SSH jumphost for accessing internal services via Tailscale.
| User | Shell | Purpose |
|---|---|---|
ssh-admin |
/bin/ash |
Administrative access, can add/remove keys |
ssh-user |
/sbin/nologin |
Port forwarding and tunneling only |
# Switch to staging AWS profile and login to ECR
aws sso login --profile staging
export AWS_PROFILE=staging
ACCOUNT_ID=$(aws sts get-caller-identity --query Account --output text)
aws ecr get-login-password --region us-west-1 | \
docker login --username AWS --password-stdin $ACCOUNT_ID.dkr.ecr.us-west-1.amazonaws.com./build-and-push.sh $ENVIRONMENTcd terraform
tofu workspace select $ENVIRONMENT
tofu apply -target=module.jumphost -var-file=terraform.$ENVIRONMENT.tfvarscd terraform
NLB_DNS=$(tofu output -raw jumphost_nlb_public_dns)ssh ssh-admin@$NLB_DNSFor Hawk human-evaluation sandboxes, the jumphost's authorized_keys is managed automatically: hawk human eval start registers the human's public key when the sandbox starts, and hawk delete removes it. Users get a copy-paste-ready ssh -J command via hawk human eval ssh-command <eval-set-id> instead of constructing the ProxyJump manually.
As ssh-admin:
# Add a public key for ssh-user
sudo /add-public-key.sh "ssh-rsa AAAA... user@example.com"
# Verify key was added
cat /home/ssh-user/.ssh/authorized_keys
# Remove a public key
sudo /remove-public-key.sh "user@example.com"# Add your key
ssh ssh-admin@$NLB_DNS 'sudo /add-public-key.sh "$(cat ~/.ssh/id_ed25519.pub)"'
# Port forwarding example
ssh -N -L 5432:internal-db:5432 ssh-user@$NLB_DNSaws ecs describe-services --cluster $ENVIRONMENT-vivaria --services $ENVIRONMENT-vivaria-jumphost \
--query 'services[0].{running:runningCount,desired:desiredCount}'aws logs tail /ecs/$ENVIRONMENT-vivaria-jumphost --follow --since 5mAfter redeployment, clear the old host key:
ssh-keygen -R $NLB_DNS