Re: Read host keys from environment variables
Darren Tucker via openssh-unix-dev <[email protected]>
| Newsgroups | gmane.network.openssh.devel |
|---|---|
| Message-ID | <CALDDTe31D7RJORRtp=o+9cV36WK-nvjNtLkWf4UHcnWYooAOxg@mail.gmail.com> |
On Tue, 11 Aug 2026 at 19:47, Philipp Marek via openssh-unix-dev <[email protected]> wrote: > Hi everybody, > > for use in containers it would be nice to pull SSH host keys from > environment variables. Well for one thing, on many systems environment variables are visible to every other user on the system, which seems like a really bad attribute to have for the secret which is the only thing preventing someone from MITMing your connection. > I saw "HostKeyAgent", but providing a unix-socket to a different > container running an agent You could maybe cook something up with HostKeyAgent to an ssh-agent in the same container. This works to load a key from an environment variable: $ ssh-keygen -f tmp-key -t ed25519 $ key=$(cat tmp-key) $ echo "$key" | ssh-add /dev/stdin so you could in theory plumb an environment variable through to a host key available to sshd. That sounds like a bad idea, though. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.