fix(install): keep SSH reachable when sshd will start on the target - #417
Open
duketopceo wants to merge 1 commit into
Open
fix(install): keep SSH reachable when sshd will start on the target#417duketopceo wants to merge 1 commit into
duketopceo wants to merge 1 commit into
Conversation
firewall.sh left default-deny-incoming armed for next boot with no SSH allow rule, so any install administered only over SSH lost its access path on first reboot. When sshd.service or sshd.socket is enabled on the installed system, rate-limit-allow SSH before the deny takes effect — limit rather than allow, since an exposed SSH port should still blunt password-guessing. Targets without sshd get no new inbound rule. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #299.
install/config/firewall.sharmed default-deny-incoming for next boot with no SSH allowance, so a headless/remote install lost its only access path at first reboot — before any other way in existed.When
sshd.serviceorsshd.socketis enabled on the installed system, the script now addsufw limit ssh(rate-limited rather than plain allow — an exposed SSH port should still blunt password-guessing). Targets without sshd get no new inbound rule, preserving the deny-everything posture for console-only machines.is-enabledreads unit files from disk so it works correctly inside the install chroot.Test plan
firewall-config-test.shextended: sshd-enabled target gets thelimit sshrule, sshd-absent target opens no port 22, all prior offline/retry cases still pass — 6/6sshd.serviceis enabled — the real-world lockout caseGenerated with Devin