Files
jump-host/CHANGELOG.md
T
wmantly 36e9d5b0b3 feat: initial jump-host — SSH jump host for the theta42 stack
An SSH jump host that authenticates users against the shared LDAP
directory, authorizes them from the SSO Manager's inventory graph, and
bridges them to downstream hosts — auditing everything.

- Username-grammar routing (uid_-_target@jump) + interactive TUI picker
- Inbound LDAP auth (publickey / password with off|local|all policy)
- Directory-driven access (LDAP groups x /api/discovery/resources?group=)
- Per-user key injection into sshPublicKey, connects downstream as the user
- Shell / exec / SFTP-subsystem bridging (WinSCP works)
- Web UI + HTTP API (:3002) for audit + metrics; LDAP-admin gated
- Packaged like proxy: ops/install.sh + systemd, all-in-one Docker, compose
- Tests: 23 unit + 3 integration (node --test), all green

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-23 15:48:49 -04:00

1.7 KiB
Raw Blame History

Changelog

All notable changes to this project are documented here. Format loosely follows Keep a Changelog; versions correspond to git tags (vX.Y.Z) and nodejs/package.json's version.

[1.0.0] - 2026-07-23

Added

  • Initial release. An SSH jump host for the theta42 stack:
    • Username-grammar routing: ssh {uid}_-_{target}@jumphost bridges straight to the downstream host (target = a directory host slug, bare hostname, or IP). Shell, exec, and the SFTP subsystem all pass through, so WinSCP/sftp work.
    • Interactive TUI picker: plain ssh {uid}@jumphost lists the hosts the user can reach (from the SSO directory) and bridges to the chosen one.
    • LDAP auth of the inbound user (publickey against the user's sshPublicKey, or password via LDAP bind — password policy is off/local/all).
    • Directory-driven access: reachable hosts are the union of the user's LDAP groups × the SSO directory (/api/discovery/resources?group=).
    • Per-user key injection: the jump host appends its own public key to the user's sshPublicKey on first use, then connects downstream as that user (downstream hosts already serve LDAP keys via ldap-client's AuthorizedKeysCommand).
    • Web UI + HTTP API (:3002) for auditing and metrics: active sessions, paged audit log, per-user/per-host counters. Admin login gated by LDAP group membership.
    • Audit logging of every connection attempt/session (user, target, method, result, bytes, duration, downstream host-key fingerprint).
    • Packaged like theta42/proxy: idempotent ops/install.sh + systemd unit, all-in-one Docker image, standalone docker-compose.yml.