docs(runbook): document git-over-SSH client-IP limitation (#91) #153

Sammanfogat
supernaut sammanfogade 1 incheckning från docs/91-ssh-client-ip-limitation in i main 2026-07-19 21:07:25 +00:00
Ägare

Investigation — the two fix candidates aren't feasible in the current architecture

Option 1 (socket activation, like #81): not applicable. #81 works because Caddy natively consumes a systemd-passed fd (bind fd/3 in the Caddyfile). git-over-SSH here is served by the image's bundled OpenSSH (START_SSH_SERVER=false; the rootful image runs its own sshd, PublishPort={{ git_ssh_port }}:22). OpenSSH sshd has no way to consume a systemd-passed socket fd for its main listener — so the fd-passing trick that de-pasta'd Caddy can't de-pasta sshd.

Option 2 (PROXY protocol): not applicable. SSH_SERVER_PROXY_PROTOCOL governs Forgejo's built-in SSH server, which is disabled. OpenSSH sshd doesn't speak PROXY protocol.

Resolution (option 3 for now) + recommendation

Documented as a known limitation in the runbook (this PR). A real fix requires a re-architecture of git-over-SSH, e.g.:

  • switch to Forgejo's built-in SSH server behind a host-level PROXY-protocol forwarder, or
  • a host-level sshd with AuthorizedKeysCommand proxying to Forgejo.

Both are sizeable changes to a core function (git push/pull) and warrant their own ADR/epic + a maintenance-window rollout — not an incidental fix. Impact is bounded: SSH access is key-authenticated and unaffected; only IP attribution in logs/audit is degraded (abuse-tracing / rate-limiting gap, not an access-control hole).

Keeping #91 open as the tracker for that re-architecture. Runbook now documents the limitation so it isn't rediscovered.

## Investigation — the two fix candidates aren't feasible in the current architecture **Option 1 (socket activation, like #81): not applicable.** #81 works because Caddy *natively consumes a systemd-passed fd* (`bind fd/3` in the Caddyfile). git-over-SSH here is served by the **image's bundled OpenSSH** (`START_SSH_SERVER=false`; the rootful image runs its own `sshd`, `PublishPort={{ git_ssh_port }}:22`). OpenSSH `sshd` has **no** way to consume a systemd-passed socket fd for its main listener — so the fd-passing trick that de-pasta'd Caddy can't de-pasta sshd. **Option 2 (PROXY protocol): not applicable.** `SSH_SERVER_PROXY_PROTOCOL` governs Forgejo's **built-in** SSH server, which is disabled. OpenSSH `sshd` doesn't speak PROXY protocol. ## Resolution (option 3 for now) + recommendation Documented as a known limitation in the runbook (this PR). A real fix requires a **re-architecture** of git-over-SSH, e.g.: - switch to Forgejo's built-in SSH server behind a host-level PROXY-protocol forwarder, or - a host-level `sshd` with `AuthorizedKeysCommand` proxying to Forgejo. Both are sizeable changes to a core function (git push/pull) and warrant their own ADR/epic + a maintenance-window rollout — not an incidental fix. **Impact is bounded:** SSH access is key-authenticated and unaffected; only IP *attribution* in logs/audit is degraded (abuse-tracing / rate-limiting gap, not an access-control hole). Keeping #91 open as the tracker for that re-architecture. Runbook now documents the limitation so it isn't rediscovered.
supernaut lade till 1 incheckning 2026-07-19 20:47:09 +00:00
docs(runbook): document git-over-SSH client-IP limitation (#91)
Alla kontroller lyckades
ci / ci (pull_request) Successful in 12s
eeac1770b6
Socket activation (#81) can't fix SSH client IPs: it works because
Caddy consumes a systemd-passed fd, and OpenSSH sshd (the image's
bundled server; Forgejo built-in SSH is off) has no equivalent.
SSH_SERVER_PROXY_PROTOCOL only applies to Forgejo's built-in server.
A real fix needs a git-over-SSH re-architecture — document as a known
limitation and keep #91 open as the tracker.

Refs #91.
supernaut sammanfogade incheckning c227e77ac2 till main 2026-07-19 21:07:25 +00:00
supernaut tog bort grenen docs/91-ssh-client-ip-limitation 2026-07-19 21:07:25 +00:00
Logga in för att delta i denna konversation.
Inga granskare
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Förfallodatumet är ogiltigt eller utanför gränserna. Använd formatet "åååå-mm-dd".

Inget förfallodatum satt.

Beroenden

Inga beroenden satta

Referens
bitborg/bitborg-infra!153
Ingen beskrivning angiven.