Merge pull request #3920 from dokku/ssh-keys-user-list

Add the ability to list ssh keys for a specific user
This commit is contained in:
Jose Diaz-Gonzalez
2020-04-04 03:47:37 -04:00
committed by GitHub
6 changed files with 148 additions and 51 deletions

View File

@@ -2,7 +2,7 @@ DOKKU_VERSION ?= master
PROCFILE_VERSION ?= 0.6.0
PLUGN_VERSION ?= 0.3.2
SSHCOMMAND_VERSION ?= 0.8.0
SSHCOMMAND_VERSION ?= 0.10.0
SSHCOMMAND_URL ?= https://github.com/dokku/sshcommand/releases/download/v${SSHCOMMAND_VERSION}/sshcommand_${SSHCOMMAND_VERSION}_linux_x86_64.tgz
PROCFILE_UTIL_URL ?= https://github.com/josegonzalez/go-procfile-util/releases/download/v${PROCFILE_VERSION}/procfile-util_${PROCFILE_VERSION}_linux_x86_64.tgz
PLUGN_URL ?= https://github.com/dokku/plugn/releases/download/v${PLUGN_VERSION}/plugn_${PLUGN_VERSION}_linux_x86_64.tgz

2
debian/control vendored
View File

@@ -3,7 +3,7 @@ Version: 0.20.1
Section: web
Priority: optional
Architecture: amd64
Depends: locales, git, cpio, curl, man-db, netcat, sshcommand (>= 0.6.0), gliderlabs-sigil, docker-engine-cs (>= 1.13.0) | docker-engine (>= 1.13.0) | docker-io (>= 1.13.0) | docker.io (>= 1.13.0) | docker-ce (>= 1.13.0) | docker-ee (>= 1.13.0), net-tools, software-properties-common, procfile-util, python-software-properties | python3-software-properties, rsyslog, dos2unix, jq
Depends: locales, git, cpio, curl, man-db, netcat, sshcommand (>= 0.10.0), gliderlabs-sigil, docker-engine-cs (>= 1.13.0) | docker-engine (>= 1.13.0) | docker-io (>= 1.13.0) | docker.io (>= 1.13.0) | docker-ce (>= 1.13.0) | docker-ee (>= 1.13.0), net-tools, software-properties-common, procfile-util, python-software-properties | python3-software-properties, rsyslog, dos2unix, jq
Recommends: herokuish (>= 0.3.4), parallel, dokku-update, dokku-event-listener
Pre-Depends: nginx (>= 1.8.0) | openresty, dnsutils, cgroupfs-mount | cgroup-lite, plugn (>= 0.3.0), sudo, python3, debconf
Maintainer: Jose Diaz-Gonzalez <dokku@josediazgonzalez.com>

View File

@@ -4,7 +4,7 @@
```
ssh-keys:add <name> [/path/to/key] # Add a new public key by pipe or path
ssh-keys:list # List of all authorized Dokku public ssh keys
ssh-keys:list [<name>] # List of all authorized Dokku public ssh keys
ssh-keys:remove <name> # Remove SSH public key by name
```
@@ -25,7 +25,7 @@ dokku ssh-keys:list
```
```
61:21:1f:88:7f:86:d4:3a:68:9f:18:aa:41:4f:bc:3d NAME="admin" SSHCOMMAND_ALLOWED_KEYS="no-agent-forwarding,no-user-rc,no-X11-forwarding,no-port-forwarding"
SHA256:ABC123ABC123+abc123abc123Zabc123abcZ123abc NAME="admin" SSHCOMMAND_ALLOWED_KEYS="no-agent-forwarding,no-user-rc,no-X11-forwarding,no-port-forwarding"
```
The output contains the following information:
@@ -34,6 +34,14 @@ The output contains the following information:
- The `KEY_NAME`.
- A comma separated list of SSH options under the `SSHCOMMAND_ALLOWED_KEYS` name.
> New as of 0.20.2
The keys for a specific user may be listed by specifying a second argument to the `ssh-keys:list` command:
```shell
dokku ssh-keys:list admin
```
### Adding SSH keys
You can add your public key to Dokku with the `ssh-keys:add` command. The output will be the fingerprint of the SSH key:
@@ -43,7 +51,7 @@ dokku ssh-keys:add KEY_NAME path/to/id_rsa.pub
```
```
b7:76:27:4f:30:90:21:ae:d4:1e:70:20:35:3f:06:d6
SHA256:ABC123ABC123+abc123abc123Zabc123abcZ123abc
```
`KEY_NAME` is the name you want to use to refer to this particular key. Including the word `admin` in the name will grant the user privileges to add additional keys remotely.

View File

@@ -8,9 +8,10 @@ cmd-ssh-keys-list() {
declare desc="List ssh key hashes"
declare cmd="ssh-keys:list"
[[ "$1" == "$cmd" ]] && shift 1
declare SSH_NAME="$1"
verify_ssh_key_file
sshcommand list dokku
sshcommand list dokku "$SSH_NAME"
}
cmd-ssh-keys-list "$@"

2
rpm.mk
View File

@@ -73,7 +73,7 @@ endif
--depends 'plugn' \
--depends 'procfile-util' \
--depends 'python' \
--depends 'sshcommand' \
--depends 'sshcommand >= 0.10.0' \
--depends 'sudo' \
--after-install rpm/dokku.postinst \
--url "https://github.com/$(DOKKU_REPO_NAME)" \

View File

@@ -50,63 +50,151 @@ teardown() {
assert_output "$help_output"
}
@test "(ssh-keys) ssh-keys:add, ssh-keys:list, ssh-keys:remove" {
run /bin/bash -c "dokku ssh-keys:add name1 /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "cat /tmp/testkey.pub | dokku ssh-keys:add name2"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:list | grep name1 && dokku ssh-keys:list | grep name2"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:remove name1"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c 'echo "" >> "${DOKKU_ROOT:-/home/dokku}/.ssh/authorized_keys"'
run /bin/bash -c 'echo "" >> "${DOKKU_ROOT:-/home/dokku}/.ssh/authorized_keys"'
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:list"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:list | grep name1"
@test "(ssh-keys) ssh-keys:add" {
run /bin/bash -c "dokku ssh-keys:add name1 /tmp/testkey-double.pub"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:list | grep name2"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:add name3 /tmp/testkey-double.pub"
run /bin/bash -c "dokku ssh-keys:add name2 /tmp/testkey-invalid.pub"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:add name4 /tmp/testkey-invalid.pub"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:add name4 /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:add name5 /tmp/testkey-no-newline.pub"
run /bin/bash -c "dokku ssh-keys:add name3 /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_success
# leave this as the last test in the sequence! It introduces an error in authorized_keys
run /bin/bash -c 'echo invalid >> "${DOKKU_ROOT:-/home/dokku}/.ssh/authorized_keys"'
run /bin/bash -c "dokku ssh-keys:list name3"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:add name5 /tmp/testkey.pub"
run /bin/bash -c "dokku ssh-keys:add name4 /tmp/testkey-no-newline.pub"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:list name4"
echo "output: $output"
echo "status: $status"
assert_success
}
@test "(ssh-keys) ssh-keys:add FILE" {
run /bin/bash -c "dokku ssh-keys:add name /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:add name /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "cat /tmp/testkey.pub | dokku ssh-keys:add name"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:add other-name /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "cat /tmp/testkey.pub | dokku ssh-keys:add other-name"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:list name"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:list other-name"
echo "output: $output"
echo "status: $status"
assert_failure
}
@test "(ssh-keys) ssh-keys:add stdin" {
run /bin/bash -c "cat /tmp/testkey.pub | dokku ssh-keys:add name"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:add name /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "cat /tmp/testkey.pub | dokku ssh-keys:add name"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:add other-name /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "cat /tmp/testkey.pub | dokku ssh-keys:add other-name"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:list name"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:list other-name"
echo "output: $output"
echo "status: $status"
assert_failure
}
@test "(ssh-keys) ssh-keys:add invalid" {
run /bin/bash -c 'echo invalid >> "${DOKKU_ROOT:-/home/dokku}/.ssh/authorized_keys"'
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:add name5 /tmp/testkey.pub"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:list"
echo "output: $output"
echo "status: $status"
assert_failure
}
@test "(ssh-keys) ssh-keys:list" {
run /bin/bash -c "dokku ssh-keys:list"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c 'echo "" >> "${DOKKU_ROOT:-/home/dokku}/.ssh/authorized_keys"'
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:list"
echo "output: $output"
echo "status: $status"
assert_success
run /bin/bash -c "dokku ssh-keys:list | grep name1"
echo "output: $output"
echo "status: $status"
assert_failure
run /bin/bash -c "dokku ssh-keys:list name1"
echo "output: $output"
echo "status: $status"
assert_failure