Skip to content

Latest commit

 

History

History
 
 

Folders and files

README.md

Vivaria Jumphost

SSH jumphost for accessing internal services via Tailscale.

Users

User Shell Purpose
ssh-admin /bin/ash Administrative access, can add/remove keys
ssh-user /sbin/nologin Port forwarding and tunneling only

Building and Deploying

Prerequisites

# Switch to staging AWS profile and login to ECR
aws sso login --profile staging
export AWS_PROFILE=staging

ACCOUNT_ID=$(aws sts get-caller-identity --query Account --output text)
aws ecr get-login-password --region us-west-1 | \
  docker login --username AWS --password-stdin $ACCOUNT_ID.dkr.ecr.us-west-1.amazonaws.com

Build and Push

./build-and-push.sh $ENVIRONMENT

Deploy Infrastructure

cd terraform
tofu workspace select $ENVIRONMENT
tofu apply -target=module.jumphost -var-file=terraform.$ENVIRONMENT.tfvars

Manual Testing

Get NLB DNS

cd terraform
NLB_DNS=$(tofu output -raw jumphost_nlb_public_dns)

SSH as Admin

ssh ssh-admin@$NLB_DNS

Human Evaluations via Hawk

For Hawk human-evaluation sandboxes, the jumphost's authorized_keys is managed automatically: hawk human eval start registers the human's public key when the sandbox starts, and hawk delete removes it. Users get a copy-paste-ready ssh -J command via hawk human eval ssh-command <eval-set-id> instead of constructing the ProxyJump manually.

Key Management

As ssh-admin:

# Add a public key for ssh-user
sudo /add-public-key.sh "ssh-rsa AAAA... user@example.com"

# Verify key was added
cat /home/ssh-user/.ssh/authorized_keys

# Remove a public key
sudo /remove-public-key.sh "user@example.com"

Test ssh-user Access

# Add your key
ssh ssh-admin@$NLB_DNS 'sudo /add-public-key.sh "$(cat ~/.ssh/id_ed25519.pub)"'

# Port forwarding example
ssh -N -L 5432:internal-db:5432 ssh-user@$NLB_DNS

Troubleshooting

Check ECS Task Status

aws ecs describe-services --cluster $ENVIRONMENT-vivaria --services $ENVIRONMENT-vivaria-jumphost \
  --query 'services[0].{running:runningCount,desired:desiredCount}'

View Logs

aws logs tail /ecs/$ENVIRONMENT-vivaria-jumphost --follow --since 5m

Host Key Changed Warning

After redeployment, clear the old host key:

ssh-keygen -R $NLB_DNS