36e9d5b0b3
An SSH jump host that authenticates users against the shared LDAP directory, authorizes them from the SSO Manager's inventory graph, and bridges them to downstream hosts — auditing everything. - Username-grammar routing (uid_-_target@jump) + interactive TUI picker - Inbound LDAP auth (publickey / password with off|local|all policy) - Directory-driven access (LDAP groups x /api/discovery/resources?group=) - Per-user key injection into sshPublicKey, connects downstream as the user - Shell / exec / SFTP-subsystem bridging (WinSCP works) - Web UI + HTTP API (:3002) for audit + metrics; LDAP-admin gated - Packaged like proxy: ops/install.sh + systemd, all-in-one Docker, compose - Tests: 23 unit + 3 integration (node --test), all green Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1.7 KiB
1.7 KiB
Changelog
All notable changes to this project are documented here. Format loosely
follows Keep a Changelog; versions
correspond to git tags (vX.Y.Z) and nodejs/package.json's version.
[1.0.0] - 2026-07-23
Added
- Initial release. An SSH jump host for the theta42 stack:
- Username-grammar routing:
ssh {uid}_-_{target}@jumphostbridges straight to the downstream host (target= a directory host slug, bare hostname, or IP). Shell, exec, and the SFTP subsystem all pass through, so WinSCP/sftpwork. - Interactive TUI picker: plain
ssh {uid}@jumphostlists the hosts the user can reach (from the SSO directory) and bridges to the chosen one. - LDAP auth of the inbound user (publickey against the user's
sshPublicKey, or password via LDAP bind — password policy is off/local/all). - Directory-driven access: reachable hosts are the union of the user's
LDAP groups × the SSO directory (
/api/discovery/resources?group=). - Per-user key injection: the jump host appends its own public key to the
user's
sshPublicKeyon first use, then connects downstream as that user (downstream hosts already serve LDAP keys via ldap-client's AuthorizedKeysCommand). - Web UI + HTTP API (
:3002) for auditing and metrics: active sessions, paged audit log, per-user/per-host counters. Admin login gated by LDAP group membership. - Audit logging of every connection attempt/session (user, target, method, result, bytes, duration, downstream host-key fingerprint).
- Packaged like theta42/proxy: idempotent
ops/install.sh+ systemd unit, all-in-one Docker image, standalonedocker-compose.yml.
- Username-grammar routing: