Add nginx-ssh image: nginx + sshd for external SSH ingress testing - #21
Merged
Merged
Conversation
Signed-off-by: Nabeel Mohd <mmnabeel317@gmail.com>
3 tasks done
- Run sshd on port 2222 as non-root (no SCC/capabilities needed) - Generate host keys at runtime in /tmp (OpenShift random UID compatible) - Map running UID to 'sshtest' in /etc/passwd at startup - Pubkey-only auth, no PAM, StrictModes disabled for K8s Secret mounts Signed-off-by: Nabeel Mohd <mmnabeel317@gmail.com>
mmnabeel317
force-pushed
the
nginx-ssh-image
branch
from
August 18, 2026 09:32
f127681 to
355415d
Compare
venkataanil
approved these changes
Sep 1, 2026
rsevilla87
approved these changes
Sep 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a new
nginx-sshimage — a variant of the existingnginximage with OpenSSH server added. Used bykube-burner-ocp'scudn-densityworkload to validate external SSH ingress to BGP-advertised CUDN pod IPs.Closes cloud-bulldozer/kube-burner-ocp#491
Changes
nginx-ssh/Dockerfile: Based onubi9/ubi-minimal, installsnginx,openssh-server,openssh-clients,shadow-utils; creates a non-rootsshtestuser and/etc/ssh-authorized-keysdirectory for runtime key injectionnginx-ssh/root/etc/ssh/sshd_config: Configuressshtestfor pubkey-only auth via a mountedAuthorizedKeysFile; setsStrictModes noglobally (required because Kubernetes Secret volumes mount directories as 1777)nginx-ssh/root/entrypoint.sh: Starts sshd then nginx (foreground)nginx-ssh/root/etc/nginx/: Standard nginx config with TLS on 8443 and HTTP on 8080nginx-ssh/root/usr/share/nginx/html/128.html: Minimal response payload for nginx health checksMakefile: Addednginx-sshto the build targetsDesign decisions
nginxecho-style image, since thecudn-densityworkload's existing client/app pods make HTTP/HTTPS requests to the server — SSH is additive, not a replacement128.htmlis included (all other size-variant HTML files removed as unused by the workload)Test plan
podmansshtestwith a mounted public key (on baremetal OpenShift cluster)cudn-density --bgp(20/20 SSH checks passed)/cc @venkataanil