This repository was archived by the owner on Mar 24, 2025. It is now read-only.

Repository files navigation

docker-ssh-exec - Secure SSH key injection for Docker builds

Allows commands that require an SSH key to be run from within a Dockerfile, without leaving the key in the resulting image.


Overview

This program runs in two different modes:

  • a server mode, run as the Docker image mdsol/docker-ssh-exec, which transmits an SSH key on request to the the client; and
  • a client mode, invoked from within the Dockerfile, that grabs the key from the server, writes it to the filesystem, runs the desired build command, and then deletes the key before the filesystem is snapshotted into the build.

Installation

To install the server, just pull mdsol/docker-ssh-exec like any other Docker image.

To install the client, just grab it from the releases page, uncompress the archive, and copy the binary to somewhere in your $PATH. Remember that the client is run during the docker build... process, so either install the client just before invoking it, or make sure it's already present in your source image. Here's an example of the code you might run in your source image, to prepare it for SSH cloning from GitHub:

# install Medidata docker-ssh-exec build tool from S3 bucket "mybucket"
curl https://s3.amazonaws.com/mybucket/docker-ssh-exec/\
docker-ssh-exec_0.5.1_linux_amd64.tar.gz | \
tar -xz --strip-components=1 -C /usr/local/bin \
docker-ssh-exec_0.5.1_linux_amd64/docker-ssh-exec
mkdir -p /root/.ssh && chmod 0700 /root/.ssh
ssh-keyscan github.com >/root/.ssh/known_hosts

Usage

To run the server component, pass it the private half of your SSH key, either as a shared volume:

docker run -v ~/.ssh/id_rsa:/root/.ssh/id_rsa --name=keyserver -d \
mdsol/docker-ssh-exec -server

or as an ENV var:

docker run -e DOCKER-SSH-KEY="$(cat ~/.ssh/id_rsa)" --name=keyserver -d \
mdsol/docker-ssh-exec -server

The benefit of this second method is that OS X systems using a virtual Docker host cannot easily use Docker's shared volume feature with files on the OS X side. The drawback is that the kay data is exposed in the process list.

Then, run a quick test of the client, to make sure it can get the key:

docker run --rm -it mdsol/docker-ssh-exec cat /root/.ssh/id_rsa

Finally, as long as the source image is set up to trust (or ignore) GitHub's server key, you can clone private repositories from within the Dockerfile like this:

docker-exec-ssh git clone git@github.com:my_user/my_private_repo.git

The client first transfers the key from the server, writing it to $HOME/.ssh/id_rsa (by default), then executes whatever command you supply as arguments. Before exiting, it deletes the key from the filesystem.

Here's the command-line help:

Usage of docker-ssh-exec:
-key string
path to key file (default "~/.ssh/id_rsa")
-port int
server receiving port (default 1067)
-pwd string
password for encrypted RSA key
-server
run key server instead of command
-version
print version and exit
-wait int
client timeout, in seconds (default 3)

The software quits with a non-zero exit code (>100) on any error -- except a timeout from the keyserver, in which case it will just ignore the timeout and try to run the build command anyway. If the build command fails, docker-ssh-exec returns the exit code of the failed command.


Known Limitations / Bugs

The key data is limited to 4096 bytes.

On macOS 10.14 or later, the default format of ssh-keygen will produce an "OpenSSH private key" (reference). For example:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/before_rsa
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in ${HOME}/.ssh/before_rsa.
Your public key has been saved in ${HOME}/.ssh/before_rsa.pub.
The key fingerprint is:
...
$ head -2 ~/.ssh/before_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAZOJlIwH

To use a passphrase, this library requires an actual "RSA private key". To make ssh-keygen produce one, use the -m (key format) flag:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/after_rsa -m PEM
...
$ head -5 ~/.ssh/after_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,70B1F7ECFCC66C9DF073996B92D3C01E
GNhm2zcN6oz+K9yZimDMx6w5PD+mDz7ylVulz+PnYVP5TVs4yZuVZF3GGlu/NYZ1

Contribution / Development

This software was created by Benton Roberts (broberts@mdsol.com)

To build it yourself, just go get and go install as usual:

go get github.com/mdsol/docker-ssh-exec
cd $GOPATH/src/github.com/mdsol/docker-ssh-exec
go install

About

Secure SSH key injection for Docker builds

Topics

Resources

Stars

88 stars

Watchers

101 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
This repository was archived by the owner on Mar 24, 2025. It is now read-only.

Repository files navigation

docker-ssh-exec - Secure SSH key injection for Docker builds

Allows commands that require an SSH key to be run from within a Dockerfile, without leaving the key in the resulting image.


Overview

This program runs in two different modes:

  • a server mode, run as the Docker image mdsol/docker-ssh-exec, which transmits an SSH key on request to the the client; and
  • a client mode, invoked from within the Dockerfile, that grabs the key from the server, writes it to the filesystem, runs the desired build command, and then deletes the key before the filesystem is snapshotted into the build.

Installation

To install the server, just pull mdsol/docker-ssh-exec like any other Docker image.

To install the client, just grab it from the releases page, uncompress the archive, and copy the binary to somewhere in your $PATH. Remember that the client is run during the docker build... process, so either install the client just before invoking it, or make sure it's already present in your source image. Here's an example of the code you might run in your source image, to prepare it for SSH cloning from GitHub:

# install Medidata docker-ssh-exec build tool from S3 bucket "mybucket"
curl https://s3.amazonaws.com/mybucket/docker-ssh-exec/\
docker-ssh-exec_0.5.1_linux_amd64.tar.gz | \
tar -xz --strip-components=1 -C /usr/local/bin \
docker-ssh-exec_0.5.1_linux_amd64/docker-ssh-exec
mkdir -p /root/.ssh && chmod 0700 /root/.ssh
ssh-keyscan github.com >/root/.ssh/known_hosts

Usage

To run the server component, pass it the private half of your SSH key, either as a shared volume:

docker run -v ~/.ssh/id_rsa:/root/.ssh/id_rsa --name=keyserver -d \
mdsol/docker-ssh-exec -server

or as an ENV var:

docker run -e DOCKER-SSH-KEY="$(cat ~/.ssh/id_rsa)" --name=keyserver -d \
mdsol/docker-ssh-exec -server

The benefit of this second method is that OS X systems using a virtual Docker host cannot easily use Docker's shared volume feature with files on the OS X side. The drawback is that the kay data is exposed in the process list.

Then, run a quick test of the client, to make sure it can get the key:

docker run --rm -it mdsol/docker-ssh-exec cat /root/.ssh/id_rsa

Finally, as long as the source image is set up to trust (or ignore) GitHub's server key, you can clone private repositories from within the Dockerfile like this:

docker-exec-ssh git clone git@github.com:my_user/my_private_repo.git

The client first transfers the key from the server, writing it to $HOME/.ssh/id_rsa (by default), then executes whatever command you supply as arguments. Before exiting, it deletes the key from the filesystem.

Here's the command-line help:

Usage of docker-ssh-exec:
-key string
path to key file (default "~/.ssh/id_rsa")
-port int
server receiving port (default 1067)
-pwd string
password for encrypted RSA key
-server
run key server instead of command
-version
print version and exit
-wait int
client timeout, in seconds (default 3)

The software quits with a non-zero exit code (>100) on any error -- except a timeout from the keyserver, in which case it will just ignore the timeout and try to run the build command anyway. If the build command fails, docker-ssh-exec returns the exit code of the failed command.


Known Limitations / Bugs

The key data is limited to 4096 bytes.

On macOS 10.14 or later, the default format of ssh-keygen will produce an "OpenSSH private key" (reference). For example:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/before_rsa
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in ${HOME}/.ssh/before_rsa.
Your public key has been saved in ${HOME}/.ssh/before_rsa.pub.
The key fingerprint is:
...
$ head -2 ~/.ssh/before_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAZOJlIwH

To use a passphrase, this library requires an actual "RSA private key". To make ssh-keygen produce one, use the -m (key format) flag:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/after_rsa -m PEM
...
$ head -5 ~/.ssh/after_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,70B1F7ECFCC66C9DF073996B92D3C01E
GNhm2zcN6oz+K9yZimDMx6w5PD+mDz7ylVulz+PnYVP5TVs4yZuVZF3GGlu/NYZ1

Contribution / Development

This software was created by Benton Roberts (broberts@mdsol.com)

To build it yourself, just go get and go install as usual:

go get github.com/mdsol/docker-ssh-exec
cd $GOPATH/src/github.com/mdsol/docker-ssh-exec
go install

About

Secure SSH key injection for Docker builds

Topics

Resources

Stars

88 stars

Watchers

101 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Mar 24, 2025. It is now read-only.

Repository files navigation

docker-ssh-exec - Secure SSH key injection for Docker builds

Allows commands that require an SSH key to be run from within a Dockerfile, without leaving the key in the resulting image.


Overview

This program runs in two different modes:

  • a server mode, run as the Docker image mdsol/docker-ssh-exec, which transmits an SSH key on request to the the client; and
  • a client mode, invoked from within the Dockerfile, that grabs the key from the server, writes it to the filesystem, runs the desired build command, and then deletes the key before the filesystem is snapshotted into the build.

Installation

To install the server, just pull mdsol/docker-ssh-exec like any other Docker image.

To install the client, just grab it from the releases page, uncompress the archive, and copy the binary to somewhere in your $PATH. Remember that the client is run during the docker build... process, so either install the client just before invoking it, or make sure it's already present in your source image. Here's an example of the code you might run in your source image, to prepare it for SSH cloning from GitHub:

# install Medidata docker-ssh-exec build tool from S3 bucket "mybucket"
curl https://s3.amazonaws.com/mybucket/docker-ssh-exec/\
docker-ssh-exec_0.5.1_linux_amd64.tar.gz | \
tar -xz --strip-components=1 -C /usr/local/bin \
docker-ssh-exec_0.5.1_linux_amd64/docker-ssh-exec
mkdir -p /root/.ssh && chmod 0700 /root/.ssh
ssh-keyscan github.com >/root/.ssh/known_hosts

Usage

To run the server component, pass it the private half of your SSH key, either as a shared volume:

docker run -v ~/.ssh/id_rsa:/root/.ssh/id_rsa --name=keyserver -d \
mdsol/docker-ssh-exec -server

or as an ENV var:

docker run -e DOCKER-SSH-KEY="$(cat ~/.ssh/id_rsa)" --name=keyserver -d \
mdsol/docker-ssh-exec -server

The benefit of this second method is that OS X systems using a virtual Docker host cannot easily use Docker's shared volume feature with files on the OS X side. The drawback is that the kay data is exposed in the process list.

Then, run a quick test of the client, to make sure it can get the key:

docker run --rm -it mdsol/docker-ssh-exec cat /root/.ssh/id_rsa

Finally, as long as the source image is set up to trust (or ignore) GitHub's server key, you can clone private repositories from within the Dockerfile like this:

docker-exec-ssh git clone git@github.com:my_user/my_private_repo.git

The client first transfers the key from the server, writing it to $HOME/.ssh/id_rsa (by default), then executes whatever command you supply as arguments. Before exiting, it deletes the key from the filesystem.

Here's the command-line help:

Usage of docker-ssh-exec:
-key string
path to key file (default "~/.ssh/id_rsa")
-port int
server receiving port (default 1067)
-pwd string
password for encrypted RSA key
-server
run key server instead of command
-version
print version and exit
-wait int
client timeout, in seconds (default 3)

The software quits with a non-zero exit code (>100) on any error -- except a timeout from the keyserver, in which case it will just ignore the timeout and try to run the build command anyway. If the build command fails, docker-ssh-exec returns the exit code of the failed command.


Known Limitations / Bugs

The key data is limited to 4096 bytes.

On macOS 10.14 or later, the default format of ssh-keygen will produce an "OpenSSH private key" (reference). For example:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/before_rsa
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in ${HOME}/.ssh/before_rsa.
Your public key has been saved in ${HOME}/.ssh/before_rsa.pub.
The key fingerprint is:
...
$ head -2 ~/.ssh/before_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAZOJlIwH

To use a passphrase, this library requires an actual "RSA private key". To make ssh-keygen produce one, use the -m (key format) flag:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/after_rsa -m PEM
...
$ head -5 ~/.ssh/after_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,70B1F7ECFCC66C9DF073996B92D3C01E
GNhm2zcN6oz+K9yZimDMx6w5PD+mDz7ylVulz+PnYVP5TVs4yZuVZF3GGlu/NYZ1

Contribution / Development

This software was created by Benton Roberts (broberts@mdsol.com)

To build it yourself, just go get and go install as usual:

go get github.com/mdsol/docker-ssh-exec
cd $GOPATH/src/github.com/mdsol/docker-ssh-exec
go install

About

Secure SSH key injection for Docker builds

Topics

Resources

Stars

88 stars

Watchers

101 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Mar 24, 2025. It is now read-only.

Repository files navigation

docker-ssh-exec - Secure SSH key injection for Docker builds

Allows commands that require an SSH key to be run from within a Dockerfile, without leaving the key in the resulting image.


Overview

This program runs in two different modes:

  • a server mode, run as the Docker image mdsol/docker-ssh-exec, which transmits an SSH key on request to the the client; and
  • a client mode, invoked from within the Dockerfile, that grabs the key from the server, writes it to the filesystem, runs the desired build command, and then deletes the key before the filesystem is snapshotted into the build.

Installation

To install the server, just pull mdsol/docker-ssh-exec like any other Docker image.

To install the client, just grab it from the releases page, uncompress the archive, and copy the binary to somewhere in your $PATH. Remember that the client is run during the docker build... process, so either install the client just before invoking it, or make sure it's already present in your source image. Here's an example of the code you might run in your source image, to prepare it for SSH cloning from GitHub:

# install Medidata docker-ssh-exec build tool from S3 bucket "mybucket"
curl https://s3.amazonaws.com/mybucket/docker-ssh-exec/\
docker-ssh-exec_0.5.1_linux_amd64.tar.gz | \
tar -xz --strip-components=1 -C /usr/local/bin \
docker-ssh-exec_0.5.1_linux_amd64/docker-ssh-exec
mkdir -p /root/.ssh && chmod 0700 /root/.ssh
ssh-keyscan github.com >/root/.ssh/known_hosts

Usage

To run the server component, pass it the private half of your SSH key, either as a shared volume:

docker run -v ~/.ssh/id_rsa:/root/.ssh/id_rsa --name=keyserver -d \
mdsol/docker-ssh-exec -server

or as an ENV var:

docker run -e DOCKER-SSH-KEY="$(cat ~/.ssh/id_rsa)" --name=keyserver -d \
mdsol/docker-ssh-exec -server

The benefit of this second method is that OS X systems using a virtual Docker host cannot easily use Docker's shared volume feature with files on the OS X side. The drawback is that the kay data is exposed in the process list.

Then, run a quick test of the client, to make sure it can get the key:

docker run --rm -it mdsol/docker-ssh-exec cat /root/.ssh/id_rsa

Finally, as long as the source image is set up to trust (or ignore) GitHub's server key, you can clone private repositories from within the Dockerfile like this:

docker-exec-ssh git clone git@github.com:my_user/my_private_repo.git

The client first transfers the key from the server, writing it to $HOME/.ssh/id_rsa (by default), then executes whatever command you supply as arguments. Before exiting, it deletes the key from the filesystem.

Here's the command-line help:

Usage of docker-ssh-exec:
-key string
path to key file (default "~/.ssh/id_rsa")
-port int
server receiving port (default 1067)
-pwd string
password for encrypted RSA key
-server
run key server instead of command
-version
print version and exit
-wait int
client timeout, in seconds (default 3)

The software quits with a non-zero exit code (>100) on any error -- except a timeout from the keyserver, in which case it will just ignore the timeout and try to run the build command anyway. If the build command fails, docker-ssh-exec returns the exit code of the failed command.


Known Limitations / Bugs

The key data is limited to 4096 bytes.

On macOS 10.14 or later, the default format of ssh-keygen will produce an "OpenSSH private key" (reference). For example:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/before_rsa
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in ${HOME}/.ssh/before_rsa.
Your public key has been saved in ${HOME}/.ssh/before_rsa.pub.
The key fingerprint is:
...
$ head -2 ~/.ssh/before_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAZOJlIwH

To use a passphrase, this library requires an actual "RSA private key". To make ssh-keygen produce one, use the -m (key format) flag:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/after_rsa -m PEM
...
$ head -5 ~/.ssh/after_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,70B1F7ECFCC66C9DF073996B92D3C01E
GNhm2zcN6oz+K9yZimDMx6w5PD+mDz7ylVulz+PnYVP5TVs4yZuVZF3GGlu/NYZ1

Contribution / Development

This software was created by Benton Roberts (broberts@mdsol.com)

To build it yourself, just go get and go install as usual:

go get github.com/mdsol/docker-ssh-exec
cd $GOPATH/src/github.com/mdsol/docker-ssh-exec
go install

About

Secure SSH key injection for Docker builds

Topics

Resources

Stars

88 stars

Watchers

101 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
This repository was archived by the owner on Mar 24, 2025. It is now read-only.

Repository files navigation

docker-ssh-exec - Secure SSH key injection for Docker builds

Allows commands that require an SSH key to be run from within a Dockerfile, without leaving the key in the resulting image.


Overview

This program runs in two different modes:

  • a server mode, run as the Docker image mdsol/docker-ssh-exec, which transmits an SSH key on request to the the client; and
  • a client mode, invoked from within the Dockerfile, that grabs the key from the server, writes it to the filesystem, runs the desired build command, and then deletes the key before the filesystem is snapshotted into the build.

Installation

To install the server, just pull mdsol/docker-ssh-exec like any other Docker image.

To install the client, just grab it from the releases page, uncompress the archive, and copy the binary to somewhere in your $PATH. Remember that the client is run during the docker build... process, so either install the client just before invoking it, or make sure it's already present in your source image. Here's an example of the code you might run in your source image, to prepare it for SSH cloning from GitHub:

# install Medidata docker-ssh-exec build tool from S3 bucket "mybucket"
curl https://s3.amazonaws.com/mybucket/docker-ssh-exec/\
docker-ssh-exec_0.5.1_linux_amd64.tar.gz | \
tar -xz --strip-components=1 -C /usr/local/bin \
docker-ssh-exec_0.5.1_linux_amd64/docker-ssh-exec
mkdir -p /root/.ssh && chmod 0700 /root/.ssh
ssh-keyscan github.com >/root/.ssh/known_hosts

Usage

To run the server component, pass it the private half of your SSH key, either as a shared volume:

docker run -v ~/.ssh/id_rsa:/root/.ssh/id_rsa --name=keyserver -d \
mdsol/docker-ssh-exec -server

or as an ENV var:

docker run -e DOCKER-SSH-KEY="$(cat ~/.ssh/id_rsa)" --name=keyserver -d \
mdsol/docker-ssh-exec -server

The benefit of this second method is that OS X systems using a virtual Docker host cannot easily use Docker's shared volume feature with files on the OS X side. The drawback is that the kay data is exposed in the process list.

Then, run a quick test of the client, to make sure it can get the key:

docker run --rm -it mdsol/docker-ssh-exec cat /root/.ssh/id_rsa

Finally, as long as the source image is set up to trust (or ignore) GitHub's server key, you can clone private repositories from within the Dockerfile like this:

docker-exec-ssh git clone git@github.com:my_user/my_private_repo.git

The client first transfers the key from the server, writing it to $HOME/.ssh/id_rsa (by default), then executes whatever command you supply as arguments. Before exiting, it deletes the key from the filesystem.

Here's the command-line help:

Usage of docker-ssh-exec:
-key string
path to key file (default "~/.ssh/id_rsa")
-port int
server receiving port (default 1067)
-pwd string
password for encrypted RSA key
-server
run key server instead of command
-version
print version and exit
-wait int
client timeout, in seconds (default 3)

The software quits with a non-zero exit code (>100) on any error -- except a timeout from the keyserver, in which case it will just ignore the timeout and try to run the build command anyway. If the build command fails, docker-ssh-exec returns the exit code of the failed command.


Known Limitations / Bugs

The key data is limited to 4096 bytes.

On macOS 10.14 or later, the default format of ssh-keygen will produce an "OpenSSH private key" (reference). For example:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/before_rsa
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in ${HOME}/.ssh/before_rsa.
Your public key has been saved in ${HOME}/.ssh/before_rsa.pub.
The key fingerprint is:
...
$ head -2 ~/.ssh/before_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAZOJlIwH

To use a passphrase, this library requires an actual "RSA private key". To make ssh-keygen produce one, use the -m (key format) flag:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/after_rsa -m PEM
...
$ head -5 ~/.ssh/after_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,70B1F7ECFCC66C9DF073996B92D3C01E
GNhm2zcN6oz+K9yZimDMx6w5PD+mDz7ylVulz+PnYVP5TVs4yZuVZF3GGlu/NYZ1

Contribution / Development

This software was created by Benton Roberts (broberts@mdsol.com)

To build it yourself, just go get and go install as usual:

go get github.com/mdsol/docker-ssh-exec
cd $GOPATH/src/github.com/mdsol/docker-ssh-exec
go install

About

Secure SSH key injection for Docker builds

Topics

Resources

Stars

88 stars

Watchers

101 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Mar 24, 2025. It is now read-only.

Repository files navigation

docker-ssh-exec - Secure SSH key injection for Docker builds

Allows commands that require an SSH key to be run from within a Dockerfile, without leaving the key in the resulting image.


Overview

This program runs in two different modes:

  • a server mode, run as the Docker image mdsol/docker-ssh-exec, which transmits an SSH key on request to the the client; and
  • a client mode, invoked from within the Dockerfile, that grabs the key from the server, writes it to the filesystem, runs the desired build command, and then deletes the key before the filesystem is snapshotted into the build.

Installation

To install the server, just pull mdsol/docker-ssh-exec like any other Docker image.

To install the client, just grab it from the releases page, uncompress the archive, and copy the binary to somewhere in your $PATH. Remember that the client is run during the docker build... process, so either install the client just before invoking it, or make sure it's already present in your source image. Here's an example of the code you might run in your source image, to prepare it for SSH cloning from GitHub:

# install Medidata docker-ssh-exec build tool from S3 bucket "mybucket"
curl https://s3.amazonaws.com/mybucket/docker-ssh-exec/\
docker-ssh-exec_0.5.1_linux_amd64.tar.gz | \
tar -xz --strip-components=1 -C /usr/local/bin \
docker-ssh-exec_0.5.1_linux_amd64/docker-ssh-exec
mkdir -p /root/.ssh && chmod 0700 /root/.ssh
ssh-keyscan github.com >/root/.ssh/known_hosts

Usage

To run the server component, pass it the private half of your SSH key, either as a shared volume:

docker run -v ~/.ssh/id_rsa:/root/.ssh/id_rsa --name=keyserver -d \
mdsol/docker-ssh-exec -server

or as an ENV var:

docker run -e DOCKER-SSH-KEY="$(cat ~/.ssh/id_rsa)" --name=keyserver -d \
mdsol/docker-ssh-exec -server

The benefit of this second method is that OS X systems using a virtual Docker host cannot easily use Docker's shared volume feature with files on the OS X side. The drawback is that the kay data is exposed in the process list.

Then, run a quick test of the client, to make sure it can get the key:

docker run --rm -it mdsol/docker-ssh-exec cat /root/.ssh/id_rsa

Finally, as long as the source image is set up to trust (or ignore) GitHub's server key, you can clone private repositories from within the Dockerfile like this:

docker-exec-ssh git clone git@github.com:my_user/my_private_repo.git

The client first transfers the key from the server, writing it to $HOME/.ssh/id_rsa (by default), then executes whatever command you supply as arguments. Before exiting, it deletes the key from the filesystem.

Here's the command-line help:

Usage of docker-ssh-exec:
-key string
path to key file (default "~/.ssh/id_rsa")
-port int
server receiving port (default 1067)
-pwd string
password for encrypted RSA key
-server
run key server instead of command
-version
print version and exit
-wait int
client timeout, in seconds (default 3)

The software quits with a non-zero exit code (>100) on any error -- except a timeout from the keyserver, in which case it will just ignore the timeout and try to run the build command anyway. If the build command fails, docker-ssh-exec returns the exit code of the failed command.


Known Limitations / Bugs

The key data is limited to 4096 bytes.

On macOS 10.14 or later, the default format of ssh-keygen will produce an "OpenSSH private key" (reference). For example:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/before_rsa
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in ${HOME}/.ssh/before_rsa.
Your public key has been saved in ${HOME}/.ssh/before_rsa.pub.
The key fingerprint is:
...
$ head -2 ~/.ssh/before_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAZOJlIwH

To use a passphrase, this library requires an actual "RSA private key". To make ssh-keygen produce one, use the -m (key format) flag:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/after_rsa -m PEM
...
$ head -5 ~/.ssh/after_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,70B1F7ECFCC66C9DF073996B92D3C01E
GNhm2zcN6oz+K9yZimDMx6w5PD+mDz7ylVulz+PnYVP5TVs4yZuVZF3GGlu/NYZ1

Contribution / Development

This software was created by Benton Roberts (broberts@mdsol.com)

To build it yourself, just go get and go install as usual:

go get github.com/mdsol/docker-ssh-exec
cd $GOPATH/src/github.com/mdsol/docker-ssh-exec
go install

About

Secure SSH key injection for Docker builds

Topics

Resources

Stars

88 stars

Watchers

101 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
This repository was archived by the owner on Mar 24, 2025. It is now read-only.

Repository files navigation

docker-ssh-exec - Secure SSH key injection for Docker builds

Allows commands that require an SSH key to be run from within a Dockerfile, without leaving the key in the resulting image.


Overview

This program runs in two different modes:

  • a server mode, run as the Docker image mdsol/docker-ssh-exec, which transmits an SSH key on request to the the client; and
  • a client mode, invoked from within the Dockerfile, that grabs the key from the server, writes it to the filesystem, runs the desired build command, and then deletes the key before the filesystem is snapshotted into the build.

Installation

To install the server, just pull mdsol/docker-ssh-exec like any other Docker image.

To install the client, just grab it from the releases page, uncompress the archive, and copy the binary to somewhere in your $PATH. Remember that the client is run during the docker build... process, so either install the client just before invoking it, or make sure it's already present in your source image. Here's an example of the code you might run in your source image, to prepare it for SSH cloning from GitHub:

# install Medidata docker-ssh-exec build tool from S3 bucket "mybucket"
curl https://s3.amazonaws.com/mybucket/docker-ssh-exec/\
docker-ssh-exec_0.5.1_linux_amd64.tar.gz | \
tar -xz --strip-components=1 -C /usr/local/bin \
docker-ssh-exec_0.5.1_linux_amd64/docker-ssh-exec
mkdir -p /root/.ssh && chmod 0700 /root/.ssh
ssh-keyscan github.com >/root/.ssh/known_hosts

Usage

To run the server component, pass it the private half of your SSH key, either as a shared volume:

docker run -v ~/.ssh/id_rsa:/root/.ssh/id_rsa --name=keyserver -d \
mdsol/docker-ssh-exec -server

or as an ENV var:

docker run -e DOCKER-SSH-KEY="$(cat ~/.ssh/id_rsa)" --name=keyserver -d \
mdsol/docker-ssh-exec -server

The benefit of this second method is that OS X systems using a virtual Docker host cannot easily use Docker's shared volume feature with files on the OS X side. The drawback is that the kay data is exposed in the process list.

Then, run a quick test of the client, to make sure it can get the key:

docker run --rm -it mdsol/docker-ssh-exec cat /root/.ssh/id_rsa

Finally, as long as the source image is set up to trust (or ignore) GitHub's server key, you can clone private repositories from within the Dockerfile like this:

docker-exec-ssh git clone git@github.com:my_user/my_private_repo.git

The client first transfers the key from the server, writing it to $HOME/.ssh/id_rsa (by default), then executes whatever command you supply as arguments. Before exiting, it deletes the key from the filesystem.

Here's the command-line help:

Usage of docker-ssh-exec:
-key string
path to key file (default "~/.ssh/id_rsa")
-port int
server receiving port (default 1067)
-pwd string
password for encrypted RSA key
-server
run key server instead of command
-version
print version and exit
-wait int
client timeout, in seconds (default 3)

The software quits with a non-zero exit code (>100) on any error -- except a timeout from the keyserver, in which case it will just ignore the timeout and try to run the build command anyway. If the build command fails, docker-ssh-exec returns the exit code of the failed command.


Known Limitations / Bugs

The key data is limited to 4096 bytes.

On macOS 10.14 or later, the default format of ssh-keygen will produce an "OpenSSH private key" (reference). For example:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/before_rsa
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in ${HOME}/.ssh/before_rsa.
Your public key has been saved in ${HOME}/.ssh/before_rsa.pub.
The key fingerprint is:
...
$ head -2 ~/.ssh/before_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAZOJlIwH

To use a passphrase, this library requires an actual "RSA private key". To make ssh-keygen produce one, use the -m (key format) flag:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/after_rsa -m PEM
...
$ head -5 ~/.ssh/after_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,70B1F7ECFCC66C9DF073996B92D3C01E
GNhm2zcN6oz+K9yZimDMx6w5PD+mDz7ylVulz+PnYVP5TVs4yZuVZF3GGlu/NYZ1

Contribution / Development

This software was created by Benton Roberts (broberts@mdsol.com)

To build it yourself, just go get and go install as usual:

go get github.com/mdsol/docker-ssh-exec
cd $GOPATH/src/github.com/mdsol/docker-ssh-exec
go install

About

Secure SSH key injection for Docker builds

Topics

Resources

Stars

88 stars

Watchers

101 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
This repository was archived by the owner on Mar 24, 2025. It is now read-only.

Repository files navigation

docker-ssh-exec - Secure SSH key injection for Docker builds

Allows commands that require an SSH key to be run from within a Dockerfile, without leaving the key in the resulting image.


Overview

This program runs in two different modes:

  • a server mode, run as the Docker image mdsol/docker-ssh-exec, which transmits an SSH key on request to the the client; and
  • a client mode, invoked from within the Dockerfile, that grabs the key from the server, writes it to the filesystem, runs the desired build command, and then deletes the key before the filesystem is snapshotted into the build.

Installation

To install the server, just pull mdsol/docker-ssh-exec like any other Docker image.

To install the client, just grab it from the releases page, uncompress the archive, and copy the binary to somewhere in your $PATH. Remember that the client is run during the docker build... process, so either install the client just before invoking it, or make sure it's already present in your source image. Here's an example of the code you might run in your source image, to prepare it for SSH cloning from GitHub:

# install Medidata docker-ssh-exec build tool from S3 bucket "mybucket"
curl https://s3.amazonaws.com/mybucket/docker-ssh-exec/\
docker-ssh-exec_0.5.1_linux_amd64.tar.gz | \
tar -xz --strip-components=1 -C /usr/local/bin \
docker-ssh-exec_0.5.1_linux_amd64/docker-ssh-exec
mkdir -p /root/.ssh && chmod 0700 /root/.ssh
ssh-keyscan github.com >/root/.ssh/known_hosts

Usage

To run the server component, pass it the private half of your SSH key, either as a shared volume:

docker run -v ~/.ssh/id_rsa:/root/.ssh/id_rsa --name=keyserver -d \
mdsol/docker-ssh-exec -server

or as an ENV var:

docker run -e DOCKER-SSH-KEY="$(cat ~/.ssh/id_rsa)" --name=keyserver -d \
mdsol/docker-ssh-exec -server

The benefit of this second method is that OS X systems using a virtual Docker host cannot easily use Docker's shared volume feature with files on the OS X side. The drawback is that the kay data is exposed in the process list.

Then, run a quick test of the client, to make sure it can get the key:

docker run --rm -it mdsol/docker-ssh-exec cat /root/.ssh/id_rsa

Finally, as long as the source image is set up to trust (or ignore) GitHub's server key, you can clone private repositories from within the Dockerfile like this:

docker-exec-ssh git clone git@github.com:my_user/my_private_repo.git

The client first transfers the key from the server, writing it to $HOME/.ssh/id_rsa (by default), then executes whatever command you supply as arguments. Before exiting, it deletes the key from the filesystem.

Here's the command-line help:

Usage of docker-ssh-exec:
-key string
path to key file (default "~/.ssh/id_rsa")
-port int
server receiving port (default 1067)
-pwd string
password for encrypted RSA key
-server
run key server instead of command
-version
print version and exit
-wait int
client timeout, in seconds (default 3)

The software quits with a non-zero exit code (>100) on any error -- except a timeout from the keyserver, in which case it will just ignore the timeout and try to run the build command anyway. If the build command fails, docker-ssh-exec returns the exit code of the failed command.


Known Limitations / Bugs

The key data is limited to 4096 bytes.

On macOS 10.14 or later, the default format of ssh-keygen will produce an "OpenSSH private key" (reference). For example:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/before_rsa
Generating public/private rsa key pair.
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in ${HOME}/.ssh/before_rsa.
Your public key has been saved in ${HOME}/.ssh/before_rsa.pub.
The key fingerprint is:
...
$ head -2 ~/.ssh/before_rsa
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAACmFlczI1Ni1jdHIAAAAGYmNyeXB0AAAAGAAAABAZOJlIwH

To use a passphrase, this library requires an actual "RSA private key". To make ssh-keygen produce one, use the -m (key format) flag:

$ ssh-keygen -t rsa -b 4096 -C "...@email.com" -f ~/.ssh/after_rsa -m PEM
...
$ head -5 ~/.ssh/after_rsa
-----BEGIN RSA PRIVATE KEY-----
Proc-Type: 4,ENCRYPTED
DEK-Info: AES-128-CBC,70B1F7ECFCC66C9DF073996B92D3C01E
GNhm2zcN6oz+K9yZimDMx6w5PD+mDz7ylVulz+PnYVP5TVs4yZuVZF3GGlu/NYZ1

Contribution / Development

This software was created by Benton Roberts (broberts@mdsol.com)

To build it yourself, just go get and go install as usual:

go get github.com/mdsol/docker-ssh-exec
cd $GOPATH/src/github.com/mdsol/docker-ssh-exec
go install

About

Secure SSH key injection for Docker builds

Topics

Resources

Stars

88 stars

Watchers

101 watching

Forks

Releases

Packages

Contributors

Languages