Files
box/docs/213-ssh-perms-verification.md
operator-646 97f0e4e50e Verify SSH dial-in perms for container 646
- chmod 600 ~/.ssh/authorized_keys (already 600, verified)
- sshd listening on :22, reverse tunnel VM 127.0.0.1:2226 -> container:22 up
- authorized key present (super@bl); key-auth step belongs to key holder

Fixes #213
2026-10-09 22:49:00 +00:00

1.4 KiB

Ticket #213 verification — SSH key perms and container dial-in (646)

Date: 2026-10-09 ~22:50 UTC Operator: operator-646 (muse-646-patha) Branch: dev/646/213-fix-ssh-perms

1. authorized_keys permissions (port 2226 dial-in)

  • ~/.ssh/authorized_keys (/home/hatch/.ssh/authorized_keys):
    • before: 600 root:root
    • ran chmod 600 ~/.ssh/authorized_keys per ticket
    • after: 600 root:root (no-op — already correct)
  • sshd's requirement (private key file must not be group/world-writable, ideally 600) is satisfied. ~/.ssh itself is 700.

2. Container sshd

  • sshd running (pid 2655, listener, 0 of 10-100 startups).
  • Listening on 0.0.0.0:22 and [::]:22.
  • authorized_keys holds 1 key:
    • ssh-ed25519 SHA256:UOeqKF5BehWNmEpBSk53Qhz0Jd9aQXbFO0VKe2AVo8c (comment super@bl) — dial-in identity belongs to super.

3. Reverse tunnel (VM 2226 → container:22)

  • On VM 34.139.37.135 (as dev-operator-646): 127.0.0.1:2226 and [::1]:2226 are LISTENING — the reverse tunnel is up.
  • Bind is loopback-only (no GatewayPorts), so dial-in must originate from the VM itself — expected for ssh -R forwards.

4. Dial-in path verdict

Container-side prerequisites are all green: perms 600, sshd listening, tunnel established, authorized key present. The final key-auth step can only be completed by the holder of the super@bl private key, so no full loopback auth was attempted from this operator identity.

Fixes #213