsevilla87 merged commit 947c571 into cloud-bulldozer:main Sep 1, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants